Evidence: officially disclosed. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 048
- Date / range
- 2020
- Sector
- Consumer genetics and commercial data
- Genetic asset
- Employee email messages and attachments
- Security principle
- Unstructured Communications Are Genetic Data Stores
Event summary
Ambry Genetics disclosed unauthorized access to an employee email account in 2020, illustrating how sensitive patient and genetic-testing information may escape purpose-built databases and accumulate in ordinary communications systems.
Source: oag.ca.gov — Ambry Genetics Email-Account Breach source 1.
The case in context
The Ambry incident concerns an employee mailbox rather than an assumed breach of every laboratory system. Messages and attachments can become a second store of sensitive information even when the organization maintains a dedicated clinical platform.
The affected fields must be established from the notice for the relevant people. A mailbox associated with a genetics organization does not imply that every record contains a genetic result. The useful architectural lesson is to include communications, retention, and attachment handling in the data inventory instead of drawing the boundary around the main database alone.
Acquisition and processing
phished/compromised mailbox → messages and attachments → patient/account/insurance or testing information → unauthorized access → notification/litigation
The sequence of events
- phished/compromised mailbox
- messages and attachments
- patient/account/insurance or testing information
- unauthorized access
- notification/litigation
What became inferable or exposed
Employee email messages and attachments
Ambry Genetics disclosed unauthorized access to an employee email account in 2020, illustrating how sensitive patient and genetic-testing information may escape purpose-built databases and accumulate in ordinary communications systems.
Affected parties and consent
- Direct parties
- People whose information appeared in the affected mailbox
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Security dimensions
Confidentiality
The confidentiality question concerns employee email messages and attachments. Exposure and further inference must be distinguished from the fact of collection or availability.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Unstructured Communications Are Genetic Data Stores identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows employee email messages and attachments through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality high; integrity moderate; availability low; provenance moderate; consent high.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-1/2 if genetic reports were involved; otherwise classify by confirmed fields. Suggested GPR: GPR-2 to 5. Suggested GPI: GPI-2.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
The notice does not establish that raw genomes, every test result, or every customer’s data was accessed.
Mitigations and lessons
- Phishing-resistant MFA
- Mailbox retention limits
- Attachment controls
- Secure portals
- DLP
- Least privilege
- Token/session monitoring
- Field-level incident scoping
Primary sources
- PRIMARY SOURCE oag.ca.gov — Ambry Genetics Email-Account Breach source 1
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-048. Ambry Genetics: A Mailbox Became a Clinical-Genetics Exposure. GeneticSecurity.org. https://geneticsecurity.org/cases/048-ambry-genetics-email-breach/