The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a $700,000 settlement with Ambry Genetics Corporation following an investigation into a phishing attack involving patient health information. HHS lists the settlement among its HIPAA enforcement actions announced on September 17, 2026.
Ambry, a genetic testing and clinical genomics company based in Aliso Viejo, California, agreed to take corrective action to address potential violations of the HIPAA Security Rule.
What Happened?
In January 2020, Ambry discovered that a phishing attack had compromised an employee’s email account. The incident potentially allowed an unauthorized person to obtain the protected health information (PHI) of 225,370 individuals.
The information involved included names, addresses, dates of birth, financial information, diagnoses, medical conditions, laboratory results, medications, and treatment details. Some individuals’ Social Security numbers or driver’s license numbers were also involved.
OCR opened its investigation after Ambry submitted a breach report in March 2020.
Three Potential HIPAA Security Rule Violations
According to the announcement, OCR identified potential compliance failures in three areas:
- Risk analysis: Ambry had not conducted an accurate and thorough assessment of the risks and vulnerabilities affecting its electronic protected health information (ePHI).
- Access termination: Ambry had not implemented procedures to end access to ePHI when a workforce member’s employment or other working arrangement ended, or when access was no longer appropriate.
- Unique user identification: Ambry had not assigned unique names or numbers to identify and track users in electronic systems containing ePHI.
These findings highlight the importance of looking beyond the phishing incident itself. The HIPAA Security Rule requires organizations to maintain appropriate administrative, physical, and technical safeguards to protect electronic patient information.
Settlement Includes Two Years of Oversight
In addition to paying $700,000, Ambry agreed to implement a corrective action plan that OCR will monitor for two years.
Under the plan, Ambry must conduct a comprehensive risk analysis covering the confidentiality, integrity, and availability of its ePHI. The company must then develop and implement a risk management plan to address the security risks and vulnerabilities identified.
Ambry must also develop, review, and revise its Security Rule policies and procedures as needed, implement unique user identification across all information systems containing ePHI, and train all workforce members on its Security Rule policies and procedures.
What Healthcare Organizations Can Learn
The case offers a practical reminder for HIPAA-covered healthcare providers, health plans, healthcare clearinghouses, and business associates: protecting patient information requires ongoing attention to risks, access controls, and workforce practices. These organizations fall within the scope of the HIPAA Security Rule.
Understand where patient information is stored and shared. Identify where ePHI enters, moves through, and leaves the organization. Update risk analyses as needed and address identified vulnerabilities through a documented risk management process. HHS emphasizes both risk assessment and ongoing risk management.
Control access and review system activity. Limit access to authorized users, verify user identities, and use audit controls to record and examine activity in systems containing ePHI. Regular reviews can help organizations detect security incidents.
Protect information and strengthen workforce practices. OCR’s announcement also recommends encrypting ePHI in transit and at rest when appropriate, incorporating lessons from security incidents into the organization’s security program, and providing regular HIPAA training tailored to employees’ responsibilities.
Training should work alongside technical safeguards and clear procedures, not replace them. HHS identifies workforce training as one part of a broader security program that also includes access management, incident response, and regular evaluation of safeguards.
The resolution agreement and corrective action plan may be found at here.