PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Navigating Privacy Gaps and New Legal Requirements for Companies Processing Genetic Data

Posted on August 11, 2025 by Dissent

Tori Downey, Thora Johnson, Alyssa Wolfington, and Shannon Yavorsky of Orrick, Herrington & Sutcliffe write:

Interest in genetic data is on the rise, driven by the growth of direct-to-consumer (DTC) genetic testing and its value for AI in drug development and personalized medicine. Historically, gaps in privacy laws have sometimes left sensitive health information unprotected when individuals share it with companies outside the clinical setting. This issue has been brought into sharp relief with the 23andMe bankruptcy.

While HIPAA, at the federal level, generally protects health information, including genetic information, created and received by healthcare providers and health plans, it does not apply to data given to consumer genetics companies. Instead, consumers are treated as customers, not patients and plan enrollees, leaving their genetic information outside the reach of the nation’s strongest health data protections. The Genetic Information Nondiscrimination Act (GINA) offers some safeguards, but is limited to misuse by insurers or employers.

Moreover, state laws have also fallen short in filling the gaps in federal privacy protections. While twenty states have enacted comprehensive privacy laws, most of them do not prevent companies from selling genetic data in a bankruptcy proceeding.

Read more at JDSupra about recent and proposed laws to deal with the gaps between federal privacy laws and state laws.

No related posts.

Category: Laws

Post navigation

← Germany’s top court holds that police can only use spyware to investigate serious crimes
Site Behind Major SSN Leak Returns With Detailed Data on Millions: How to Opt Out →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States
  • India backs off mandatory ‘cyber safety’ app after surveillance backlash
  • Judge orders Trump administration to halt warrantless immigration arrests in District of Columbia

RSS Recent Posts at DataBreaches.net

  • UK Government Considers Computer Misuse Act Revision
  • Japan issues arrest warrant against teen suspected of cyberattack using AI
  • How old is the average hacker? What does a new research report suggest? (1)
  • Marquis data breach impacts over 74 US banks, credit unions
  • Virginia Twins Arrested for Conspiring to Destroy Government Databases
©2025 PogoWasRight.org. All rights reserved.