A recent enforcement action by the Federal Trade Commission (“FTC”) against 1Health.io—which sells “DNA Health Test Kits” to consumers for health and ancestry insights—serves as a reminder that the FTC is increasingly exercising its consumer protection authority in the context of privacy and data protection. This is especially true where the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) does not reach. The FTC’s settlement with 1Health.io highlights a wide-range of privacy and security issues companies should consider relating to best practices for updating privacy policies, data retention policies, configuration of cloud storage and vendor management, especially when handling sensitive genetic data.
The market for direct-to-consumer (“DTC”) genetic testing has increased dramatically over recent years as more people are using at-home DNA tests. The global market for this industry is projected to hit $2.5 billion by 2024. Many consumers subscribe to DTC genetic testing because they can provide insights into genetic backgrounds and ancestry. However, as more consumers’ genetic data becomes available and is shared, legal experts are growing concerned that safeguards implemented by U.S. companies are not enough to protect consumers from privacy risks.
Some states vary ...
Blog Editors
Recent Updates
- Importance of Negotiating Maintenance, Repair and Replacement Obligations in Health Care Leases
- Unpacking Averages: Assessing the Products Included in FDA's Voluntary Malfunction Summary Reporting Program
- Federal Update on Cannabis Scheduling: Are State Legalized Cannabis Dispensaries to Become Pharmacies?
- HHS Extends the Antidiscrimination Provisions of the Affordable Care Act to Patient Care Decision Support Tools, Including Algorithms
- It’s Been a Long Time Coming – FDA’s Final Rule on Regulation of Laboratory Developed Tests (LDTs) as Medical Devices Has Arrived