supply-chaintrade-pressNewsThe Broadside1 min read

Baylor Genetics breach exposes 30,000-plus veterans' health data

The VA says the contractor's June notification was late and incomplete, and rewrote the Interconnection Security Agreement in response.


TL;DR

A mid-June breach at VA genetic-testing contractor Baylor Genetics exposed names, dates of birth, medical testing information, lab test results, health insurance data, and partial Social Security numbers for over 30,000 veterans. The VA told congressional staff the company's initial notification "did not meet VA's expectations for timely, complete, and appropriately coordinated notifications," and revised Baylor's Interconnection Security Agreement to address delays in breach-information sharing. Baylor says it's not aware of any identity theft or fraud and that lab operations continued without interruption.

Baylor Genetics breach exposes 30,000-plus veterans' health data
Editorial illustration · drawn by The Broadside

The breach occurred around June 15, when an "unauthorized third party" accessed the data, according to a VA email viewed by FedScoop. Notification to Congress came three months later, on Monday. That lag isn't just the breach-to-disclosure gap, the VA's email makes clear it also reflects a contractor-side delay the agency found unacceptable.

The VA's response is procedural but pointed: a revised Interconnection Security Agreement and demands for an improved notification process. The ISA is the document that governs how the contractor and the agency share security-relevant information. Revising it post-breach signals the existing agreement either wasn't sufficient or wasn't followed.

The VAAR contains a liquidated-damages clause, 852.211-76, that applies when a contractor handling sensitive personal information fails to protect it. Whether that clause is in Baylor's contract and whether the VA will pursue it is unknown, but the mechanism exists: liquidated damages per affected individual to cover notification, breach analysis, and credit monitoring. The VA's email says it "advocated" for Baylor to provide free credit-monitoring services through IDX for affected veterans, a softer ask than the clause would compel.

Baylor, through a PR representative, says it "immediately secured our systems, engaged leading independent cybersecurity and forensic specialists, notified law enforcement, and implemented additional security measures." The company also says it's not aware of any identity theft, fraud, or misuse tied to the incident.

This is the third notable VA contractor data exposure FedScoop has reported in recent years, following a 2020 breach of 46,000 veterans' financial data and a 2022 incident where a contractor published source code containing credentials on GitHub. The pattern is the story: contractor-handled veteran data keeps getting exposed, and the agency's leverage sits in agreements it appears to enforce only after the fact.


Published ·Deep Fathom