READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

At-Home DNA Tests May Not Be Covered by HIPAA, and Your Genetic Data Can Be Shared More Broadly Than You Think

At-Home DNA Tests May Not Be Covered by HIPAA, and Your Genetic Data Can Be Shared More Broadly Than You Think
Millions of Americans have mailed off spit tubes and finger-prick samples without reading the fine print. A ZDNET review of ten major direct-to-consumer testing companies published June 13, 2026 found that HIPAA coverage is inconsistent, law enforcement data-sharing policies vary, and FDA review often applies only to specific tests rather than the whole service.

Since this outlet's June 13 coverage of wearables and health-data privacy, a parallel set of risks has been documented for the at-home DNA and biomarker testing market, a sector that has grown large enough that ten companies now compete for your spit sample and your credit card number.

What the fine print actually says

ZDNET senior contributing editor Elyse Betters Picaro read the privacy policies and terms of service for ten companies: Everlywell, LetsGetChecked, Labcorp OnDemand, Nebula Genomics / DNA Complete, Nucleus, SiPhox, myLAB Box, CircleDNA, SelfDecode, and 23andMe. The report was published June 13, 2026.

The headline finding: HIPAA coverage is NOT guaranteed. Some companies claim to be HIPAA-compliant; others do not. That distinction matters because HIPAA sets binding rules on how health data can be used, shared, and protected. If a company falls outside it, your genetic results may be governed only by their own privacy policy, which they can update.

Almost all ten companies cited CLIA-certified or CAP-accredited labs. Those are real quality standards for the laboratory work itself. They say nothing about what happens to your data after the test is processed.

FDA review is narrower than most people assume

When FDA language appeared in company materials, Picaro found it was usually tied to a specific test, report, or collection kit, not the company or service as a whole. A consumer who sees "FDA" anywhere in the marketing and assumes blanket federal oversight is making a significant inferential leap the fine print does not support.

Direct-to-consumer tests occupy a regulatory gray zone. The FDA has cleared or authorized certain genetic tests; it has not comprehensively regulated the industry's data practices.

Law enforcement, advertising, research

Picaro also probed three specific questions most consumers never think to ask: Can this company share my data with law enforcement? Can it use my data for advertising? Can it sell or license my data for research?

The answers varied by company, and they lived deep in policies most people never read. The ZDNET report does not name which specific company allows which specific practice, because that level of detail requires reading the full published piece. What the reporting establishes is that those practices exist somewhere in the set of ten reviewed companies, and that consumers routinely consent to them by checking a box.

Genetic data carries one risk that ordinary health data does not: it implicates people who never consented. If you submit your genome, you are partially submitting your parents', your siblings', and your children's genetic information too. A law enforcement query, an insurance underwriter's curiosity, or a research partner's dataset does not stop at you.

The strongest concern from the other direction

Defenders of the direct-to-consumer testing industry make a legitimate point. These services have genuinely democratized health information. People without insurance, people in rural areas with limited specialist access, and people managing chronic conditions have used these tests to catch real problems earlier than they otherwise would have. Restricting or over-regulating them carries a real cost in delayed diagnoses and reduced patient agency. The argument is not frivolous.

Democratizing health information does not require democratizing data collection without meaningful disclosure. The issue Picaro's reporting identifies is not that the tests exist, but that the consent architecture is buried in fine print rather than disclosed plainly at the point of purchase.

Counseling and follow-up vary widely

Beyond data privacy, the ZDNET review flagged a clinical concern: whether a medical professional explains the results to you differs significantly across companies. Some offer or require genetic counseling; others return results through a portal with no follow-up mechanism. A consumer learning they carry a BRCA variant or a predisposition to early-onset Alzheimer's with no guidance on what to do next is not a hypothetical. It is a documented pattern in the field.

What remains unresolved

The practical question from Picaro's reporting is whether any of the ten reviewed companies will update their policies in response to the coverage, and whether the FTC, which has jurisdiction over deceptive trade practices, will treat inconsistent HIPAA claims as an enforcement priority. The FTC's 2023 policy statement on health breach notifications extended some protections to health apps not covered by HIPAA, but direct-to-consumer genetic testing companies have not been the subject of a coordinated enforcement action as of June 13, 2026.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ZDNETI read the fine print on at-home DNA and health tests - watch out for these risks
center
ForbesWhat To Know About The Privacy Risks Of At-Home DNA Tests
center-left
NBC NewsAre At-Home DNA Tests Safe? Understanding the Privacy Risks
center-left
Scientific AmericanThe Long-Term Privacy Implications of At-Home DNA Testing