30,000-plus veterans affected by Baylor Genetics’ cybersecurity breach
A June cybersecurity breach at Baylor Genetics, a VA contractor, exposed personal health information for more than 30,000 veterans. The VA found Baylor’s notification process did not meet expectations and revised the company’s Interconnection Security Agreement to address delays in breach-related…
Cabrillo Club
Editorial Team · September 21, 2026 · 4 min read

Also in this intelligence package
Overview
A June cybersecurity breach at Baylor Genetics, a VA contractor, exposed personal health information for more than 30,000 veterans. The VA found that Baylor’s notification process did not meet expectations and revised the company’s Interconnection Security Agreement (ISA) to address delays in breach-related information sharing. This action signals increased VA scrutiny of contractor cybersecurity obligations and notification timelines, and it raises the likelihood of closer reviews of ISAs and reporting practices across vendors who handle veteran data. Contractors supporting the VA — and other agencies monitoring similar risks — should assume notification and interconnection requirements will be enforced more strictly. Now is the time to validate incident response and notification procedures, review contractual ISAs, and confirm alignment with named compliance regimes such as HIPAA, NIST 800-171 (NIST Special Publication 800-171), DFARS (Defense Federal Acquisition Regulation Supplement) 252.204-7012, FISMA, and FedRAMP (Federal Risk and Authorization Management Program). Use this Action Kit to prioritize immediate containment and communications, short-term remediation, and longer-term contractual and compliance updates.
Immediate Actions (This Week)
- [ ] Convene a cross-functional incident readiness brief (security, contracts, privacy, legal, and customer/account teams) to review current notification processes and escalation paths.
- [ ] Locate and review any Interconnection Security Agreements (ISAs), Business Associate Agreements (BAAs), and contractual incident-notification clauses relevant to VA and other agency customers; capture gaps that could delay information sharing.
- [ ] Validate your incident response playbook and notification templates against the stricter expectations signaled by the VA; prepare an updated rapid-notification checklist for potential breaches involving veteran data.
Short-Term Actions (30 Days)
- [ ] Remediate highest-priority gaps identified in ISAs and notification processes; produce proposed contract language or amendments to speed information sharing and approvals.
- [ ] Run an internal tabletop exercise that simulates a breach affecting veteran PHI, focusing on timeliness of notifications, coordination with agency contacts, and evidence capture for contract and regulatory review.
Long-Term Actions (90+ Days)
- [ ] Update standard contract clauses, supplier flow-down language, and template ISAs to reflect lessons learned and VA expectations; socialize changes with partners and subcontractors.
- [ ] Implement continuous monitoring and periodic drills tied to the named compliance regimes (HIPAA, NIST 800-171, DFARS 252.204-7012, FISMA, FedRAMP) and establish a recurring review cadence for ISAs and notification playbooks.
Compliance Checklist
- [ ] HIPAA — Confirm Business Associate Agreement (BAA) obligations, breach notification timelines, and privacy safeguards for protected health information.
- [ ] NIST 800-171 — Review and implement applicable NIST 800-171 controls for environments that support the affected data types.
- [ ] DFARS 252.204-7012 — Ensure DFARS clause flow-downs are present where applicable and incident reporting requirements are operationalized.
- [ ] FISMA — Verify system categorization and FISMA-related controls where agency requirements apply.
- [ ] FedRAMP — For cloud services, confirm FedRAMP authorization posture and that incident handling meets agency expectations.
- [ ] Interconnection Security Agreement (ISA) — Review and update ISA terms to eliminate unnecessary delays in breach-related information sharing and specify notification timelines and contact points.
Resources
- DFARS 252.204-7012 — Regulation text: TBD pending source review
- NIST SP 800-171 (NIST Special Publication 800-171) — Regulation text: TBD pending source review
- HIPAA — Regulation text: TBD pending source review
- FISMA — Regulation text: TBD pending source review
- FedRAMP — Guidance text: TBD pending source review
- VA guidance on ISAs and incident notification — Agency guidance: TBD pending source review
Related reading: Secure Operations Guide (/insights/secure-operations-guide) — see playbooks for incident handling and notification. Also consider CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide) for broader capture and proposal hygiene.
How Cabrillo Club Automates This
Cabrillo Signals War Room
- Cabrillo Signals War Room already detected this event and delivered this briefing within minutes. It continuously monitors federal sources for policy shifts, agency notices, and contract-vehicle changes so you receive alerts when the VA or other agencies publish updated guidance or ISA templates. For this incident, War Room provides normalized event context, a timeline of public statements, and flags for any follow-on VA communications.
Cabrillo Signals Match Engine
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →
- The Match Engine automatically rescales and reprioritizes your active opportunity pipeline when an event like this changes agency scrutiny or compliance weightings. It will adjust match scores and keyword relevance for opportunities serving VA, DOD, and HHS customers and surface solicitations where ISA or tighter notification requirements become evaluation factors.
Cabrillo Signals Intelligence Hub
- Use the Intelligence Hub to track the affected agencies and relevant NAICS codes and contract vehicles listed in your portfolio. Configure saved searches and alerts specifically for VA-related ISA updates, DFARS clause revisions, and solicitations on VA FSS, T4NG, VETS 2 (as applicable to your targets). The Hub centralizes documents and links so teams can rapidly retrieve ISA language and agency notices.
Proposal Studio (Proposal OS)
- Proposal Studio automates creation of compliance matrices, incident-notification language, and first-draft technical approaches that reflect the heightened VA expectations and named compliance regimes. It pulls your past performance entries, generates suggested BAA/ISA clauses, and helps produce bid/no-bid guidance factoring in the updated risk posture.
Proposal Studio Workflow Tracker
- The Workflow Tracker enforces a capture sequence (including an expedited compliance-review gate) so contracts and legal teams sign off on ISA language and notification commitments before proposal submission. It creates an audit-ready package documenting approvals, supplier certifications, and tabletop exercise records.
Call to action: Log into your Cabrillo dashboard to review the War Room brief, run updated Match Engine scans for your pipeline, and start a Proposal Studio draft that incorporates revised ISA and notification language.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.