Diagnostic genomics company Baylor Genetics has become the latest victim of a life sciences cybersecurity breach, affecting both patients and employees.
In an August 14 release, the company said that earlier this summer, it “identified suspicious activity within a limited portion of its information technology environment.”
After an investigation, Baylor found that an unauthorized third party “accessed certain portions of our network, and certain data stored on our network, between June 11 and June 17.”
It then undertook a more detailed review as to what had been taken, with that assessment completed on July 30. The company found that, in terms of patient data, the information “varied by individual,” but for some, there were breaches of personal information.
This included date of birth, medical testing information, lab test results, and potentially health insurance information, as well as Social Security numbers, which the company said in a statement were accessed “for a very limited subset of patients.”
The breach also impacted current and former employees. The information here “may have included personal identifying information such as Social Security numbers, government-issued identification numbers, and financial account information,” Baylor Genetics said.
The company added that it has now started “notifying potentially affected individuals,” stressing that it is “not aware of any confirmed identity theft, fraud, or misuse of personal information related to this incident.”
Baylor works on whole genome and whole exome sequencing tests, as well as targeted panels and specialized assays.
A growing number of medtech companies have been hit by cyberattacks this year, including Medtronic, iRhythm, and Stryker, as well as biopharma companies including Novo Nordisk and, most recently, Amgen.