Inside 23andMe founder Anne Wojcicki's $99 DNA Revolution
fastcompany.com
fastcompany.com
It's not 2013 I'm worried about with someone accessing this data, it's 2023.
Says Andy Page: "I view this as a tidal wave of inevitable data and a trend in the marketplace. The technology is available; the price point is decreasing. There are so many organizations and engineers and companies that are focused on this."
Of course you see it as a trend, or at least your pocketbook depends on it being one. The fact that he isn't responding with all the robust steps they do to protect data leads me to believe there's not enough concern at this company for privacy to trust them. Maybe that's okay when it's yet another SV social bullcrap site, but for medicine? Nah.
Could it be used to find matches for organ donation, for example (with subsequent accidents happen to matching donors)? I know, very "movie scenario" threat, but it is just one creepy idea.
The cavalier attitude towards privacy that pervades the field of genomics is deeply troubling to me. From the article: "23andMe's privacy statement clearly states that it collects a person's genetic, registration, web browsing, and self-reported information. The company can share its data with third parties '[after] it has been stripped of Registration Information and combined with data from a number of other users sufficient to minimize the possibility of exposing individual-level information while still providing scientific evidence.'"
Having read that, consider that "a team of geneticists reported Thursday in the journal Science that it was able to figure out the names of people who had donated their DNA to research -- even though test subjects' identities were stripped from their genomic data." (Source: http://articles.latimes.com/2013/jan/18/science/la-sci-sn-ge...)
Anne Wojcicki, co-founder of 23andme, is married to Google co-founder Sergey Brin. It doesn't seem entirely implausible that the two companies could have joint business ventures down the road. I wonder how valuable "anonymized" genomic sequences would be to advertisers.
Not for long: http://allthingsd.com/20130828/google-co-founder-sergey-brin...
They don't link the study, so it is hard to tell, but it appears that what actually happened is they used self-reported identifying information linked to DNA entries.
It's not apparent that they did any genetic analysis whatsoever.
That is still certainly a privacy attack vector, but one on par with getting your email hacked because you always use your birthday as you password.
The study took some of these public DNA samples, and searched genealogy databases to find likely relatives. The self-reported surnames were thus those of distant relatives, not of the PGP-participants themselves. The researches then combined those likely surnames with information such as zip codes on the PGP public profiles to correctly identify several participants (given that a zip code, gender, and surname is often enough information to uniquely identify a person).
It should be noted that the PGP has a rigorous education and consent process of the risks of publicly posting DNA. So while the study may have surprised some of the participants, it's not something any of them were expecting could never happen.
You can read more info on the study here: http://www.wired.com/wiredscience/2013/01/your-genome-could-...
The study: "Identifying personal genomes by surname inference." Gymrek et al. Science. 2013 Jan 18. (http://www.jhu.edu/pfleming/bioinform/files/gymrek_science_2...)
It looks like you're correct that 23andMe is not covered by HIPAA:
http://www.genomicslawreport.com/index.php/2009/10/27/federa...
I have to think you're just being contrarian, because as far as I can tell this idea is a joke at best. In other words, "good luck with that," and not important at all.
I'm not being butthurt, I could not find a single case of anything close to this "important consideration" succeeding. The only possible angle I can come up with is a DMCA action, but as far as the CFAA, contract law, or anything that has any precedent behind it, I'd guess the victim is shit out of luck, and for DMCA to succeed you'd have to forge some heavy tools to establish some IP control over the data that was leaked/shared. IANAL.
tl;dr: once you give data to a business, they can do whatever they want with it.
Suing over breaking ToS is an option (and it is done; just because they say they aim to "minimize the possibility of exposing individual-level information", which seems to offer wiggle room, doesn't mean that there aren't many interpretations of that phrase that are unconscionable and you could then sue over), however, that's not a whole lot of leverage, and there's the very real possibility that the reason your data is out is because they've gone bankrupt or are very nearly bankrupt and are either trying to recoup investor money or are in a last ditch effort to stay profitable. At that point there's not much your suit is going to do or recover, if they even disclose what they've done in the first place.
When has someone sued over ToS for a data leak?
Only the president poops in bags.
Here's just one article on that, just the first reasonable one I found googling: http://www.forbes.com/sites/stevenkotler/2012/12/13/what-is-...
So the real thing about 23AndMe, is how they took advantage of very popular misconceived exagerated expectations about a) the extent that genetics are destiny, and b) even to the extent that genes are destiny (less than you think), the extent that current science can actually succesfully figure that out -- to make a lot of money.
These are EXTREMELY popular misconceptions, they fit into the zeitgeist well. So 23AndMe can make a lot of money off them.
(And I'm not suggesting that the 23AndMe principals are intentionally taking people for a ride--I'm sure they believe it too.)
I wouldn't be so sure that 23andMe's business model depends on their customers being uninformed -- for $99, you don't need a vast amount of actionable investment to justify the purchase. Hell, getting your teeth cleaned without insurance can easily cost you more than $100. I wasn't expecting a ton of actionable insight from 23andme, but I don't regret spending the $99.
The thing that got me to change my mind was some blogger article that was going through their TOS/PP and realized that once you do this test, you are legally obligated for revealing results to the insurance company you plan to be insured with. Not sure how much the truth it is, but this plus the owner sleeping in one bed with Google's Brin ("hey honey so how is it going with collecting peoples DNAs? - very good - okay keep up the good work, in couple years I will buy you out then we can match your DNA database with their credit card / name / dob and attach it to their Google profile so we serve them more matching ads", turned me away for good.
Got a citation for that?
If that's true, then getting a 23andme test could mean price gouging for anyone looking for life insurance, disability insurance or long-term-care insurance. The Genetic Information Nondiscrimination Act (GINA, https://en.wikipedia.org/wiki/Genetic_Information_Nondiscrim...) prohibits employers and health insurance companies from genetic discrimination, but there's a big loophole for other types of insurers to. More information: http://www.npr.org/blogs/health/2013/01/17/169634045/some-ty....
This isn't true.
[1] http://en.wikipedia.org/wiki/Genetic_Information_Nondiscrimi...
This statement is based on the assumption that once 23andMe has the 25 million people sign up that the founder desires, that their genotypes (at the resolution of testing that 23andMe can provide) will actually provide a lot of actionable information.
But there is a LOT of reason to doubt that hope. I was just at the weekly meeting of my alma mater's journal club on behavior genetics today, and the papers we discussed today are about rare variants in DNA and their possible relationship to human disease.
Casals, F., & Bertranpetit, J. (2012). Human Genetic Variation, Shared and Private. Science, 337(6090), 39-40. doi: 10.1126/science.1224528
Brookes, K. J. (2013). The VNTR in complex disorders: The forgotten polymorphisms? A functional way forward? Genomics, 101(5), 273-281. doi: 10.1016/j.ygeno.2013.03.003
Maurano, M. T., Humbert, R., Rynes, E., Thurman, R. E., Haugen, E., Wang, H., . . . Stamatoyannopoulos, J. A. (2012). Systematic Localization of Common Disease-Associated Variation in Regulatory DNA. Science, 337(6099), 1190-1195. doi: 10.1126/science.1222794
Schork, A. J., Thompson, W. K., Pham, P., Torkamani, A., Roddey, J. C., Sullivan, P. F., . . . Schizophrenia Psychiat Genomics, C. (2013). All SNPs Are Not Created Equal: Genome-Wide Association Studies Reveal a Consistent Pattern of Enrichment among Functionally Annotated SNPs. Plos Genetics, 9(4). doi: 10.1371/journal.pgen.1003449
It is dismaying likely that even millions of well-genotyped samples will provide very little illumination of the development of disease risk in human beings. For you to get actionable information from 23andMe, moreover, you have to count on 23andMe having detailed personal health information about yourself and the other 23andMe customers: "But first Wojcicki needs spit. Her goal is to sign up a million customers by the end of 2013. Eventually, she says, 'I want 25 million people. Once you get 25 million people, there's just a huge power of what types of discoveries you can make.'" Translated into English, that says that the company has very little information to offer yet, and wants you to pay for the privilege of providing highly personal information in the hope that the company can use your information to draw in other customers. I'm not optimistic that that will even help your fellow customers, as I learn more about current genomics research. This business plan certainly puts a premium on the company having ironclad guarantees of customer data privacy, and gathering lots of personal health information on the strength of those guarantees. It's an open question whether this is really a good trade-off for you or me or any other individual.
In my opinion (as a statistician with minor bio experience) the future of predicting health things based on just DNA is uncertain, except for direct remedies for known current conditions like certain forms of cancer. (i.e. as a response to disease, in actual personalized medicine)
That addresses the "resolution of testing that 23andMe can provide".
The other point is that humans cluster into a small number of haplogroups, and with a small number of WGS or exomes, we can impute many things on the other lower-resolution data based on the fact people are very closely related.
I'm not defending the current approaches (GWAS, etc). They are known-broken. Nor am I defending exome sequencing - also known-broken.
Anyway, it's trivial now to do 1000+ genomes at 4X coverage, which gets you many of the rare variants.
Of course, at the end of the day, the current approaches are unlikely to unlock the full medical potential of the genome. Most people studying genomics and health have very limited mental models of how cells and tumors and organs work, and none of the existing methods really do anything beyond correlation analysis on noisy data.
http://www.illumina.com/company/events/understand-your-genom...
It's new business development- Illumina's interested in jumpstarting the clinical WGS/consumer genetics industry, so they hold things like this, expecting other companies will pick up the model and focus on it).
Because Illumina makes money on the consumables, having such an industry will be very profitable for them.
Did you watch Gattaca and think to yourself: "That is the type of world I want to live in!"
It just seems like there is some small chance that sequencing everyone will make the world better, and a much larger chance that it will make it worse.
Do you believe that your data is secure with them?
If someone wants me genome, it is fairly trivially for them to obtain it; I believe the benefits of sequencing outweigh the risks.
It is one thing for someone to steal your hair and run a somewhat expensive genome sequencing on it. It is another to have it already sequenced and stored in an internet accessible database in a easy to read file format next to all of the other relevant data I would want. Of course this is stored next to thousands or millions of other already sequenced genomes that are also in the correct format and accessible without me even leaving this chair.
My email address or credit card info generally doesn't get stolen from my shredded trash. It gets stolen from a 3rd party database chock full of tons of other emails making it a goldmine for people who want email addresses/credit card numbers.
I'm sure someone on here has more info about it than I do though...
Wikipedia says about exome sequencing that's a "cheaper but still effective alternative to whole genome sequencing."
I have some basic knowledge of biology, but I'm don't know anything about sequencing... do you have some details?
there are a few issues with exome: 1) exome prep is a big issue in itself 2) exome leaves out large regions which are likely to be important in understanding many aspects of human biology
At this point, I'm speculating:
even whole genome sequence at relatively high coverage per individual * large # of individuals is likely to not explain all the aspects of organismal biology. There appears to be a fair amount of state that is transferred from a parent cell to a child cell during mitosis that is not expressed in our current DNA assemblies. The whole chromosomes themselves are complex, enormous structures that undergo massive rearrangements during the various phases of the cell cycle... yet are still capable of maintaining tons of epigenetic state. Very little or none of this is really being analyzed in a systematic or rigorous way, which is frustrating to see because, as somebody with a training in human molecular biology, all of this has been KNOWN FOR DECADES! I mean seriously, Chapter One of Molecular Cell Biology, please!
Spaghetti on the wall, with poor execution. People invested $126 million in this? The emperor has no clothes.