Remember That DNA You Gave 23andMe?
theatlantic.com
theatlantic.com
They do what is called "genotyping"[1] which is much cheaper than full "sequencing" [2], but which only probes for a limited set of known variants. So it's only partial information.
Since then 23andMe has launched a more expensive 23andMe+ Total Health offering, which does full sequencing, but like most people, I never subscribed to that package. In fact I had no occasion to interact with the company after the first result, which may be why they are struggling financially.
DNA testing is something most people might do at most once in their lives -- then they lose interest.
[1] https://customercare.23andme.com/hc/en-us/articles/202904610... [2] https://customercare.23andme.com/hc/en-us/articles/202904600...
Maybe if you were a celebrity of some sort, maybe, but even then..
Imagine someone doing this to the judge that ruled they owe child support for their child from a previous marriage out of spite.
(This was a plot point in a sci-fi story I vaguely remember.)
Everyone knew price would drop in time, but, assuming you’re correct, it’s amazing to hear that’s happening
Mostly a US concern, as usual.
No way to know how the regulation will change in the future depending on the amount of lobby dollars that are thrown.
This is especially scary in small, closely related communities like Iceland or Utah where a relatively low number of collected samples can be extrapolated to large swaths of the population that didn't give their genetic info away.
Also that protection is relatively new in the US and is constantly being attacked politically so it isn't unreasonable to think about a world where it is removed like other longstanding health related protections.
If the implication is that it is so old it won't ever be challenged it's worth noting that roe v wade was in '73.
Also, since 1991, many US states had already passed laws that prohibit insurers' use of genetic information in pricing, issuing, or structuring health insurance.
THing is about the bases
1. most of them are the same in everyone
2. the ones that are different tend to be correlated with each other locally and thus captured by their 1Mb assay
so
3. you can infer all the stuff they didn't sequence with pretty high confidence. Not a "in theory" but more like "has been a typical thing to do in the statistical genetics field for at least a decade"
4. outside of the genome there is the epigenome which may or may not be relevant, it undergoes very specific resets short after fertilization
also worth noting
5. bioinformatics is an imperfect and algorithm based science. Reads are aligned according to error and difference profiles (i.e. string mismatches and the most and least types of mismatches). So unless things are finely calibrated, a level of analysis most bioinformatics don't do, deeply study their read alignment penalties for particular data sets, even a robust bug-free read aligner correctly applying penalties will have bad alignments, false positives, false negatives
anyways I for one hope the futurepopele will clone me from the bytestream
[edit]
From their website:
Data retention
23andMe will retain some information to comply with legal
obligations, including your DNA, sex, and date of birth
So apparently you can permanently delete your data, except for, oh just your DNA....[edit 2]
From NYT (https://archive.is/ynvDR)
However, 23andMe uses a laboratory that must follow
regulations under the Clinical Laboratory Improvement
Amendments, or CLIA. This means that some data, including
your DNA, sex and date of birth will be retained in order
to comply with these regulations. The company will no
longer use that information, though. You can read more
about the company’s deletion processhere.https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-...
Tissue. Preserve remnants of tissue for pathology examination until a diagnosis is
made on the specimen.
Depending on what "until a diagnosis is made" would mean in the 23andMe context.I wonder which law supposedly says this.
I’m not saying this is what they are worried about, but it could be something along those lines. I work in big finance, and there is a LOT of regulation around data retention, and it’s a lot more nuanced than people think.
Should we be allowed to delete the data? Absolutely. This will likely be a hallmark case setting president for the future.
Of course the Golden State Killer was extenuating circumstances. He killed about a dozen people and sexually assaulted over 50 women in the 70s. But, it makes you wonder about the future of criminology.
A doctor I recently visited whipped out his iPhone and asked if I was okay with him recording our conversation so that some fly-by-night rando AI company could vacuum up our private conversation and spit out some LLM-generated summary of our visit. "Not to worry," he insisted, "they're HIPAA compliant!"
I probably should have walked out of the office right then and there, but instead I simply told him no, not under any circumstances may he record our private conversation and send it off to some third party over the Internet. He seemed a bit taken aback because I guess I am the only patient he's had push back on it. He tried saying that the service "really helped him" or something like that. It seemed like he was trying to make me feel bad for "making his job harder."
I simply replied that HIPAA compliance didn't prevent the last 5 or 6 letters I've received from both hospitals and insurance companies about "cybersecurity events" leading to the compromise of my PII. And not just any PII, mind you. It was my medical information, supposedly "protected" by HIPAA. These were major insurance companies and hospitals. And you want me to believe that some fly-by-night AI startup is going to somehow be a safe place for a goddamned fscking full audio recording of our private visit, just because they claim to be HIPAA compliant? Are you kidding me?
I've made it a point to start writing my representatives in government about these issues. They need to wake up and start doing something meaningful to protect the people who are being bamboozled by all the yahoos who play fast-and-loose with their privacy, especially medical PII.
As a condition of getting a flu and covid vaccine, CVS made me agree to give them permission to share my medical history, test results, etc. with my employer and their affiliates.
Either way, it's still a too-broad agreement, but my assumption is that CVS thinks it's easier to opt everyone in by default than to ask patients to opt in as needed, and then inevitably have some patients not opt in when they should have, and then deal with the resulting bureaucratic nightmare when the nursing home they work for calls and demands to see immunization records.
Besides that immediately making me question their security, it is a great example how people trust things without much thought. I’ve heard of calls for statistics to be pushed over calculus to improve math literacy in the general population, perhaps some cybersecurity courses should be pushed over “learn to code” to improve tech literacy.
Okay, great. So which employees were held personally liable for these two breeches? I got "The Letter" telling me I was one of the victims for both of them.
https://www.hhs.gov/hipaa/for-professionals/compliance-enfor...
It is technologically agnostic, because it applies whether your doctor is fully remote and everything uses electronic records, or if the provider is still using pen and paper and carrier pigeons.
For actual security details, there may be some regulations with the change to the mandating of electronic records, but nothing in HIPAA ourself. For that, you want to look for organizations that have a certification like SOC2 or similar.
How about the 18 standards labelled A) through R) in page 97 of: https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/ad...
I am no expert but HIPPA seems far more prescriptive than say GDPR or PII regulations.
I do agree that self-certification leads to perverse incentives and lowers the bar
I don’t know how to accomplish this, but we need to educate as many people as we can about privacy
Hell, even tech companies fall for this. They'll upload their shit to some cloud without setting up proper guards because "oh well it's Atlassian". Hope you don't have anything too compromising in that Jira!
"HIPAA compliant" doesn't mean nothing. It means a whole lot. It's just not relevant here, because - as mentioned at the beginning of the article - 23 and Me is not regulated under HIPAA.
That's the only reassurance I have. It would be like illegally collected evidence. Sure, you may have some evidence (my DNA), but it's not admissible because you're not supposed to have had access to it.
Are there analogous rules around the DNA sent to 23andMe, would you have an enforceable opportunity to block uses of that, and would you even know when they're using it that way?
Honest and sincere question: why would you even use their service in the first place?
Legal changes that allow insurance companies to use genetic information to increase or deny coverage. Not just to you but your entire lineage.
Being added to a database searched by police - this has its own hazards even for non criminals.
There are certainly other possibilities, but once the cat is out of the bag you can't avoid them.
It's probably already possible, given sufficient resources, to tailor-make a virus that targets a specific person, family, or ethnic group.
Presumably it will get easier to develop designer virii, as time marches on, not more difficult.
Finding out that I had all the known markers for Parkinson’s 30 years before symptoms are expected to show up gave me an unbelievable head start and changed the trajectory of my life in several ways.
I read the TOS at the time. Would do again even with the data leak.
It might not be a huge disaster, but to me the issue is that the company can't make any real promises about how they might profit from the DNA of it's customers in the future. It's not a problem unique to 23andMe, I will never sign up to another social network, because of Facebooks behavior. I'll never sign up to another service such as Gmail, Outlook, YouTube or Reddit, because I've seen what those companies did and how they behaved I can no longer trust any online service. The trust that existed in the early 2000s is gone, the idea that if we didn't like something we could just leave and delete everything is gone. I don't envy someone trying to bootstrap a new service, the previous generation of companies have poisoned the well.
Just keep in mind the Golden State Killer lost his DNA in the 70s, and was prosecuted in the 2010s. Using DNA from a third cousin who used an online DNA service.
Maybe don't kill anyone and you're fine, maybe not. Time will tell.
The conviction that every corporation is inherently evil or can turn evil at any point in the future never seems to fail, but many people just aren't that skeptical.
But as 23andme is an US company, it is not under the jurisdiction of the GDPR. The legal situation isn't clear, the EU would claim some jurisdiction, but I (IANAL) think it's more like you go to the US, walk into a Walgreen and give up your data.
> The GDPR is retained in domestic law as the UK GDPR, but the UK has the independence to keep the framework under review.
The UK GDPR. It’s like the GDPR, only with a Union Jack and a bulldog slapped on the side.
Now, in practice, companies seem significantly less scared of the ‘UK GDPR’ than its full-fat European progenitor (probably for good reason; even before brexit, ICO was one of the less aggressive regulators, with its largest GDPR fine ever only being 20mn pounds), and of course the EU has a number of _newer_ consumer protections in this general area (DMA, DSA, AI Act etc) which the UK has _not_ implemented, but, for the moment at least, the UK still has some degree of data protection.
If Sam were to target an EU citizen then it would.
But if you just walk into a pharmacy in the US and send your sample from there GDPR has nothing to do with it
The only way to service EU customers is when we assume entering data on an US website is not exporting data from the EU to the US by the US company. Just like when I go into a Walgreen in NYC as an EU citizen.
For the last decade US and EU companies have ignored the fact that it is/was mostly illegal do transfer EU citizen data to the US (it is currently legal but will be illegal again) - also every EU company that exports data to the US (e.g. by using Mailchimp) needs to guarantee the safety of the data by auditing Mailchimp, no one does and there have been no fine for now, but I assume there will in the future.
See the discussions around
https://en.wikipedia.org/wiki/EU%E2%80%93US_Data_Privacy_Fra...
"The EU parliament raised substantial doubts that the new agreement reached by Ursula von der Leyen is actually conform with EU laws, as it still does not sufficiently protect EU citizens from US mass surveillance and severely fails to enforce basic human digital rights in the EU. In May 2023 a resolution on this matter passed the EU parliament with 306 votes in favor and only 27 against, but so far has stayed without consequences."
However if 23&me were targeting European citizens that would be different.
Despite what the adtech industry likes to claim online, Bobs Burger Joint in Baltimore does not have to be specifically concerned about abusing their customers data even if a customer happens to be an EU citizen.
Now if they shipped frozen burgers to France online then sure they would. If they sold “merch” in euros they would. But a local store with a physical premises trading in person? Not covered.
A European citizen living in Austin buying from Amazon though, could well be covered. Amazon do target EU citizens
“Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. ”
https://commission.europa.eu/law/law-topic/data-protection/r...
I was an Estonian resident a while ago, and I wanted to delete data in my old VK.com account (a Russian company). They didn’t do anything, naturally, so I wrote to Estonian data protection inspector or something. They said that (surprise!) they can’t do anything either.
Things might be better now, but my bet is if you register a company in, say, Seychelles, and your business is purely digital, you can ignore GDPR all you want.
EU can, in theory, tell payment processors to stop working with you, but I haven’t heard of such cases. Even then it won’t help if you don’t sell anything (apart from user data).
Some EU countries have started blocking websites (by spoofing DNS) – this could actually work to put some actual pressure on non-compliant companies, but also is kinda too authoritarian for EU?
Tl;dr: GDPR has good intentions, it just doesn’t work right now if the data processor is not in EU.
https://gdpr.eu/article-3-requirements-of-handling-personal-...
I’m sure there are US companies that happen to sell to EU residents that happen to acquire some PII but don’t know and can’t correlate it with the EU, and so aren’t subject to the GDPR. But according to the law’s language, it seems as though something simple on a company’s website like using Google Analytics, which does identify and “monitor” the behavior of people by location, might trigger GDPR. I might expect 23AndMe to trigger applicability for multiple reasons, including that they are using DNA to identify regional heritage and relatives, the samples may be delivered with EU addresses on them, and the samples are as personally identifying as it gets. That’s on top of whatever the website, account registration, and sale process collects.
And exporting data to the US is illegal because US companies can't guarantee that the EU citizen data is protected (which is the goal of the GDPR).
But then again, it is not clear if this applies if an EU citizen goes to a company in the US (real or website in US datacenter) and leaves their data there.
The problem is that the EU parliament thinks this does not work, because US companies can be (secretly) coerced into giving data to the US government, even without telling the affected EU citizens (the EU commission has a different view). And the EU cititzen have no way of going to court over this. And a US company can't guarantee in any way to protect EU citizen data.
Which also the reason that all the *Shields failed and were killed by EU courts [0]
The view of the parliament is that you can't export personal data to the US at all as a company, so 23andMe can put up anything on the website they want, either they don't export data to the US (my Walgreen example) or they do, then they do it illegally.
So I (again, IANAL) would say this is marketing speak aimed towards users and has no relevancy.
[0] https://en.wikipedia.org/wiki/EU%E2%80%93US_Privacy_Shield
https://techcrunch.com/2023/12/04/23andme-confirms-hackers-s...
Despite my curiosity, for privacy reasons I made the decision to not use 23andMe. (Basically - feels like information an insurer will inevitably want to use against me.) My wife did, however, and over the years our kids did too, for various reasons (an interest in genealogy, a kid with celiacs looking to trace the genetic component, etc).
Recently I was very surprised to look at the app on my wife's phone and see that they have a shadow account for me with a lot of details filled in, due to my wife/kids/siblings/cousins having used the service. I should not be suprised -- this is how they caught the golden state killer, after all.
That sounds like a GDPR breach to me, you should report it to the ICO (if you’re in the UK, not sure what the EU equivalent is).
They should not hold data on any UK or EU citizen without the citizen’s consent.
Data is money, so of course companies will pull out every stop to harvest it, monetize it, deprive you of control over it, and ransom you with it.
Fortunately we don't see applications like "personalized poisons" yet, but it is likely inevitable.
If, say, an insurance company denies you some policy because of what they learnt from your relative's DNA, you suffered a concrete harm from that sampling decision.
We are not isolated units. Almost all our choices have impact on others. Lack of a shared culture creates societies where people are rightfully scared what the next isolated unit will do with their sensitive data.
It’s possible to live in a high trust society.
Secondly I don't trust anyone with that information because even though I trust how it might be used today, I don't know how it might be used in ten years.
I was also able to find out where I came from and connect with distant relatives. To those who are tightly connected with their huge family, you’re privileged.
I’d be sad if this resource went away but I don’t fear it being used for nefarious purposes. I can rest assured the US government is already miles ahead toward that end.
I got enough out of the deal (instead of nothing from the government) that it was in my mind an acceptable tradeoff. No one's about to start cloning me.
Your DNA is not secret. You leave it everywhere you go. You have no reasonable expectation of privacy for your litter when you litter. It's only a matter of time and of tech before everybody has a copy of everybody's DNA.
Lastly, security through obscurity is not something to be relied upon. But it can work for a period of time.
Would you care if 23AndMe sold your DNA & analysis to a private for-profit medical insurance data provider who could recommend hiking your price or denying coverage, based on your genetic markers, without having to tell the insurance company why and without having to share your DNA? This is one of the private business nefarious purposes I worry about, based on having a friend who worked in credit processing saying that they were looking for legal ways to sell purchasing habits to medical insurance companies.
This is just strange.
Do you have no imagination whatsoever or have you never set foot in school or do you know literally nothing about history (maybe you were born yesterday and really quickly figured out how to write, I don't know)?
I’ve done time with an individual who got (I believe) wrongfully convicted due to genetic genealogy. A lay jury watches Law and Order, hear “DNA”, and will proverbially buy the Brooklyn Bridge from prosecutors.
Get too unpopular with those in power, and maybe your DNA can be traced to a shell casing for an unsolved assassination a continent away from you.
Annie Dookhan wrongfully convicted thousands upon thousands upon her doctored drug tests. Someone just like her could do it to you or someone else with your DNA test.
There are laws against insurers citing preexisting conditions to deny coverage, and most DNA is equivocal as to whether you’ll develop expensive maladies. So that doesn’t worry me either.
Okay, yes convictions can be messy and wrong, and juries can believe stuff from TV that isn’t true. Neither of those demonstrates government intent. None of the lawyers nor the juries nor the producers of Law and Order necessarily work for the government. You complained about my use of “imagine” and then threw out a completely hypothetical and vague scenario (three, actually). Even abuses of power by government employed individuals seeking some kind of retribution don’t demonstrate nefarious government purpose on the whole.
There are laws against wrongful convictions and untrue testimony and abuse of power too. Annie Dookhan went to prison, and convictions based on her false evidence are being dropped and overturned. Why do you choose to feel safe with insurance laws made by the government and not trial laws?
I strongly encourage you to get in the habit of proofreading your posts for tone. You write with pique, a habit I find familiar, as I used to do the same when I was younger.
It’s not just what you say but how you say it, and tone can either further your contribution or get in the way.
I know the government does crappy things sometimes, even things that contradict its own laws. I’m still curious, piqued if you will, about how DNA can be used by the government against me, what things I/we should be potentially concerned about.
Personal experience is fair. It’s also the reason I lean towards fear of DNA being used against me by private for-profit companies more that I worry about the government.
In the US, those laws have been under persistent attack by Republicans since enactment, and there hasn't been a major election cycle where its repeal wasn't a campaign dog whistle[1].
And since when has for-profit industry required unequivocal evidence to strengthen their balance sheets and fatten their bottom lines?? These gamified business decisions are always beyond opaque and the burden of proof is always unfavorably shifted onto consumers in harm's way.
[1] https://www.whitehouse.gov/briefing-room/statements-releases...
Has 23andMe disclosed how many users' genetic data have been accessed by govt or LE agencies or third parties? Is it obligated to? Does this obligation still attach if/when 23andMe ceases to exist? Have any privacy researchers estimated what (ancestry-only?) data got resold on the darkweb since 2023?
Since federal laws like HIPAA don't cover 23andMe or the genetic data(!) it holds on 14+m users, because as currently written “HIPAA does not protect data that’s held by direct-to-consumer companies [outside of healthcare] like 23andMe” [1]. Although CA and FL consumer laws give some protection against the company - but no criminal protection against people selling it on the darkweb. Also, it's unclear whether any protections automatically attach in the event of a firesale of assets/bankruptcy.
Hence 23andMe was able to settle the 2023 breach of 6.9m users' data (ancestry data, not actual genetic data) lawsuit for a tiny $30m [2], no criminal penalty, no admission of negligence or wrongdoing, no executive resignations.
Compare to the (suspended) criminal conviction of the CEO in the 2020 Finland Vastaamo psychotherapy center data breach (only ~36,000 patients), for violating GDPR. [3]
Also, to the GDPR-related discussion on expectations about cloud sovereignty of genetic and ancestry data, there's an obvious implication that consumers want GDPR to effectively protect their data, they should at absolute minimum insist on a cast-iron guarantee that sovereignty is enforced. With strong criminal penalties.
[0]: Fusion.net, 2015, "Cops are asking Ancestry.com and 23andMe for their customers’ DNA" https://news.ycombinator.com/item?id=10400550 -> https://web.archive.org/web/20160707221934/http://fusion.net...
[1]: https://www.npr.org/2024/10/03/g-s1-25795/23andme-data-genet...
[2]: https://news.ycombinator.com/item?id=41536494
[3]: https://en.wikipedia.org/wiki/Vastaamo_data_breach#Legal_aft...