Baylor Genetics Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Baylor Genetics
Active investigation Data breach · Healthcare Notices mailed Aug 14, 2026

Received an August 2026 breach notice from Baylor Genetics?

Dapeer Law, P.A. is investigating a potential class action against Baylor Genetics, a Houston-based genetic testing laboratory affiliated with Baylor College of Medicine, on behalf of the 305,066 patients and partners whose personal, financial, and medical information may have been exposed in the June 2026 network intrusion.

Submit your claim See what to do No fee unless we recover for you
Breach window
Jun 11 to 17, 2026
Unauthorized network access
Notification delay
About 2 months
Detected Jun 15, 2026, notices Aug 14, 2026
Credit monitoring
24 months
Through IDX, bureau coverage not stated in the notice
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Baylor Genetics dated August 2026.
  • Your letter offered enrollment in 24 months of free credit monitoring and identity protection through IDX, using the enrollment code printed in the notice.
  • You were a patient, family member, or referring provider whose personal, financial, or medical information was held by Baylor Genetics in its capacity as a clinical genetic testing laboratory.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

Baylor Genetics detected suspicious activity in its information technology environment on June 15, 2026. The laboratory secured its systems and engaged independent cybersecurity and digital forensics specialists, whose investigation confirmed that an unauthorized third party had access to certain segments of the network between June 11 and June 17, 2026. Baylor Genetics has not publicly identified how the intrusion occurred or who was responsible, and it states that it has not identified any confirmed misuse of the information to date.

The laboratory completed its review of the affected data on or about July 30, 2026 and began mailing notification letters on August 14, 2026, the same day it filed notice with the California Attorney General. State regulatory filings report 305,066 affected individuals, including 248,430 Texas residents and 56,636 Massachusetts residents. According to the notice, the information involved may have included name, address, date of birth, Social Security number, driver's license or state identification number, other government-issued identification number, financial account information, health insurance information, and medical information. Baylor Genetics is offering 24 months of complimentary credit monitoring and identity protection services through IDX, with enrollment instructions included in the mailed letter.

This combination of data elements is among the most sensitive that can be involved in a breach. A Social Security number paired with medical and health insurance details supports both financial identity theft and medical identity theft, in which another person uses someone else's coverage to obtain treatment or prescriptions. A Social Security number cannot be reissued on request, and medical records cannot be recalled once copied. The public notice does not state that genetic or genomic test results were involved, and Dapeer Law is evaluating that question along with the laboratory's data security practices and the roughly two-month gap between detection and the notice letters under Texas, Massachusetts, and California law.

Genetic testing laboratory breach Social Security numbers exposed Medical and health insurance information California Attorney General Massachusetts Attorney General Medical identity theft risk
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the enrollment code for the free IDX identity protection service and is important evidence that you were among the 305,066 individuals identified in the regulatory filings if you decide to participate in a lawsuit.

2

Enroll in the free 24-month credit monitoring

Enroll in the 24 months of IDX credit monitoring and identity protection offered in your letter, following the instructions and deadline printed in the notice. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because medical and health insurance information was reported as involved, also review the Explanation of Benefits statements from your insurer for providers, treatment, or prescriptions you do not recognize, and request a copy of your medical file if anything looks unfamiliar.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We will review your notice letter, explain how Texas, Massachusetts, and California breach notification requirements and HIPAA-related standards apply to a clinical laboratory, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

Jun 11, 2026 Passed
Unauthorized access to the Baylor Genetics network begins
Jun 15, 2026 Passed
Suspicious activity detected, systems secured, forensic investigation begins
Jun 17, 2026 Passed
End of the unauthorized access window identified by the investigation
Jul 30, 2026 Passed
Review of the affected data completed
Aug 14, 2026 Passed
Notice filed with the California Attorney General, letters mailed to 305,066 individuals
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. The IDX enrollment deadline is printed on your individual notice letter, so check that date before it passes. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, medical-claim and health insurance fraud, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Baylor Genetics to implement stronger data security practices going forward, including improved network monitoring and identity and access management, encryption of stored patient records, and faster breach notification to affected individuals.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Baylor Genetics. What should I do? +

Keep the letter and the envelope, including the enrollment code. Enroll in the 24 months of free IDX credit monitoring and identity protection using the instructions in your notice. Review your bank, credit card, and Explanation of Benefits statements for activity you do not recognize, request your free credit reports, and consider placing a fraud alert or a security freeze with Equifax, Experian, and TransUnion, which is free. Then speak with a data breach attorney about your options.

Am I eligible to join a class action against Baylor Genetics? +

If you received the August 14, 2026 notice letter from Baylor Genetics, or can otherwise confirm that your information was involved, you may be eligible. Eligibility and the value of a claim can depend on your state of residence, which categories of your information were involved, and whether you have documented losses, unauthorized charges, or time spent resolving fraud. Most affected individuals are Texas residents (248,430), with 56,636 Massachusetts residents also notified. A free consultation is the fastest way to find out where you stand.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

According to the notice, the information involved may have included name, address, date of birth, Social Security number, driver's license or state identification number, other government-issued identification number, financial account information such as an account, credit, or debit card number, health insurance information, and medical information. The categories that apply to you specifically should be described in your individual letter, so check it and keep it. The public notice does not state that genetic or genomic test results were involved, and Baylor Genetics has not disclosed how the intrusion occurred.

Did Baylor Genetics offer free credit monitoring? +

Yes. Baylor Genetics is offering 24 months of complimentary credit monitoring and identity protection services through IDX at no cost, with enrollment instructions and a deadline included in the mailed notice. The notice does not state whether the monitoring covers one credit bureau or all three. Enrolling does not waive your right to pursue a legal claim, and it does not release the laboratory from liability.

How many people were affected by the Baylor Genetics breach? +

State filings report 305,066 affected individuals: 248,430 Texas residents and 56,636 Massachusetts residents. Notification began on August 14, 2026, the same day notice was filed with the California Attorney General. This page will be updated if Baylor Genetics or a regulator revises the count.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

The notice of the data event was filed with the California Attorney General, and the notice letter is also published by the Massachusetts Attorney General as filing 2026-1366. Both PDFs are linked in the Sources and references section of this page. If you cannot locate your letter or need help obtaining a copy, Dapeer Law can assist during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Baylor Genetics, IDX, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with the California Attorney General on August 14, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Langwasser & Company CPAs Data Breach Lawsuit Investigation

Next
Next

Paylogix, LLC Data Breach Lawsuit Investigation