Baylor Genetics Data Breach: Genetic Test Results and SSNs of 305,066 People Exposed
Notification letters started arriving in mid-August 2026. There is no settlement, no claim form and no deadline yet — and anyone telling you otherwise is not describing this case. Here is where things actually stand as of 24 August 2026, and what is worth doing this week.
Revisado Editorialmente — Contenido revisado en cuanto a exactitud utilizando investigación legal publicada, datos gubernamentales y registros judiciales verificados. Vea nuestra metodología
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened
Baylor Genetics is a Houston-based clinical genetic testing laboratory whose tests include preimplantation genetic testing (PGT-A) used during IVF — which is why this breach reaches couples who never set foot in a Baylor facility. An unauthorized third party accessed portions of the company's network between June 11 and June 17, 2026. State regulatory filings report 305,066 people affected, including 248,430 Texas residents and 56,636 in Massachusetts. The exposed information varies by person and may include name, address, date of birth, Social Security number, driver's license or other government-issued ID numbers, financial account information, health insurance information and medical information — and the company's filing with the California Attorney General describes genetic and genomic test results and family medical history among the affected data.
Case Details
As of 24 August 2026, no class action lawsuit has been filed that we could confirm — this case is in the investigation stage. Multiple plaintiffs' firms, including Murphy Law Firm, Cole & Van Note, Abington, Emery Reddy and Dapeer, have opened investigations and are speaking with affected patients, partners and employees. That is the normal first step: firms gather clients and facts, then file. In comparable healthcare breaches of this size, the first complaints have typically followed within weeks of the notification letters going out.
Status as of 24 August 2026
Who Is Affected
The 305,066 figure covers patients, their partners and employees. Two groups are easy to miss. First, IVF partners: PGT-A testing involves genetic material and information from both partners, so people who were never themselves a Baylor Genetics patient can still be in the affected population — if your partner did embryo testing, watch the mail for a letter in your own name. Second, people who have moved: letters go to the address on file, which for many patients is years old. If you believe you are affected but received nothing, you can contact Baylor Genetics through the security update page on its official website rather than waiting.
What Compensation Could Look Like
How This Unfolded
- 1
June 11–17, 2026 — the intrusion
An unauthorized third party accesses portions of the Baylor Genetics network and data stored on it during this window.
- 2
About June 15, 2026 — detection
The company identifies suspicious activity, secures the affected systems and begins a forensic investigation.
- 3
About July 30, 2026 — data review completed
The review determines whose information was involved and what categories of data were affected.
- 4
August 14, 2026 — notification begins
Notification letters start going out by mail, with 24 months of IDX credit monitoring offered. Baylor Genetics files notice with the California Attorney General the same day; state filings report 305,066 people affected.
- 5
August 24, 2026 — where things stand
Multiple law firms are investigating and signing up affected people. No class action complaint, settlement or claim deadline exists yet that we could confirm.
Three Things to Ignore
A breach with six-figure victim counts and no official claims process yet is exactly the gap scammers work. These are the patterns to expect.
“File your Baylor Genetics claim now”
There is no settlement and no claim form. Any website or advertisement offering to file a Baylor Genetics claim for you today is not describing a real process. When a settlement eventually exists, the claim will be free and run by a court-appointed administrator.
Calls or emails asking to “verify” your details
The real notification came as a postal letter, and IDX enrollment works through the instructions in that letter. Nobody legitimate will call, text or email asking you to confirm your Social Security number, test results or bank details because of this breach — that contact is the scam itself, likely powered by the very data that leaked.
Paying for protection you already get free
The 24 months of IDX monitoring costs nothing, and credit freezes at all three bureaus are free by law and stronger than any paid monitoring. A pitch to sell you identity protection because of this breach is charging you for less than what you already have.
Common Questions
Has a lawsuit actually been filed?
Not that we could confirm as of 24 August 2026. Several plaintiffs' firms are formally investigating and gathering affected clients, which is the step that precedes filing. Speaking with an investigating firm costs nothing — data breach class actions are handled on contingency, meaning fees come out of any eventual recovery, not your pocket.
Should I enroll in the free IDX monitoring?
Yes. It is free, it starts protection now, and enrolling in monitoring offered after a breach does not, as a general matter, waive your right to participate in litigation — though it is always worth reading the enrollment terms. Declining the monitoring does not earn you anything extra later.
What makes genetic data different from a stolen card number?
A card can be cancelled and reissued; your genome cannot. Genetic test results and family medical history are permanent identifiers that also carry information about your relatives and, in the IVF context, about embryos and fertility decisions. That permanence is why genetic-privacy breaches have been treated as serious in prior litigation, and why the sensible protective steps are the durable ones: credit freezes and long-term vigilance rather than a one-time password change.
My partner did IVF testing — could I be affected too?
Yes. The affected population includes patients and partners, because PGT-A testing during IVF involves information from both people. Watch for a letter addressed to you personally, and if your household has moved since the testing, consider contacting Baylor Genetics through its official security update page to check.
What should I do this week?
Four things. Enroll in the IDX monitoring using the letter. Freeze your credit at Equifax, Experian and TransUnion — free, online, reversible. Keep the notification letter itself; it is your proof of membership in the affected class. And start a simple record of anything suspicious or any costs the breach causes you — documented losses are the strongest claims if a settlement comes.
When would any settlement money arrive?
Years out, realistically. No case has even been filed yet. As a reference point, the MNGI healthcare breach took about two years and nine months from breach to first payments, and larger cases with more victims often take longer. This page tracks the case, and we update it as the litigation develops.
How do I verify what this page says?
Baylor Genetics maintains a security update page on its official website, and the notification is on file with state regulators including the California and Texas Attorneys General — the 305,066 figure comes from those state filings as reported in regulatory summaries. Everything here reflects what we could confirm as of 24 August 2026; where a court docket exists in future, the docket is authoritative.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.