5.5 Privacy, Confidentiality, Documentation & Genomic Data Security

Key Takeaways

  • HIPAA Privacy and Security Rules treat genetic information as protected health information (PHI) when held by covered entities/business associates—governing use, disclosure, and safeguards.
  • Genetic counseling documentation must be accurate, timely, and sufficient to support clinical care, medical necessity, and continuity—without speculative or judgmental language.
  • Confidentiality can tension with duties to warn or protect identifiable third parties; genetics cases are taught as counseling/legal-awareness frameworks (Tarasoff-adjacent), not as license to give legal advice.
  • Genomic data security includes access controls, minimum necessary use, secure transmission/storage, vendor/BA agreements, and caution with email, portals, and research repositories.
  • Board items reward the best next privacy/documentation/security action—not absolute secrecy promises or casual oversharing with relatives or employers.
Last updated: August 2026

Privacy and security as everyday genetic counseling practice

After GINA’s non-discrimination frame (5.4), Domain 5C turns to how genetic information is handled: who may see it, how it is recorded, when confidentiality yields to competing duties, and how genomic data are secured. The Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules are the federal backbone for covered entities (health plans, most providers, clearinghouses) and their business associates.

On the CGC exam, privacy stems rarely ask you to recite regulatory subsection numbers. They ask whether you recognize PHI, apply minimum necessary thinking, document appropriately, avoid improper disclosures, and respond wisely when a client refuses to tell at-risk relatives.

HIPAA applied to genetic information

Protected health information (PHI) includes individually identifiable health information held or transmitted by a covered entity/business associate. Genetic test results, pedigrees with identifiers, counseling notes, and billing details tied to an individual are classic PHI.

HIPAA conceptPractical meaning in geneticsExam cue
Privacy RuleLimits uses/disclosures of PHI; grants patient rights (access, amendments, accounting in defined ways)Can we release results to a relative without authorization?
Security RuleAdministrative, physical, and technical safeguards for electronic PHI (ePHI)Portal access, encryption, workstation policies
Minimum necessaryUse/disclose only what is needed for the purposeSending an entire chart when a result summary suffices
AuthorizationPatient permission for many non-treatment/payment/operations disclosuresEmployer, life insurer, or curious relative requests
Business associateVendors handling PHI (labs’ portals, cloud EHR, billing firms) need appropriate agreements/safeguardsWho hosts the genomic data?

Genetic information is not “extra-secret HIPAA” by default—but it is sensitive

HIPAA does not create a separate “genetic-only” statute that replaces the Privacy Rule; genetic information is generally handled as PHI with heightened clinical sensitivity. Additional state genetic-privacy laws may impose stricter consent or disclosure rules—acknowledge without inventing statutes (same discipline as GINA state-law teaching).

Treatment, payment, and health-care operations (TPO) disclosures among involved clinicians often proceed under HIPAA without a separate authorization, but “involved” is not unlimited: do not email identifiable results to a relative who is not the patient, post pedigrees to social media, or discuss cases in public spaces.

Documentation standards for genetic counseling

Medical documentation in genetics supports clinical care, continuity, billing/medical necessity, risk management, and patient access rights. High-yield documentation content:

  1. Indication and history — phenotype, family history summary, prior testing.
  2. Counseling provided — risks/benefits/limitations discussed; psychosocial issues; decision aids used.
  3. Informed consent elements for testing (what was ordered, alternatives, residual risk, result types including VUS).
  4. Results disclosure — what was communicated, patient understanding, follow-up plan, cascade recommendations.
  5. Resources and referrals offered.
  6. Privacy/GINA discussion when material to the decision (protections and gaps).
Documentation practicePreferredRisky / exam distractor
ToneObjective, specific, respectfulPejorative labels (“noncompliant,” “difficult”) without clinical facts
UncertaintyDocument residual risk and VUS counselingImplying certainty the science does not support
Family historyRecord what was reported and limitationsFabricating relatives to meet testing criteria
DisclosuresNote authorizations and what was released“Told sister everything” without patient direction/authority
AmendmentsFollow institutional process for correctionsQuietly altering notes to hide an error

Documentation is discoverable in legal and regulatory processes. Write as if a future clinician—and a future reviewer—must understand the care.

Confidentiality vs duty to warn: genetics awareness (not legal advice)

Genetics uniquely implicates blood relatives. A client may refuse to share a pathogenic variant that would change a sibling’s screening. Classic teaching draws on Tarasoff-adjacent duty-to-warn/protect ideas from mental-health case law and later genetics literature (e.g., discussions around warning identifiable at-risk relatives). For OpenExamPrep/CGC purposes:

  • Frame this as counseling and legal-awareness, not as authorizing you to practice law or to declare a universal mandatory warning rule in every jurisdiction.
  • Typical clinical pathway: explore barriers, offer support for disclosure, provide letters relatives can use, involve supervising clinicians/ethics/legal resources per institution when refusal creates serious preventable harm to identifiable third parties.
  • Jurisdictions and institutional policies vary. Boards reward process: protect privacy by default, escalate appropriately, document efforts, avoid unilateral gossip to relatives as the first move.
ApproachWhen it fitsWhy
Supportive disclosure counselingMost refusal casesPreserves autonomy and often succeeds
Written tools for relativesPatient agrees to indirect sharingMaintains accuracy of medical facts
Ethics/legal consultHigh-stakes preventable harm + persistent refusalPolicy and law are local
Immediate unauthorized call to a relativeAlmost never the first board answerBypasses privacy process and role limits

Emphasize: you are not giving the examinee legal advice to break confidentiality casually. You are teaching recognition of the tension and professional escalation.

Genomic data security basics

Genomic datasets are identifiable or re-identifiable, large, and often shared across labs, EHRs, research repositories, and patient portals. Security literacy for counselors:

  • Access controls — unique logins, role-based access, no shared passwords.
  • Secure channels — prefer approved portals/EHR messaging over consumer email for results; if email is used, follow institutional encryption/policy.
  • Device hygiene — lock screens, avoid PHI on personal devices unless approved.
  • Minimum necessary downloads — do not export full VCFs to USB “for convenience.”
  • Vendor awareness — laboratories and software vendors are often business associates; breaches can affect thousands of examinees.
  • Secondary use caution — research repositories and data-sharing require consent/IRB pathways (see 5.6), not silent clinical reuse.
  • Breach response — know to report suspected incidents immediately through institutional channels.
RiskExampleMitigation
Misdirected disclosureResults faxed to wrong clinicVerify identifiers; confirm fax/portal destination
Oversharing in family sessionsDiscussing one relative’s result with another present without permissionSeparate encounters; explicit permission
Portal account sharingSpouse uses patient’s login indefinitelyCounsel on account control; document authorized representatives properly
Unsecured slidesPedigree with names left on conference laptopDe-identify teaching cases

Integrated scenarios

Scenario A — relative request: A patient’s sister calls asking for the patient’s BRCA result “because we’re family.” Best action: explain you cannot disclose the patient’s PHI without appropriate authorization; offer to help the patient share or provide a release process—not read the result over the phone.

Scenario B — employer letter: Employer requests “all genetic records” after a workplace wellness dispute. Best action: do not release without valid authorization and institutional review; GINA/employment issues may also apply (5.4)—privacy release and non-discrimination are related but distinct.

Scenario C — refusal to inform: Client with a highly penetrant pathogenic variant refuses to tell an identical twin. Best process: explore barriers, offer assistance, document, and involve supervising clinician/ethics/legal resources per policy when serious identifiable harm is at stake—not an immediate unauthorized disclosure as the default first step.

Scenario D — security: Counselor downloads identifiable exome files to a personal laptop to finish a letter at a café on public Wi-Fi. This fails Security Rule/practical security expectations; use approved systems and secure environments.

Common traps

  • Disclosing PHI to relatives or employers without authorization because “they deserve to know.”
  • Promising absolute secrecy that conflicts with mandatory reporting or institutional safety policies.
  • Charting speculative blame or altering notes improperly.
  • Treating genomic files as ordinary attachments without safeguards.
  • Confusing HIPAA privacy with GINA non-discrimination (both may apply; they answer different questions).
  • Giving definitive legal instructions about Tarasoff duties as if one nationwide genetics rule exists.

Quick exam checklist

  • Is the requestor the patient or a third party? Authorization needed?
  • Does documentation support care, consent, and follow-up without harmful language?
  • If relatives are at risk and the patient refuses, did I counsel, document, and escalate—not freelance disclose?
  • Are genomic data handled with minimum necessary access and secure systems?
  • Am I separating privacy (HIPAA), non-discrimination (GINA), and research rules (Common Rule)?
Test Your Knowledge

A patient’s adult sibling calls the genetics clinic requesting the patient’s multigene panel result to guide their own screening. The patient has not signed an authorization. What is the most appropriate immediate action?

A
B
C
D
Test Your Knowledge

Which documentation practice best meets genetic counseling standards after disclosing a pathogenic variant?

A
B
C
D
Test Your Knowledge

A client refuses to inform an identifiable sibling who would clearly benefit from knowing a familial pathogenic variant. What is the best Domain 5C framing of the counselor’s role?

A
B
C
D
Test Your Knowledge

Which action best reflects genomic data security expectations for electronic protected health information?

A
B
C
D