U.S. genetic privacy is protected by a patchwork of federal laws and state statutes rather than one unified code. The Genetic Information Nondiscrimination Act, HIPAA, and the Common Rule each cover specific contexts, such as employment, clinical records, and federally funded research, but substantial gaps remain for life and disability insurance, some direct-to-consumer testing arrangements, and certain forms of law enforcement access. Consumers who want stronger protection should review a testing company’s privacy policy closely, avoid uploading raw data to public genealogy platforms, and request clinician-ordered testing when HIPAA coverage matters.
TL;DR:
- Federal laws leave significant gaps in genetic privacy protections for life, disability, and long-term care insurance, which are not covered by GINA or HIPAA.
- State laws vary widely, with many extending restrictions beyond federal scope, such as prohibiting unauthorized testing and limiting law enforcement access, depending on the jurisdiction.
- The FTC actively enforces privacy protections through actions requiring companies to destroy genetic data and improve security, highlighting industry compliance risks.
- Law enforcement access to genetic data generally requires a legal warrant when data is stored in clinical records, but public genealogy platforms can be searched with a warrant or opt-in consent.
- Consumers should ask detailed questions about data retention, research use, law enforcement policies, and third-party sharing before testing to manage privacy risks effectively.
Table of Contents
- Federal laws that set the baseline for genetic privacy
- How much does your state actually protect your DNA?
- What happens when the FTC steps in on genetic privacy?
- Can law enforcement access your genetic data without your consent?
- Where GINA stops: insurance and employment gaps you should know
- A practical checklist before you take a genetic test
- What a clinical perspective adds to the privacy conversation
- Why the next decade of genetic privacy law needs a clearer federal floor
- US Diagnostics Center: privacy-aware testing options for your situation
- Sources
- FAQ
Federal laws that set the baseline for genetic privacy
Three federal frameworks do most of the legal work in this space, and each one covers a different slice of a person’s genetic life. Understanding where one law stops and another begins is the first step toward knowing whether a particular test, record, or data transfer is actually protected.
GINA, enacted in 2008, prohibits health insurers from using genetic information in underwriting decisions and bars employers from using it in hiring, firing, or promotion decisions. Title II of the statute applies to employers with 15 or more employees, which means small businesses below that threshold fall outside its employment protections even though the health insurance provisions apply more broadly. GINA does not touch life insurance, disability insurance, or long-term care insurance, a gap discussed in more detail below. It also does not regulate how a direct-to-consumer testing company stores, shares, or monetizes genetic data once a sample has been processed.
HIPAA’s Privacy Rule protects genetic information only when it is held by a “covered entity,” meaning a health plan, health care clearinghouse, or health care provider that transmits information electronically in connection with certain transactions. When a physician orders a genetic test as part of diagnosis or treatment, the resulting data becomes part of the patient’s protected health information and carries HIPAA’s restrictions on disclosure. Clinician-ordered DNA tests get HIPAA protection in a way that most consumer kits ordered directly online do not, because a typical direct-to-consumer company is not a covered entity under the statute. HIPAA also contains exceptions that allow disclosure without patient authorization in specific situations, including valid court orders, certain subpoenas, and public health reporting requirements. A peer-reviewed analysis of the “web of protections” surrounding genomic data confirms that HIPAA still permits disclosures under legal demands even when the data originated in a clinical setting, so HIPAA coverage reduces exposure without eliminating it entirely.
The Common Rule governs federally funded human subjects research and requires informed consent along with institutional review board oversight before genetic samples can be collected or analyzed for research purposes. Researchers can also apply for Certificates of Confidentiality, which add a further layer of protection by allowing investigators to resist compelled disclosure of identifiable research data in legal proceedings, including court orders. The National Human Genome Research Institute describes these federal research protections as one piece of a broader patchwork that also depends heavily on who holds the data and which state’s laws apply.
The practical contrast that matters most for everyday consumers is this:
- A test ordered by a physician for diagnostic purposes is typically protected as part of a HIPAA-covered medical record, with disclosure limited to the exceptions described above.
- A direct-to-consumer kit purchased online and processed outside a covered entity is generally governed by the company’s own privacy policy and by general consumer protection law, not by HIPAA.
- Data uploaded to a research study may gain Common Rule protections and, in some cases, a Certificate of Confidentiality, depending on the funding source and study design.
- Data uploaded to a public genealogy platform can lose most of these protections entirely, a point explored further in the law enforcement section below.
None of these frameworks were written specifically to anticipate today’s consumer genetic testing market, which is part of why NIH and academic reviewers consistently describe the current system as incomplete rather than comprehensive.
How much does your state actually protect your DNA?
Federal law sets a floor, not a ceiling, and most of the meaningful variation in genetic privacy protection happens at the state level. States have moved at different speeds and in different directions, so the practical answer to “is my DNA protected” often depends more on your zip code than on any single federal statute.
Many states have enacted laws that prohibit the unauthorized collection, retention, or analysis of a person’s DNA without consent, treating genetic material with some of the same legal weight as other sensitive personal data. A number of these statutes extend further than GINA by restricting insurers beyond the health insurance context GINA covers, reaching into areas like life or long-term care underwriting that federal law leaves open. Academic literature reviewing state genetic privacy statutes notes that several states create broad rights against disclosure “by any person,” not just by employers or insurers, and some attach criminal penalties to unauthorized acquisition or testing of a person’s genetic material without consent.
State approaches tend to differ along a few recurring lines:
- Scope of covered entities: Some states regulate only insurers and employers, while others extend obligations to testing companies, laboratories, and even individuals who obtain someone else’s DNA without permission.
- Retention and destruction rules: A handful of states require that genetic samples be destroyed or returned after a specified period or purpose has been fulfilled, while others leave retention terms entirely to the testing company’s own policy.
- Law enforcement access limits: States vary in whether and how they restrict police use of genetic genealogy databases, with some requiring a warrant for familial searching and others leaving the question largely to the company’s terms of service.
- Protections for minors: Several states have specific rules addressing genetic testing or sample collection involving children, often requiring parental consent beyond what federal law separately requires.
- Private right of action: Some statutes allow individuals to sue directly for unauthorized testing or disclosure, while others rely solely on state attorney general enforcement.
Because this variation is real and ongoing, readers trying to understand their own state’s rules are better served by checking a current legislative tracker than by relying on general summaries, since state legislatures amend these laws frequently. The NIH’s genomics policy page points to this variability directly, noting that genomic privacy protections differ by state and that effective policy solutions likely require clearer federal baselines alongside continued state innovation.
For individuals and families, the practical implication is straightforward: a resident of a state with strong genetic privacy statutes may have legal remedies for unauthorized testing or disclosure that someone in a state without such a law simply does not have, even though both residents are equally covered by GINA and HIPAA at the federal level. Legal professionals advising clients on genetic privacy matters should treat the state statute search as a mandatory step, not an optional one, since the difference between states can be the difference between a viable claim and none at all.
What happens when the FTC steps in on genetic privacy?
The Federal Trade Commission enforces genetic privacy indirectly, using its general authority under the FTC Act to prohibit unfair or deceptive practices rather than a genetics-specific statute. This authority has become one of the most active sources of real consumer protection in this space, filling gaps that GINA and HIPAA leave open for companies outside their direct coverage.
In June 2023, the FTC brought an enforcement action against a genetic testing company after finding that it had failed to protect the privacy and security of consumers’ DNA data and had unfairly changed its privacy practices. The resulting settlement required monetary remedies along with a comprehensive information security program and mandated destruction of certain genetic materials the company had retained beyond its own stated timeframes.
The FTC’s 2023 action required both monetary remedies and mandatory data-destruction measures, a combination that signals regulators are willing to force companies to delete genetic material, not just pay a fine and continue business as usual. That outcome matters for any consumer wondering whether a vendor’s privacy promises carry real consequences.
Several patterns run through FTC enforcement in this sector:
- The agency expects companies to obtain affirmative express consent before using genetic data for purposes beyond the original testing request.
- Security failures, such as unencrypted data or exposed cloud storage, are treated as actionable even without evidence that data was actually misused.
- Deceptive changes to privacy policies after a consumer has already submitted a sample are a recurring basis for enforcement.
- Remedies increasingly include data deletion and security audits rather than fines alone.
The FTC’s own guidance on genetic privacy lays out the practical lessons from these cases: companies should inventory what genetic data they hold, encrypt it, limit access, and respond quickly to credible security warnings. State attorneys general act as a complementary layer of enforcement, often pursuing parallel claims under state consumer protection statutes when a company’s conduct affects residents of that state specifically.
For consumers, the realistic takeaway is that enforcement creates pressure on industry practice over time, but it does not substitute for reading a company’s privacy policy before testing. A deletion request made after a breach or settlement may not remove every copy of your data if backups or third-party processors were never covered by the original agreement, so documentation matters as much as the promise itself.
Can law enforcement access your genetic data without your consent?
Law enforcement can obtain genetic data through valid warrants and subpoenas, and in some cases through voluntary searches of public genealogy databases that users have opted into for matching purposes. The legal pathway differs sharply depending on where your data lives and what kind of company holds it.
When genetic information sits inside a HIPAA-covered medical record, law enforcement generally needs a valid court order, warrant, or specific subpoena that meets HIPAA’s disclosure exceptions before a provider can release it. Direct-to-consumer testing companies, which typically operate outside HIPAA’s reach, set their own policies for responding to law enforcement requests, and those policies vary considerably from one company to another.
Public genealogy databases introduced a different kind of exposure. After investigators used an open genealogy platform to help identify a suspect in the Golden State Killer case, the role of public databases in law enforcement drew national attention, and several platforms subsequently shifted toward opt-in models for law enforcement matching rather than allowing searches by default. Even with opt-in protections in place, a warrant can still compel a platform to search its database, so opting out reduces but does not eliminate the possibility of access. Academic reviewers of direct-to-consumer genetic services note that uploading raw data to a third-party platform can expand legal exposure well beyond what the original testing company’s privacy policy promised, since the upload destination sets its own rules and may also expose genetic relatives who never tested at all.
A few practical steps reduce this kind of exposure:
- Check whether a public genealogy platform defaults to opt-in or opt-out for law enforcement matching before uploading raw data.
- Keep in mind that uploading your profile can reveal information about relatives who never consented to testing.
- Favor testing arrangements routed through a covered entity when the legal protection of HIPAA’s disclosure rules matters to you.
- Read a platform’s law enforcement cooperation policy directly rather than assuming it matches another company’s practices.
The gap between “protected by HIPAA” and “governed by a company’s terms of service” is one of the starkest divides in U.S. genetic privacy law, and it is often invisible to consumers until a request for access actually arrives.
Where GINA stops: insurance and employment gaps you should know
GINA’s protections are real but narrower than many people assume, and the gaps left open affect some of the most consequential financial decisions a person will make. Understanding exactly where the statute stops is essential before assuming any genetic test result is automatically shielded from an insurer’s view.
GINA prohibits health insurers from using genetic information to set premiums, determine eligibility, or otherwise make underwriting decisions, and it bars covered employers from requesting, requiring, or using genetic information in employment decisions. As noted earlier, Title II’s employment protections apply to employers with 15 or more employees, leaving smaller employers outside its direct reach.
The federal baseline simply does not extend to life insurance, disability insurance, or long-term care insurance. An applicant for a life insurance policy can, under federal law, be asked about genetic test results and can see that information used in underwriting decisions, a gap that academic reviewers of genetic privacy law have documented as one of the most significant holes in the current federal framework. Some states have passed their own restrictions narrowing insurers’ ability to use genetic information in these excluded categories, while others have not addressed the issue at all, which means the practical protection an applicant has can depend entirely on the state where the policy is underwritten.
Workplace protections also continue to develop at the state and federal level beyond GINA’s original 2008 text, and ongoing legislative activity on genetic discrimination in the workplace reflects continued attention to gaps that advocates argue the original statute left unaddressed.
A few practical points for applicants and policyholders:
- Confirm whether a life, disability, or long-term care insurance application asks about genetic test results, since GINA does not prohibit the question.
- Check your state’s insurance code for any genetic-information restrictions that go beyond the federal baseline.
- Understand that employer wellness programs sometimes request genetic information voluntarily, and GINA’s protections around voluntary programs carry their own specific conditions.
- Consult an attorney before disclosing genetic test results on an insurance application if you are uncertain how the information will be used.
A practical checklist before you take a genetic test
Most genetic privacy risk is manageable with a handful of concrete questions asked before a sample ever leaves your hands. Treating this as a checklist, rather than an afterthought, puts you in a stronger position than most consumers who skip straight to ordering.
- Ask how long the company retains your physical sample and whether it is destroyed automatically after testing or stored indefinitely for potential future use.
- Confirm whether your data can be deleted on request, and ask the company to describe its actual deletion process, including whether backups or third-party processors are covered.
- Find out whether your sample or data will be used for research beyond the original testing purpose, and whether that use requires separate opt-in consent.
- Ask directly about the company’s law enforcement cooperation policy, including whether it requires a warrant before releasing data.
- Review whether the company shares data with third parties, including pharmaceutical partners, advertisers, or data brokers, and under what terms.
MedlinePlus Genetics publishes a consumer-facing checklist covering many of these same questions, which is a useful starting point before comparing specific companies’ privacy policies side by side.
Raw-data downloads deserve particular caution. Once you download your raw genetic data file, you control where it goes next, and uploading it to a public genealogy platform can expose both you and your genetic relatives to searches that the original testing company’s privacy policy never covered. Guidance on discreet shipping and private paternity testing practices also applies more broadly: how a sample is packaged, labeled, and transported affects your privacy well before any data analysis begins.
Pro Tip: Before uploading raw DNA data anywhere, check whether the receiving platform defaults to opt-in or opt-out for third-party matching and law enforcement searches, since that single setting determines who can see your profile.

A short list of account-hygiene habits rounds out a reasonable privacy posture: use a unique password for any genetic testing account, review and adjust sharing settings shortly after your results arrive, rather than leaving defaults in place, and periodically revisit a company’s privacy policy, since these documents change more often than most consumers expect.
What a clinical perspective adds to the privacy conversation
Legal frameworks tell you what companies and employers are allowed to do with genetic data, but they do not tell you how a sample is actually handled on the lab bench, and that gap matters for anyone weighing privacy alongside accuracy and evidentiary value.
Clinician-ordered testing carries a practical advantage beyond HIPAA coverage: a treating physician or legal professional overseeing the process can specify exactly how a sample should be collected, labeled, and transferred, creating a documented chain of custody that a mail-order kit opened at a kitchen table generally cannot replicate. For situations where test results may later matter in a legal proceeding, such as a custody dispute or an immigration case, that documentation can be the difference between a result that holds weight and one that invites challenge.
Chain of custody is not a formality. It is the record that lets a result withstand scrutiny months or years after the sample was collected.
A reasonable checklist for anyone comparing testing options on privacy and handling grounds includes:
- Ask whether the lab documents every point where a sample changes hands, from collection to analysis to reporting.
- Confirm the lab’s stated retention period for both physical samples and digital results.
- Ask directly how long processing takes and whether expedited options exist, since vague turnaround estimates often signal vague data-handling practices as well.
- Request a copy of the lab’s data security policy in writing rather than relying on marketing language alone.
Detailed guidance on paternity test confidentiality and sample retention practices covers these questions in more depth for readers specifically weighing a paternity test. When a result may end up in front of a judge, an attorney, or an immigration officer, consulting a lawyer before testing, not after receiving results, is the step most consumers skip and most often regret.
Why the next decade of genetic privacy law needs a clearer federal floor
The current patchwork works reasonably well for employment and health insurance discrimination, where GINA and HIPAA do real work, but it leaves glaring inconsistencies in exactly the areas where consumers are least equipped to protect themselves: life and disability insurance underwriting, law enforcement access through public genealogy platforms, and the privacy practices of direct-to-consumer companies that fall outside HIPAA entirely.
Lawmakers do not need to rebuild the system from scratch. A targeted federal fix extending GINA-style protections to life, disability, and long-term care insurance would close one of the most consequential gaps without disturbing the parts of the law that already function. Congress could also look to FTC enforcement history for a template, since cases built around affirmative consent requirements and mandatory data security programs have already demonstrated what workable standards look like in practice.
States still have a role to play, and the best of them offer a preview of what a stronger federal floor might require: explicit retention limits, affirmative consent for research use, child-specific protections, and a private right of action when those rules are broken. A federal baseline modeled on these provisions, paired with continued state flexibility to go further, would do more to protect genetic privacy than either level of government is achieving alone today.
— Dr. Todd Lewis
US Diagnostics Center: privacy-aware testing options for your situation
Choosing where to test matters as much as understanding the law, and US Diagnostics Center offers a range of at-home kits built around specific family situations rather than a one-size-fits-all approach. A guided test finder helps match your circumstances, whether you need a straightforward paternity answer or a more complex kinship analysis, to the right kit before you order.
Current offerings include the Home Paternity Test Kit, the Home Maternity Test Kit, and sibling, grandparent, and aunt/uncle kits. Every kit ships with a prepaid return envelope, and lab processing typically takes 2 to 3 business days once your sample arrives, with standard order-to-results turnaround running 7 to 10 business days from the day you place your order.
- Home Paternity Test Kit and Home Single Profile DNA Test, each $79, for straightforward individual or two-party comparisons.
- Home Maternity Test Kit at $129 for confirming a maternal relationship.
- Home Aunt/Uncle, Home Grandparent, and Full and Half Sibling kits, each $139, for extended kinship questions.
- Home Twin Zygosity Test Kit at $119 for distinguishing identical from fraternal twins.
- Next-Day Results available for an additional $100 when you need an answer faster than the standard turnaround.
If timing matters more than the standard schedule allows, the test finder page lets you add expedited processing directly to your order. For anyone still deciding which kit fits their situation, reviewing the full home DNA test collection alongside your own privacy questions, retention preferences, and documentation needs is a reasonable next step before you check out.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- Genetic Information Nondiscrimination Act (GINA) — Cornell Law School Legal Information Institute
- FTC press release — Enforcement action against genetic testing company (June 2023)
- Privacy in Genomics — National Human Genome Research Institute (NIH)
- Protecting Participants in Genomic Research: Understanding the ‘Web of Protections’ — PMC/NCBI
FAQ
What is the new DNA law?
There is no single new nationwide DNA law; instead, states continue to pass individual statutes addressing collection, retention, and disclosure of genetic information, while federal protections remain anchored in GINA, HIPAA, and the Common Rule. Readers should check their own state’s current statute, since legislative activity in this area moves frequently and varies widely by state.
Does the government have access to everyone’s DNA?
No, the government does not have automatic access to everyone’s genetic data. Law enforcement generally needs a valid warrant, subpoena, or court order to obtain genetic information from a covered medical record or a testing company, though public genealogy databases that use opt-in matching can sometimes be searched when a user has consented to that use.
What are the 12 exceptions to the Privacy Act?
The federal Privacy Act governs how federal agencies handle records and includes a set of specific exceptions allowing disclosure without individual consent, such as for law enforcement purposes, congressional requests, and statistical research by the Census Bureau. This statute applies to federal government record systems generally and is distinct from genetic privacy laws like HIPAA and GINA, which govern health plans, providers, and employers rather than federal agency recordkeeping.
Does Ancestry DNA hold up in court?
Direct-to-consumer ancestry and recreational genetic tests are generally not designed to meet the chain-of-custody and documentation standards that courts require for legal proceedings such as custody or immigration cases. US Diagnostics Center does not currently offer court-admissible or legal testing services, so readers who need a result for a legal proceeding should consult an attorney about appropriate testing and documentation requirements before ordering any kit.

0 comments