Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
At-Home DNA Tests May Not Be Covered by HIPAA, and Your Genetic Data Can Be Shared More Broadly Than You Think

Since this outlet's June 13 coverage of wearables and health-data privacy, a parallel set of risks has been documented for the at-home DNA and biomarker testing market, a sector that has grown large enough that ten companies now compete for your spit sample and your credit card number.
What the fine print actually says
ZDNET senior contributing editor Elyse Betters Picaro read the privacy policies and terms of service for ten companies: Everlywell, LetsGetChecked, Labcorp OnDemand, Nebula Genomics / DNA Complete, Nucleus, SiPhox, myLAB Box, CircleDNA, SelfDecode, and 23andMe. The report was published June 13, 2026.
The headline finding: HIPAA coverage is NOT guaranteed. Some companies claim to be HIPAA-compliant; others do not. That distinction matters because HIPAA sets binding rules on how health data can be used, shared, and protected. If a company falls outside it, your genetic results may be governed only by their own privacy policy, which they can update.
Almost all ten companies cited CLIA-certified or CAP-accredited labs. Those are real quality standards for the laboratory work itself. They say nothing about what happens to your data after the test is processed.
FDA review is narrower than most people assume
When FDA language appeared in company materials, Picaro found it was usually tied to a specific test, report, or collection kit, not the company or service as a whole. A consumer who sees "FDA" anywhere in the marketing and assumes blanket federal oversight is making a significant inferential leap the fine print does not support.
Direct-to-consumer tests occupy a regulatory gray zone. The FDA has cleared or authorized certain genetic tests; it has not comprehensively regulated the industry's data practices.
Law enforcement, advertising, research
Picaro also probed three specific questions most consumers never think to ask: Can this company share my data with law enforcement? Can it use my data for advertising? Can it sell or license my data for research?
The answers varied by company, and they lived deep in policies most people never read. The ZDNET report does not name which specific company allows which specific practice, because that level of detail requires reading the full published piece. What the reporting establishes is that those practices exist somewhere in the set of ten reviewed companies, and that consumers routinely consent to them by checking a box.
Genetic data carries one risk that ordinary health data does not: it implicates people who never consented. If you submit your genome, you are partially submitting your parents', your siblings', and your children's genetic information too. A law enforcement query, an insurance underwriter's curiosity, or a research partner's dataset does not stop at you.
The strongest concern from the other direction
Defenders of the direct-to-consumer testing industry make a legitimate point. These services have genuinely democratized health information. People without insurance, people in rural areas with limited specialist access, and people managing chronic conditions have used these tests to catch real problems earlier than they otherwise would have. Restricting or over-regulating them carries a real cost in delayed diagnoses and reduced patient agency. The argument is not frivolous.
Democratizing health information does not require democratizing data collection without meaningful disclosure. The issue Picaro's reporting identifies is not that the tests exist, but that the consent architecture is buried in fine print rather than disclosed plainly at the point of purchase.
Counseling and follow-up vary widely
Beyond data privacy, the ZDNET review flagged a clinical concern: whether a medical professional explains the results to you differs significantly across companies. Some offer or require genetic counseling; others return results through a portal with no follow-up mechanism. A consumer learning they carry a BRCA variant or a predisposition to early-onset Alzheimer's with no guidance on what to do next is not a hypothetical. It is a documented pattern in the field.
What remains unresolved
The practical question from Picaro's reporting is whether any of the ten reviewed companies will update their policies in response to the coverage, and whether the FTC, which has jurisdiction over deceptive trade practices, will treat inconsistent HIPAA claims as an enforcement priority. The FTC's 2023 policy statement on health breach notifications extended some protections to health apps not covered by HIPAA, but direct-to-consumer genetic testing companies have not been the subject of a coordinated enforcement action as of June 13, 2026.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.