Back to articles
Healthcare Operations

Ambry Genetics HIPAA Settlement Highlights Why Security Risk Analyses Remain the Foundation of Compliance

Dr. Jose I. Delgado
5 min read
HIPAA SRA and P&P

Healthcare organizations continue to face phishing, credential theft, ransomware, cloud-security concerns, and other threats to electronic protected health information (ePHI). When a breach occurs, however, federal regulators do not look only at the attack itself. They also examine whether the organization had identified foreseeable risks, implemented appropriate safeguards, and documented its security management process before the incident.

The September 17, 2026 settlement announced by the U.S. Department of Health and Human Services Office for Civil Rights (OCR) involving Ambry Genetics Corporation is a strong example. The case reinforces a long-standing HIPAA Security Rule principle: an accurate and thorough Security Risk Analysis is a foundational part of protecting ePHI and demonstrating a functioning compliance program.

What Happened at Ambry Genetics?

Ambry Genetics, a California-based provider of genetic testing and clinical genomics services, discovered in January 2020 that an employee email account had been compromised through a phishing attack. According to OCR, the protected health information of 225,370 individuals was potentially exfiltrated. The information potentially included names, addresses, dates of birth, some Social Security or driver’s license numbers, financial information, diagnoses and conditions, laboratory results, medications, and treatment information.

Ambry reported the breach to HHS in March 2020. OCR then investigated not only the phishing incident, but also Ambry’s broader compliance with the HIPAA Security Rule.

What OCR Found

OCR identified potential violations in three important areas. The agency stated that Ambry potentially failed to conduct an accurate and thorough risk analysis of risks and vulnerabilities to ePHI, failed to implement procedures to terminate workforce access when access was no longer appropriate, and failed to assign unique user identification for systems containing ePHI.

Those findings matter because they show how a single cyber incident can expose wider governance and control gaps. A compromised account may be the event that draws attention, but an investigation can quickly expand to risk analysis, access management, identity controls, policies, workforce practices, and documentation.

The Settlement and Corrective Action Plan

To resolve the investigation, Ambry paid $700,000 to OCR and agreed to a corrective action plan that OCR will monitor for two years. The plan requires Ambry to conduct an accurate and thorough risk analysis, develop and implement a risk management plan, review and revise Security Rule policies and procedures as needed, implement unique user identification across systems containing ePHI, and train workforce members on Security Rule policies and procedures.

For healthcare leaders, that list is useful because it closely resembles the core activities organizations should maintain before a breach occurs, not only after OCR becomes involved.

Why the Security Risk Analysis Matters

A HIPAA Security Risk Analysis is not merely a vulnerability scan, penetration test, or IT checklist. The Security Rule requires regulated entities to assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI they create, receive, maintain, or transmit. OCR guidance describes risk analysis as the first step in identifying and implementing safeguards that comply with the Security Rule.

A meaningful analysis should account for where ePHI is located, how it enters and leaves the organization, which systems and vendors handle it, who has access, what threats and vulnerabilities exist, and what controls are already in place. The analysis should then feed a documented risk management process so leadership can prioritize corrective action.

Why Risk Analysis Must Evolve

Healthcare environments change constantly. Organizations add cloud applications, telehealth platforms, remote access, mobile devices, artificial intelligence tools, third-party integrations, and new vendor relationships. Workforce roles also change, and attackers continuously refine phishing and credential-theft techniques.

Because the environment changes, a risk analysis cannot be treated as a one-time compliance exercise. HHS guidance explains that the risk analysis process should be ongoing and updated as needed. A prior assessment may no longer reflect current workflows, systems, threats, or access patterns. The practical question is not simply whether an organization has an SRA on file, but whether the assessment accurately reflects the organization as it operates today.

Practical Actions for Healthcare Organizations

Healthcare leaders can use the Ambry case as a focused review point. Prioritize the following steps:

  1. Confirm the scope of ePHI. Identify where ePHI is created, received, maintained, transmitted, and shared with vendors or business associates.

  2. Review the current Security Risk Analysis. Make sure it reflects present-day systems, cloud services, remote access, telehealth, AI-enabled workflows, and other material changes.

  3. Connect findings to a risk management plan. Assign owners, priorities, target dates, and documented follow-up for identified vulnerabilities.

  4. Strengthen identity and access controls. Use unique user IDs, review permissions, and promptly terminate access when a workforce member leaves or no longer needs it.

  5. Review system activity. Maintain appropriate audit controls and routinely examine relevant system activity for unusual or unauthorized access.

  6. Train the workforce. Provide role-appropriate HIPAA Security Rule and cybersecurity training, including phishing awareness and incident reporting expectations.

  7. Learn from incidents. Incorporate lessons from security events into policies, procedures, training, and the broader security management process.

Compliance Connection

The Ambry settlement also illustrates the relationship between cybersecurity and compliance governance. Technical safeguards matter, but technology alone does not create a defensible security program. Leaders need documented policies, defined accountability, workforce training, regular review, and evidence that identified risks are being addressed.

Taino Consultants has worked with healthcare organizations for nearly three decades on HIPAA compliance and Security Risk Analyses. Its SRA approach is designed to evolve with OCR guidance, cloud technology, telehealth, cybersecurity threats, artificial intelligence adoption, and changing operational risks. The objective is to help organizations evaluate current conditions rather than rely on outdated checklists.

Conclusion

The Ambry Genetics settlement is a reminder that phishing is not only an email-security problem. It can reveal weaknesses in risk analysis, user access, identity management, training, documentation, and overall security governance.

Healthcare organizations should use the case as an opportunity to ask whether their current Security Risk Analysis reflects today’s systems, vendors, workforce, and threats, and whether identified risks are being tracked through a documented management process. A current SRA cannot prevent every cyber incident, but it can help an organization identify vulnerabilities earlier, prioritize safeguards, and demonstrate a deliberate approach to protecting ePHI.

Call to Action

Is your Security Risk Analysis current? Taino Consultants can help healthcare organizations review their HIPAA security posture, identify vulnerabilities, and develop practical risk-management priorities. Consider scheduling a HIPAA Security Risk Analysis review before a breach or regulatory inquiry exposes gaps for you.

About Dr. Jose I. Delgado

Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.

Need help with healthcare compliance?

Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.

Schedule a consultation