5.8 Genomic Data Security, DTC Testing & Data Sharing

Key Takeaways

  • HIPAA applies to covered entities and their business associates; most direct-to-consumer genetic testing companies are neither, so consumer genomic data sits largely outside HIPAA protection.
  • The 23andMe Chapter 11 filing in March 2025 established that consumer genetic data can be treated as a saleable bankruptcy asset, prompting objections from a bipartisan coalition of state attorneys general.
  • Genomic data is inherently re-identifiable and is shared involuntarily with biological relatives, so an individual’s consent decision affects people who never consented.
  • Investigative genetic genealogy uses consumer genealogy databases to identify criminal suspects through distant relatives, a use most participants never anticipated.
  • The 21st Century Cures Act information blocking provisions mean genetic results may reach a patient portal before the counselor has called, which changes how disclosure is planned.
Last updated: August 2026

5.8 Genomic Data Security, DTC Testing & Data Sharing

Quick Answer: HIPAA does not reach most DTC companies. Consumer genetic data has been treated as a saleable bankruptcy asset (23andMe, March 2025) and has been breached (6.9 million accounts, 2023). Genomic data is re-identifiable and shared involuntarily with relatives. Investigative genetic genealogy uses genealogy databases to find suspects through cousins. Cures Act information blocking rules can release a result to the portal before your call.

Subdomain 5C lists genomic data security as its own sub-topic alongside privacy and confidentiality regulations. The distinction matters: privacy is about who may lawfully see a record, while data security is about what happens to a genome once it exists as a file that can be copied, sold, breached, or queried by someone the patient never met.

The protection gap: what HIPAA does not cover

SettingHIPAA applies?Governing rules
Hospital or clinic genetics serviceYes — covered entityHIPAA Privacy and Security Rules; state genetic privacy laws
Clinical laboratory performing an ordered testYes — covered entity or business associateSame, plus CLIA record requirements
Direct-to-consumer genetic testing companyUsually noCompany terms of service and privacy policy; FTC enforcement against unfair or deceptive practices; some state genetic privacy statutes
Third-party raw-data interpretation siteUsually noTerms of service; often minimal security commitments
Consumer genealogy matching databaseUsually noTerms of service and the site's law-enforcement policy

This is the single most consequential fact in the section. A patient who assumes "my genetic information is protected by HIPAA" is right about the clinic and usually wrong about the consumer product. GINA adds nothing here either: it addresses health insurance and employment discrimination, not the sale or breach of a consumer database.

What actually happened to consumer genomic data

The 23andMe sequence is now the standard teaching case, and candidates should be able to describe it without embellishment:

EventDetail
2023 credential-stuffing breachData associated with approximately 6.9 million customers exposed, including relative-matching information
March 2025 Chapter 11 filingThe company sought bankruptcy protection with the genetic data of roughly 15 million customers among its assets
June 2025 state objectionsA bipartisan coalition of state attorneys general objected in bankruptcy court to the sale of customers' genetic data without their knowledge or consent
July 2025 court-approved saleAssets sold for $305 million to TTAM Research Institute, a nonprofit founded by the company's co-founder, after negotiated privacy commitments including deletion rights, enhanced security requirements, and an advisory board
July 2026 multistate settlementA group of state attorneys general announced a settlement of bankruptcy claims arising from the 2023 breach

The durable lesson is not the company. It is that a consumer genomic database is a corporate asset that can be sold, and that the buyer's obligations depend on contracts and negotiated commitments rather than on health-privacy law. Pretest counseling for a patient considering consumer testing should include: what happens to the sample and the data if the company is acquired or dissolved, whether deletion is genuinely available, and whether the data will be used for research or shared with partners.

Why genomic data is different from other health data

  1. It is permanent. A password can be changed; a genome cannot.
  2. It is re-identifiable. Genomic data is not meaningfully de-identified by removing a name. Research has demonstrated that surnames can be inferred from Y-chromosome markers combined with public genealogy databases, and that individuals can be identified within aggregated datasets.
  3. It is familial. One person's decision to upload a profile exposes relatives who never consented — including future children. This makes genomic consent structurally different from consenting to share a blood pressure reading.
  4. It is dense. A genome file carries information about ancestry, relatedness, carrier status, disease predisposition, and pharmacogenomics simultaneously, most of which was not the reason it was generated.

Investigative genetic genealogy

Law enforcement can upload a crime-scene profile to consumer genealogy matching databases and identify a suspect through distant relatives, then narrow by traditional genealogy. Databases differ in their policies — some require affirmative opt-in for law-enforcement matching, others have permitted it by default — and the U.S. Department of Justice adopted an interim policy governing federal use of the technique. For counseling purposes: a person who uploads a profile to a matching database is making an identifiability decision for their extended family, and that is worth saying out loud before the upload rather than after.

Research data sharing and its protections

MechanismWhat it does
Controlled-access repositoriesDatasets deposited for broad research use are released to approved investigators under data-use agreements rather than posted openly
Certificates of ConfidentialityProtect identifiable research information from compelled disclosure in most legal proceedings; issued automatically for NIH-funded research collecting identifiable, sensitive information
Broad consent under the revised Common RulePermits future unspecified secondary research use of identifiable data or biospecimens when consented for at collection
Data-use agreementsContractually bind secondary users to security and re-identification prohibitions

A Certificate of Confidentiality is a frequent exam distractor in both directions: it is not a guarantee of absolute secrecy — it does not prevent voluntary disclosure by the participant, mandated reporting, or disclosure for audit — and it is not something a clinical service can invoke to shield a medical record.

Immediate electronic release changes disclosure planning

Information blocking provisions under the 21st Century Cures Act require that electronic health information be made available to patients without unreasonable delay, which in practice means many laboratory results appear in the patient portal as soon as they are finalized. For genetics this is operationally significant: a patient may read "pathogenic variant detected in MLH1" on a phone at work before the counselor has called.

Practical responses that belong in the pretest conversation:

  • Tell the patient when and how results are expected to appear, including the portal.
  • Ask how they want to be contacted and agree on a plan if they see the result first.
  • Schedule the disclosure appointment relative to the expected result date, not after it.
  • Recognize that a patient's right of access is the default; the answer to "can we hide it until I call?" is generally no, and the workable answer is to get there first.

Everyday security practice

  • Do not export identifiable VCF or FASTQ files to personal devices or removable media.
  • Use institutional secure channels rather than consumer email or messaging for results.
  • Treat third-party variant-interpretation websites as data disclosures, not as tools — uploading a patient's file to one may transmit protected information outside the institution.
  • De-identify teaching cases and pedigrees before presentation, including dates and rare-condition combinations that make a family recognizable.
  • Report suspected incidents immediately through institutional channels; genomic breaches are not self-limiting.

Common traps

  • Telling a patient that HIPAA protects data held by a consumer genetic testing company.
  • Claiming that removing identifiers makes genomic data anonymous.
  • Treating a consumer database upload as a purely individual decision when it exposes relatives.
  • Describing a Certificate of Confidentiality as absolute protection.
  • Promising to withhold a result from the patient portal until after a counseling call.
  • Uploading patient sequence files to third-party interpretation sites without institutional review.
Test Your Knowledge

A patient asks whether the genetic data she submitted to a direct-to-consumer testing company is protected the same way as the results in her hospital record. What is the most accurate response?

A
B
C
D
Test Your Knowledge

What did the 2025 bankruptcy of a major consumer genetic testing company most clearly demonstrate about consumer genomic data?

A
B
C
D
Test Your Knowledge

A client is considering uploading his consumer genetic data file to a public genealogy matching database. Which counseling point is most important and most often overlooked?

A
B
C
D
Test Your Knowledge

A counselor orders a hereditary cancer panel and tells the patient, "I will make sure the result stays hidden in the system until I can call you." What is the problem with this plan?

A
B
C
D