After reading this article I decided to download my data in case they go under. Was greeted with this message on the relevant page. Does anybody have some insight if this is related to the data breach or something else?
After reading this article I decided to download my data in case they go under. Was greeted with this message on the relevant page. Does anybody have some insight if this is related to the data breach or something else?
https://lawforbusiness.usc.edu/direct-to-consumer-generic-te...
Hint, the "I" in HIPAA stands for "insurance." A general rule - if an insurance company isn't involved HIPAA doesn't apply. HIPAA is a law that regulates insurance companies and entities that deal directly with insurance companies, not "medical data."
HIPAA doesn't apply to 23andMe. At all. HIPAA only applies to "covered entities" - https://www.hhs.gov/hipaa/for-professionals/covered-entities...
Not exactly. If you go to most any healthcare provider, and pay out-of-pocket, HIPAA still applies. More accurately, HIPAA applies to any healthcare providers who transmits any health information in electronic form in connection with a transaction covered by 45 C.F.R. §160.103. Or in other words, basically every healthcare provider is also a covered entity, unless they're completely 100% cash only and don't take insurance for anyone ever. Do these even exist?
Although, still 23andMe wouldn't be covered because they're not providing healthcare services.
This is correct - I should have been more specific. If a business doesn't take insurance then HIPAA doesn't apply. Not that insurance isn't involved in a specific transaction. I've edited my GP comment to be more specific.
>Do these even exist?
Yes, absolutely.
https://www.healthline.com/health-news/these-doctors-accept-...
https://www.nytimes.com/2012/11/24/your-money/dealing-with-d...
https://www.fawkeshealth.com/insights/are-cash-only-clinics-...
So-called "pill mills" are almost always cash-only when they operate.
There's also health centers on university campuses that are funded through student fees and don't bill insurance.
If you email them about it, you just basically get a copy-pasta reply restating the message on the site, and if you keep emailing them 3+ times asking for a refund (ask me how I know), they'll tell you you can manually upload identity verification and they'll get back to you in 6-8 weeks with the data.
My guess is also that they use the hack as an excuse to keep people in.