These questions landed in my inbox last week after news broke that Ambry Genetics agreed to pay a $700,000 HIPAA fine for a 2020 phishing incident that exposed the information of 225,000 patients. The company had already settled a civil claim for $12.25 million related to the same breach. Several regulatory affairs teams reached out with versions of the same concerns: What does this mean for us? How do we protect genetic data when the threat landscape keeps shifting?
Here's what I told them.
Does Genetic Data Carry More Risk than Other PHI?
Yes, and it's not just about regulatory exposure.
When a phishing attack compromises a patient's name, date of birth, and insurance ID, you're dealing with identity theft risk. When it compromises genetic test results, family history, and diagnostic information, you're dealing with something that can't be changed or reset. You can't issue someone a new genome.
The Office for Civil Rights (OCR) investigation into Ambry found violations that will sound familiar: failure to conduct an accurate and thorough HIPAA Security Rule risk analysis, failure to implement access termination procedures when workforce members leave, and failure to assign unique user identifiers in systems containing Electronic Protected Health Information (ePHI). These aren't exotic failures. They're the same gaps OCR finds in most enforcement actions.
But the consequences scale differently when the compromised data includes genetic markers, hereditary disease risk, and biomarker profiles. That's why you're seeing civil settlements in the eight figures alongside regulatory fines. Ambry's $12.25 million civil settlement offered up to $10,000 per class member for documented out-of-pocket costs, plus three years of credit and identity monitoring.
The regulatory fine is what OCR can impose. The civil liability is what a jury thinks the harm is worth.
What Specific Controls Would've Prevented This?
Start with what OCR actually cited.
Ambry failed to conduct an accurate and thorough risk analysis under 45 CFR § 164.308(a)(1)(ii)(A). That's not a paperwork violation. If you don't know where your ePHI lives, who can access it, and what threats exist, you can't design controls that match your risk profile.
The phishing incident succeeded in January 2020. Ambry reported it to OCR in March 2020. Between those dates, someone with compromised credentials accessed systems containing the information of 225,000 patients. That tells you the access controls weren't sufficient to detect or limit the damage.
Here's what would've helped:
Unique user identification (Required Specification under 164.312(a)(2)(i)). If you can't trace which account accessed which record, you can't audit access patterns or spot anomalies. OCR found Ambry failed to implement this control across all systems containing ePHI.
Access termination procedures (Addressable Specification under 164.308(a)(3)(ii)(C)). When someone leaves your organization or changes roles, their access should end immediately. Ambry didn't have adequate procedures here. In a phishing scenario, this matters because compromised credentials for former employees can persist undetected.
Multi-factor authentication on email and any system touching ePHI. The source article doesn't specify whether Ambry had MFA deployed, but phishing attacks that lead to ePHI access typically exploit single-factor authentication.
Security awareness training that goes beyond annual check-the-box modules. Your workforce needs to recognize phishing attempts in real time, not in a training scenario six months later.
Handling AI Without Creating New Exposure
This is where the Ambry case gets complicated.
Ambry's parent company, Tempus AI, is facing separate proposed class action litigation alleging that when Tempus acquired Ambry in 2025, it transferred genetic information from hundreds of thousands (possibly millions) of Ambry patients to train Tempus' AI models without patient consent. The lawsuit claims violations of genetic privacy and medical-confidentiality statutes in several states.
If you're using patient data (genetic or otherwise) to train AI models, you need explicit legal authority. That's either:
- Patient authorization under the HIPAA Privacy Rule, with clear disclosure of how their information will be used in model training.
- De-identified Information that meets Safe Harbor or Expert Determination requirements under 45 CFR § 164.514.
- A Limited Data Set with a data use agreement that explicitly permits the AI training use case.
"We acquired the company and the data came with it" isn't a legal basis for a new use. Neither is "the data will improve healthcare outcomes generally." You need specific, documented authority for each use.
Should We Be Doing Anything Differently After This Settlement?
Run your risk analysis again, with genetic data in mind.
OCR's corrective action plan for Ambry requires the company to conduct an accurate and thorough risk analysis, develop and implement a risk management plan to address identified risks, revise policies to comply with HIPAA rules, implement unique user identification across all systems containing ePHI, and train all workforce members on updated Security Rule policies and procedures. OCR will monitor compliance for two years.
That's your roadmap. If you're handling genetic test results, family health histories, or genomic data, ask:
- Where does this data live? Cloud storage, local databases, business associate systems, archived records?
- Who can access it? Clinicians, researchers, IT staff, business associates, AI development teams?
- What happens when access should end? Termination, role change, project completion?
- How do we detect unauthorized access? Audit logs, anomaly detection, access reviews?
- What's our plan if credentials get compromised? Incident response, containment, notification?
The NIST SP 800-66 guide to implementing the HIPAA Security Rule walks through the risk analysis process in detail. Use it.
What About Vendors and Business Associates?
The phishing attack hit Ambry directly, but genetic testing labs routinely share data with sequencing vendors, clinical interpretation services, electronic health record systems, and research partners.
Every one of those relationships needs a business associate agreement that addresses the specific risks of genetic data. Your BAA should require:
- Unique user identification and access controls
- Encryption of ePHI at rest and in transit
- Incident response and breach notification procedures
- Restrictions on further use or disclosure (especially for AI training or research)
- Right to audit and terminate for non-compliance
Don't assume your vendor's security program matches your risk tolerance. Validate it.
Are We Going to See More Enforcement in This Space?
Yes. OCR has signaled that genetic data breaches warrant scrutiny, and the civil litigation trend suggests plaintiffs' attorneys see these cases as high-value targets.
You're also seeing more attacks. Recent incidents include a June breach at Baylor Genetics affecting 2.8 million people, data theft from Abbott Laboratories and its Exact Sciences cancer diagnostics unit, and claims by cybercrime groups that they've stolen AI models and genomic datasets from pharmaceutical companies.
The threat actors know genetic data has value. They're targeting labs, diagnostic companies, and pharma firms specifically for genomic datasets and AI training models.
Where Do I Go for More Detail?
Start with OCR's resolution agreement and corrective action plan for Ambry. It's public record and shows exactly what OCR expects.
Review your most recent HIPAA Security Rule risk analysis. If it doesn't specifically address genetic data, AI model training, or business associate access to genomic datasets, update it.
Check your business associate agreements. If they were drafted before your organization started handling genetic test results or using AI models, they probably don't cover the current risk profile.
And if you're considering acquiring a company with genetic data assets or launching an AI initiative that uses patient genomic information, bring your privacy counsel in early. The regulatory and civil liability landscape has shifted, and the old playbook doesn't cover it.





