Genetic lab’s old email breach draws a $700K federal fine

Federal regulators faulted the lab's risk analysis and access controls after a 2020 phishing email.

MedRisk Staff
By
2 Min Read

A phishing email that sat unnoticed in an employee inbox for two days in 2020 has now cost a California genetic testing company $700,000 and two years of federal oversight.

The HHS Office for Civil Rights reached the settlement with Ambry Genetics, an Aliso Viejo firm that runs clinical genomics and hereditary testing. Investigators found an unauthorized party inside a staff email account from January 22 to January 24, 2020, after the employee replied to a phishing message. Records caught up in the incident included names, addresses, birth dates, driver’s license numbers, diagnoses, medications, treatment details and some Social Security numbers, covering 225,370 people.

OCR concluded the company had not performed an accurate, thorough risk analysis, had failed to cut off system access when workers left, and had not issued unique usernames so activity could be tracked. Ambry accepted a corrective action plan requiring a full risk analysis, a risk management program, rewritten HIPAA policies, unique workforce identifiers and staff training. The lab separately settled class action litigation over the breach for $12.25M.

“Email phishing is a common cyberattack that can lead to a breach of PHI and reveal HIPAA Security Rule deficiencies,” OCR Director Paula Stannard said.

The takeaway for providers and their vendors is familiar: the security rule’s risk-analysis and access-control requirements are the obligations regulators return to most often.

Share This Article