HHS civil rights office settles phishing breach case for $700,000
Issue
On September 17, 2026, the HHS Office for Civil Rights settled with Ambry Genetics over a 2020 phishing attack that exposed data on 225,370 people. Ambry paid $700,000 and accepted two years of monitoring over gaps in risk analysis, access removal and unique user logins.
OCR urged every health care provider to keep its risk analysis current.
Sources for this story
U.S. Department of Health and Human Services, Office for Civil RightsSources for your board packet
This story's source plus 4 related stories and their sources, ready to print for your team or board.
Free. Unlocking the packet subscribes you to Intel Brief. You'll be subscribed right away, with no confirmation email. Unsubscribe with one click in any issue. If you unsubscribed before, we won't re-add you. We never sell your email. You can open each source above without an email.
Part of
- Enforcement: privacy, fraud and audits
HIPAA rules and OCR enforcement
FQHC Talent. (2026, September 17). HHS civil rights office settles phishing breach case for $700,000. Source: U.S. Department of Health and Human Services, Office for Civil Rights. Retrieved October 6, 2026, from https://www.fqhctalent.com/intel/hhs-ocr-ambry-genetics-phishing-settlement-700k-september-2026
More in Risk & Compliance
Sep 29
HHS civil rights office says when states can use substance use records
Sep 25
CMS and 37 states pledge to judge Medicaid by health outcomes
Sep 24
Geiger Gibson review finds health centers expect a heavy work-rule frailty burden
Sep 24
CMS seeks input on Part D pharmacy contract terms, including 340B claims