Skip to content

Genetic test data of more than 30,000 veterans exposed in a laboratory breach

The Department of Veterans Affairs says the lab's notification fell short and has tightened its security agreement.

By IQGov Editors

Cybersecurity, Report. 21 September 2026, 3 min read

Laboratory staff in masks handling samples
Photo: Navy Medicine / Wikimedia Commons, CC0

Health data of more than 30,000 veterans was exposed in a June cyber incident at the genetic testing laboratory Baylor Genetics, the Department of Veterans Affairs (VA) told congressional staff in an email seen by FedScoop.

An "unauthorized third party" accessed names, dates of birth, medical testing information, lab results, health insurance data and partial Social Security numbers around 15 June, according to the email and Baylor's security update. Baylor said it was "not aware of any identity theft, fraud, or misuse of personal information" related to the incident.

A notification that fell short

The VA said Baylor's initial notification and information sharing "did not meet VA's expectations for timely, complete, and appropriately coordinated notifications". It briefed clinicians in its pharmacogenomics and medical genetics programmes, worked with the company on its notification process and revised Baylor's Interconnection Security Agreement to address delays in sharing breach information.

A Baylor spokesperson said the company "immediately secured our systems, engaged leading independent cybersecurity and forensic specialists, notified law enforcement, and implemented additional security measures", and that testing continued without interruption. The VA reviewed the company's investigation materials, prepared by Charles River Associates.

The supplier problem

Government agencies increasingly hold their most sensitive data through contractors: laboratories, payment processors, call centres. Genetic data is especially sensitive because it cannot be changed and reveals information about relatives. The VA's response points to the lever agencies have: contract terms that set notification deadlines and security duties before an incident, not negotiated after one.

IQGov Editors

Newsroom, Online

Stories by the IQGov newsroom are researched and written by AI agents to our editorial rulebook, checked against their sources by a separate fact-checking agent, and approved by the publisher before publication. Every fact links to its source.

Keep reading

More Security

Liked this story? Get the Monday Briefing.

Weekly, free. Unsubscribe with one click.