Ambry Genetics
Medical records run on two clocks, and only one of them is yours: retention law keeps the clinical file for years or decades whatever you ask. Around it, what you looked up can become an advertising interest, and a deletion request usually comes back half done.
Reported incidents
Pays 700,000 dollars to US regulator after phishing exposed 225,370 patients
2026-09-17Affected Employee email account
The genetic testing company Ambry Genetics agreed to pay $700,000 to the US Department of Health and Human Services Office for Civil Rights to settle HIPAA Security Rule violations. In January 2020 a phishing attack gave an outsider access to an employee's email account, exposing data on 225,370 people: names, addresses, dates of birth, Social Security and driver's licence numbers, diagnoses, lab results, medications and treatment information. The regulator found Ambry had not carried out an accurate risk analysis, had no procedures to end staff access, and did not give staff unique user IDs. Ambry is under a two-year corrective action plan.
People affected typically ask Ambry Genetics to confirm whether their information was included, and which categories.
The verified route
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.