U.S. Lacks Unified Genetic Data Privacy Law, Leading to Fragmented Protections
The United States currently operates without a general-purpose federal statute specifically addressing genetic data privacy. Instead, the legal landscape is characterized by a fragmented collection of overlapping definitions and regulations tied to various statutory regimes. For instance, the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule defines genetic information as 'protected health information' (PHI) only when held by specific covered entities like health plans or most healthcare providers. This means that genetic data held by direct-to-consumer (DTC) testing companies, such as 23andMe, is generally not considered PHI under HIPAA. The Genetic Information Nondiscrimination Act of 2008 (GINA) offers a broader definition of 'genetic information' but applies strictly to anti-discrimination contexts in employment and group health insurance. State laws further complicate this patchwork, with California's Privacy Rights Act (CPRA) classifying genetic data as 'sensitive personal info...