Genetic information held by a doctor, hospital, health plan, or healthcare clearinghouse is protected health information under the HIPAA Privacy Rule, which means it carries the same confidentiality protections as the rest of your medical record.1HHS.gov. Does the HIPAA Privacy Rule Protect Genetic Information? That treatment was locked in by a 2013 amendment implementing the Genetic Information Nondiscrimination Act (GINA), which classified genetic data as health information and barred health plans from using it for underwriting.2National Human Genome Research Institute. Privacy in Genomics The limit worth knowing up front: HIPAA only reaches certain organizations, so a large share of the genetic data collected today falls outside the law entirely.
What Counts as Genetic Information
The federal regulations define the term broadly. Under 45 CFR 160.103, four categories are protected when a HIPAA-covered organization holds them in identifiable form:3eCFR. 45 CFR 160.103 – Definitions
- Your own genetic tests, meaning any analysis of DNA, RNA, or chromosomes that looks for changes, mutations, or markers tied to disease or inherited traits.
- A relative’s genetic test results when they appear in your record, because those results reveal information about you.
- Family medical history, which providers routinely collect at intake and which counts as genetic information even though no lab work is involved.
- Requests for or receipt of genetic services, including counseling, education, or participation in research that includes genetic testing, whether or not a test is ever performed.
All four sit alongside diagnoses, prescriptions, and billing records as PHI. The same rules apply.
Who Has to Follow the Rules
HIPAA reaches three types of organizations, called covered entities: health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically for billing or similar transactions.3eCFR. 45 CFR 160.103 – Definitions Your primary care office, your insurer, and the hospital lab that runs your genetic test are all covered.
Any outside company that handles PHI on a covered entity’s behalf is a business associate. That includes billing services, cloud storage vendors that host electronic records, and independent labs processing samples for a hospital. Covered entities have to sign a written Business Associate Agreement with each of these partners requiring the same safeguards. That chain is what keeps genetic data protected after it leaves the doctor’s office.
Your Rights Over Genetic Records
When a covered entity holds your genetic information, the Privacy Rule gives you several concrete rights. They matter more for genetic data than for most other records, because genetic information is permanent and speaks to your relatives as well as to you.
You can request a copy of your genetic test results and any related information in your file, and the entity must provide records in the format you ask for if it can reasonably produce them that way, including electronic copies of electronic records.4eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
If you find an error, you can ask the entity to correct it. The entity has 60 days to respond and may take one 30-day extension with written notice.5eCFR. 45 CFR 164.526 – Amendment of Protected Health Information If the amendment is denied, you have the right to file a written statement of disagreement that then travels with your record.
You can also request an accounting of disclosures: a list of every time your genetic PHI was shared over the past six years for reasons other than treatment, payment, or healthcare operations.6eCFR. 45 CFR 164.528 – Accounting of Disclosures of Protected Health Information This is often the only way to surface a sharing you didn’t know about.
Beyond the exceptions described below, any other use or sharing of your genetic information requires your written authorization identifying what will be shared, with whom, and for what purpose.7eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required You can revoke that authorization in writing at any time, though the revocation doesn’t reverse disclosures already made.
The Ban on Using Genetic Information for Health Insurance Underwriting
Because GINA required it, HHS amended the Privacy Rule to bar covered health plans from using or disclosing genetic PHI for underwriting purposes. “Underwriting” covers eligibility, premium calculations, pre-existing condition exclusions, and any other activity connected to creating, renewing, or replacing a health insurance contract.8HHS.gov. Genetic Information
In practical terms, a health insurer cannot raise your premium because a genetic test showed you carry a BRCA mutation, and it cannot deny coverage because your family history shows a hereditary pattern. The protection applies to employer group plans, individual marketplace plans, and Medicare supplemental plans administered by private insurers.
What the ban does not cover is where many people get caught out. Life insurance, disability insurance, and long-term care insurance are not “health plans” under HIPAA, and GINA’s underwriting ban does not extend to them.9National Human Genome Research Institute. Genetic Discrimination An insurer writing a life policy can ask about genetic test results and use them to set premiums or deny coverage in most states. If you plan to apply for those products, the order in which you test and apply can matter.
When a Provider Can Share Genetic Data Without Asking You
HIPAA permits covered entities to use and disclose genetic PHI without authorization in a limited set of circumstances. These are the situations where your data can move without your signature on a release.
Treatment, Payment, and Operations
Your doctor can send genetic results to a specialist for a consult. A lab can transmit results to the ordering physician. Your health plan can receive enough information to process and pay a claim for a genetic test. These everyday healthcare functions don’t need your authorization.10eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations
Public Health
Covered entities may disclose genetic PHI to public health authorities legally authorized to receive reports for preventing or controlling disease, including some reporting of genetic conditions to state health departments and reporting of suspected child abuse or neglect.11HHS.gov. Disclosures for Public Health Activities
Courts and Law Enforcement
Genetic records can be disclosed in response to a court order or certain subpoenas, and law enforcement can obtain them under specific, narrower circumstances defined by the Privacy Rule. A police officer cannot simply demand a lab’s records; the request generally has to be backed by legal process or fit a defined exception, such as identifying a deceased person or reporting a crime that occurred on the entity’s premises.
Research
Researchers most often need your written authorization with specific elements: a description of the information, who will see it, the purpose, an expiration date, and notice of your right to revoke.12HHS.gov. Summary of the HIPAA Privacy Rule An Institutional Review Board or Privacy Board can waive the authorization requirement if it finds the research poses no more than minimal privacy risk, could not practicably be done with individual consent, and could not proceed without access to the PHI. Research using de-identified data or data from deceased individuals can bypass authorization entirely.
Where HIPAA Protection Stops
The most important thing to understand about HIPAA’s genetic protections is where they end. Several major categories of genetic data fall outside the law completely.
Direct-to-Consumer Testing Companies
Ancestry kits, wellness reports, and trait analyses sold directly to consumers are generally not covered by HIPAA. Those companies are not health plans or clearinghouses, and most do not bill insurance or run the electronic transactions that would make them covered providers. Mail a saliva sample to one of them, and the resulting data is governed by that company’s privacy policy and terms of service, not by federal health privacy law.1HHS.gov. Does the HIPAA Privacy Rule Protect Genetic Information?
Privacy policies can change, and some have. In 2023, the Federal Trade Commission charged 1Health.io (formerly Vitagene) with leaving raw genetic data of hundreds of consumers in publicly accessible cloud storage without encryption and retroactively changing its privacy policy to allow broader sharing of data it had already collected. The settlement required affirmative consent before sharing health data, an order to contract labs to destroy DNA samples retained more than 180 days, and a comprehensive security program.13Federal Trade Commission. FTC Says Genetic Testing Company 1Health Failed to Protect Privacy and Security of DNA Data and Unfairly Changed Its Privacy Policy
There is one federal backstop for breaches at these companies. The FTC’s Health Breach Notification Rule applies to vendors of personal health records that are not HIPAA-covered, and it explicitly includes services that track genetic information. A covered company that experiences a breach involving genetic data must notify affected individuals within 60 calendar days of discovering the breach, notify the FTC, and alert major media if 500 or more residents of any state are affected.14eCFR. 16 CFR Part 318 – Health Breach Notification Rule The rule creates accountability after a breach; it does not regulate day-to-day handling of the data.
Life, Disability, and Long-Term Care Insurance
This is the largest gap in federal genetic privacy law. GINA prohibits genetic discrimination in health insurance and employment, and HIPAA’s underwriting ban covers health plans, but none of that extends to life, disability, or long-term care insurance.9National Human Genome Research Institute. Genetic Discrimination An insurer evaluating an application for one of these products can ask whether you have had genetic testing and can factor the results into its decision. Some states have enacted their own restrictions; many have not.
Employer Decisions Outside Health Plan Administration
GINA prohibits employers from using genetic information in hiring, firing, promotion, and other employment decisions, and the Equal Employment Opportunity Commission enforces that.15U.S. Equal Employment Opportunity Commission. Genetic Information Discrimination HIPAA itself generally does not reach the employer’s workplace decisions; it applies to an employer only when it is acting as a health plan sponsor. An employer that improperly obtains an employee’s genetic information and uses it against them in the workplace is violating GINA, not HIPAA, and the complaint routes are different.
Filing a Complaint When the Rule Was Broken
HHS’s Office for Civil Rights (OCR) enforces the Privacy and Security Rules. If you believe a covered entity or business associate mishandled your genetic information, you can file a written complaint with OCR within 180 days of learning about the violation, though OCR can extend that deadline for good cause. Complaints can go through OCR’s online portal, by email to OCRComplaint@hhs.gov, or by mail, and must name the entity and describe what happened.16HHS.gov. How to File a Health Information Privacy or Security Complaint OCR does not investigate anonymous complaints, so you need to include your name and contact information, though OCR does not share that with the entity unless doing so is necessary for the investigation.