Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic testing and clinical genomics company Ambry Genetics Corporation have agreed to a settlement to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA). Ambry Genetics has agreed to pay a $700,000 financial penalty and adopt a corrective action plan to address the areas of noncompliance identified by OCR during its investigation of a breach of the electronic protected health information (ePHI) of 225,370 individuals.
The data breach was reported to OCR on March 22, 2020, initially as involving the protected health information of 232,772 individuals, although the total was later updated to 225,370 individuals. Ambry Genetics identified suspicious activity within its email environment on January 22, 2020, and its forensic investigation determined that an unauthorized third party gained access to an employee’s email account as a result of a response to a phishing email. The account was accessed by a criminal actor between January 22 and January 24, 2020, exposing names, addresses, dates of birth, driver’s license numbers, diagnosis/condition information, medications, treatment information, and some Social Security numbers.
OCR investigates all data breaches affecting 500 or more individuals and launched an investigation after being informed about the phishing-related data breach. OCR determined that Ambry Genetics failed to conduct an accurate and thorough risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
In addition, there was a failure to implement policies and procedures for terminating access to ePHI when the employment of members of the workforce was terminated, or access to ePHI was otherwise no longer required. Unique usernames had not been assigned to all members of the workforce who required access to ePHI to allow them to be identified and their interactions with ePHI to be tracked.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
OCR notified Ambry Genetics of the findings of the investigation and the intention to impose a financial penalty, along with an offer to settle the alleged HIPAA violations informally. Ambry Genetics accepted and agreed to settle the alleged HIPAA violations with a $700,000 financial penalty and a corrective action plan to ensure full compliance with the HIPAA Rules. Ambry Genetics will be monitored for compliance with the corrective action plan for a period of two years.
The corrective action plan requires Ambry Genetics to conduct a comprehensive and accurate risk analysis and develop and implement a risk management program to reduce and mitigate the risks identified by the risk analysis. Policies and procedures must be developed to ensure compliance with the HIPAA Security Rule and other HIPAA policies and procedures, and all members of the workforce must be assigned unique identification to allow their activity to be tracked in information systems containing ePHI. All workforce members must receive HIPAA training on the policies and procedures. The phishing attack has proven costly for Ambry Genetics. Ambry Genetics faced class action litigation over the data breach and settled the lawsuit for $12.25 million.
“Email phishing is a common cyberattack that can lead to a breach of PHI and reveal HIPAA Security Rule deficiencies,” said OCR Director Paula M. Stannard. “Conducting a compliant risk analysis, engaging in risk management, and full implementation of the Security Rule provisions continue to be the foundation for effective cybersecurity and the best cyber defense.” This is the 10th financial penalty to be imposed by OCR this year to resolve alleged violations of the HIPAA Rules, and its 188th penalty to date. All but one of this year’s penalties have resolved risk analysis failures. So far this year, OCR has collected $3,030,250 in HIPAA fines.


