Originally posted by FiveFiveSixFan:
That's great that 23 and Me wants to move up the value chain and offer services beyond genealogy but I don't see where that has anything to do with either the article linked (which was written 4 years ago) or with HIPAA since they certainly were not bound by HIPAA 4 years ago. To the the best of my knowledge, they still aren't today. That being the case, the company would not be at risk for any consequences which would normally arise from any behavior that would constitute a HIPAA violation for a covered entity until such time as they actually become one. Hence, the companies strategic intentions, especially from 4 years ago, would seem moot.
What would seem more relevant is what is actually contained in their rather voluminous
Privacy Policy , and, perhaps equally important and relevant, what is not there. Specifically, any reference to HIPAA since the privacy policies of covered entities typically reference HIPAA quite repetitively.
As mentioned in joel9507's post, the fine print of the Privacy Policy contains enough worrisome clauses to give pause to anyone who values and wishes to protect their most personal information.