30,000-plus veterans affected by Baylor Genetics’ cybersecurity breach
A cybersecurity breach at Baylor Genetics, a VA contractor, exposed personal health information of more than 30,000 veterans in June. The Department of Veterans Affairs determined Baylor’s breach notification process did not meet VA expectations and revised the contractor’s Interconnection…
Cabrillo Club
Editorial Team · September 21, 2026 · 4 min read

Also in this intelligence package
TL;DR
A cybersecurity breach at Baylor Genetics, a VA contractor, exposed personal health information of more than 30,000 veterans in June. The Department of Veterans Affairs determined Baylor’s breach notification process did not meet VA expectations and revised the contractor’s Interconnection Security Agreement (ISA) to address delays in breach-related information sharing. The VA action signals heightened scrutiny of contractor cybersecurity obligations and notification requirements and creates immediate compliance and operational risk for contractors that handle veteran data. Contractors in healthcare IT, medical laboratory and genetic testing services, cybersecurity, and related IT services should treat this as a trigger to review ISAs, incident response plans, and contract notification processes. Expect increased VA oversight and potential contract-level changes that could affect ongoing and future work.
Key Points
- What happened: A cybersecurity breach at Baylor Genetics exposed personal health information for over 30,000 veterans; VA found the contractor’s notification process did not meet expectations and revised the contractor’s Interconnection Security Agreement to address delays in breach-related information sharing.
- Who is affected: Healthcare IT, Cybersecurity, Medical Laboratory Services, Genetic Testing Services, Veterans Healthcare, Health Information Management, IT Services; NAICS and agency segments in the event segmentation.
- Timeline: The breach occurred in June; VA revised the ISA following its review.
- What contractors should do NOW: Immediately review existing ISAs and notification clauses with the VA, validate incident response and breach-notification procedures against applicable compliance regimes, notify internal stakeholders (CISO, contracting officer representative, BD/capture, legal/compliance), and use Cabrillo Signals products to rescore pipelines and monitor for VA follow-on actions.
Who Is Affected
Affected market segments and compliance surfaces are explicit in event segmentation:
- NAICS: 621511, 541512, 541519, 541690, 621399, 541715
- Agencies: VA, DOD, HHS
- Contract vehicles: VA FSS, T4NG, VETS 2
- Market segments: Healthcare IT, Cybersecurity, Medical Laboratory Services, Genetic Testing Services, Veterans Healthcare, Health Information Management, IT Services
- Compliance surfaces: HIPAA, NIST 800-171 (NIST Special Publication 800-171), FISMA, FedRAMP (Federal Risk and Authorization Management Program), DFARS (Defense Federal Acquisition Regulation Supplement) 252.204-7012, Interconnection Security Agreement (ISA)
Frequently Asked Questions
Q: What specific change did the VA make after the Baylor Genetics breach?
A: The VA revised Baylor Genetics’ Interconnection Security Agreement to address delays in breach-related information sharing. For full ISA changes and language, pending source review.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →
Q: Does this affect other contractors beyond Baylor Genetics?
A: Yes. The incident highlights increased VA scrutiny of contractor cybersecurity obligations and notification requirements and has potential implications for all contractors handling veteran data.
Q: What immediate compliance actions should contractors take to reduce risk?
A: Immediate actions include reviewing ISAs and contract notification clauses with agency contracting officers, validating incident response playbooks against applicable compliance regimes (e.g., HIPAA, NIST 800-171, DFARS 252.204-7012), and confirming internal escalation paths for breaches. Specific contractual or timeline obligations are pending source review.
Definitions
- Baylor Genetics: The contractor named in the event whose systems were breached, exposing veteran personal health information.
- Interconnection Security Agreement (ISA): A formal agreement that defines the technical and security requirements for connections between information systems, here revised by the VA to address breach-notification delays.
- Cybersecurity breach: An incident resulting in unauthorized access to systems or data — in this event, exposure of personal health information for veterans.
Intelligence Response
- Cabrillo Signals War Room — Already detected this event and delivered this briefing. Continuously monitors regulatory changes, contract vehicles, and policy shifts to surface high-severity contractor-impact events.
- Cabrillo Signals Match Engine — Automatically rescored affected opportunity pipelines and reprioritized live pursuits where VA scrutiny may change win probability.
- Cabrillo Signals Intelligence Hub — Tracking the named agencies, NAICS codes, and contract vehicles from the segmentation. Saved searches and alerts are configured to notify when related solicitations, amendments, or ISA updates appear on SAM.gov (System for Award Management).
- Proposal Studio (Proposal OS) — Prepared to generate compliance matrices and bid/no-bid assessments tied to the incident’s compliance surfaces.
- Proposal Studio Workflow Tracker — Can be used to enforce accelerated capture gating and audit-ready documentation for any rapid-response proposals.
Who to notify internally: CISO/Cybersecurity Lead — immediate risk and remediation; Contracts/COO/COR — to review ISA and notification obligations; Legal/Privacy Officer — HIPAA and breach-notification counsel; Business Development/Capture — to reassess pipelines and pursue amended/rapid procurements.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →
First 48-hour playbook (high-level):
- Hour 0-4: Convene incident leadership call (CISO, Legal, Contracts, BD). Confirm whether the organization holds VA ISAs or connects to VA systems. Isolate any suspected compromise and preserve logs.
- Hour 4-12: Review ISA/contract notification clauses and gather evidence for potential reporting. Initiate statutory/contractual notification timelines where applicable. Configure Cabrillo Signals War Room alerts and run Match Engine rescoring on active pursuits.
- Hour 12-24: Prepare stakeholder communications and compliance status brief for contracting officers and internal leadership. Use Proposal Studio to map compliance obligations to current contracts and proposals.
- Hour 24-48: Execute remediation and monitoring plan; update capture strategy and pipeline priorities via Match Engine and Intelligence Hub saved searches. Document all actions in the Proposal Studio Workflow Tracker for audit readiness.
Reference materials: Secure Operations Guide (/insights/secure-operations-guide). Also review CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide) for controls mapping and secure CRM practices relevant to DoD (Department of Defense)/VA engagements.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.