On September 17, 2026, the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a Resolution Agreement with Ambry Genetics Corporation, a provider of genetic testing and clinical genomics services (Ambry), requiring payment of a $700,000 financial settlement and imposing a two-year corrective action plan (CAP).
Phishing attack led to a data breach
In January 2020, Ambry discovered that a threat actor compromised an Ambry email account via a phishing attack, potentially exfiltrating protected health information (PHI) of 225,370 individuals, including a number of sensitive identifiers such as Social Security numbers, driver’s license numbers, and financial information. Ambry reported the breach to OCR in March 2020. As organizations look to OCR enforcement to understand the agency’s priorities and, in particular, how large cyberattacks are handled from an enforcement perspective, it is important to remember that many of these investigations can take time and even span across administrations. The length of time between breach notification and enforcement remains a common theme in OCR investigations—often due to the complexity of these reviews as well as the volume of reported breaches and complaints alleging HIPAA violations.
Potential violations: more than just security risk analysis
Earlier this month, OCR Director Paula M. Stannard told attendees at a joint OCR/National Institute of Standards and Technology (NIST) conference, an organization’s lack of a compliant security risk analysis remains a “major concern” for OCR and “one of the most common compliance failures.” This echoes Director Stannard’s broader remarks on HIPAA Security Rule compliance made earlier this year. In the Ambry matter, OCR found that Ambry failed to conduct an accurate and thorough risk analysis of the risks and vulnerabilities to the electronic PHI (ePHI) it held. HIPAA-regulated organizations that have yet to conduct a risk analysis, or who are handling it internally without an outside vendor, can use the updated OCR/Office of the National Coordinator for Health Information Technology risk analysis tool to support their analysis.
While we know the focus OCR puts on its Risk Analysis Initiative, in the Ambry investigation, OCR also found that Ambry failed to implement procedures for terminating access to PHI when an individual’s employment ended or if access was no longer required. It also found that Ambry failed to assign unique names and numbers for tracking specific users in its electronic systems. Both are important security controls for HIPAA-regulated entities to ensure that only authorized individuals have access to ePHI.
Training: above and beyond the module
Ambry’s CAP requires the organization to ensure that its workforce members are trained on its Security Rule policies and procedures. The OCR release describing the Ambry enforcement emphasizes the need for “regular HIPAA training that is specific to the organization” and to the job duties of the applicable workforce members. HIPAA covered entities and business associates should ensure that their privacy, security, and breach notification training not only addresses the HIPAA requirements, but also the organization’s policies and procedures. HIPAA-regulated entities also should ensure that the training informs workforce members about how those requirements are implemented in the individuals’ particular roles.


