On June 15, Baylor Genetics in Texas discovered a breach. An investigation subsequently determined that an unauthorized party had accessed data between June 11 and June 17. From their press release:
For all impacted patients, the information potentially involved varied by individual and may have included names and one or more of the following for patients: date of birth, medical testing information, laboratory test results, and potentially health insurance information, as well as Social Security number (for a very limited subset of patients).
For certain current or former employees, the information may have included personal identifying information such as Social Security numbers, government-issued identification numbers, and financial account information.
At this time, Baylor Genetics is not aware of any confirmed identity theft, fraud, or misuse of personal information related to this incident.
Read the full release.
Baylor Genetics does not indicate whether they know what threat actor or group acquired the data, whether there was any extortion demand, or whether they paid any demand. No group has publicly claimed responsibility for the attack.
