The 23andMe Settlement Is Not a Consumer Privacy Story. It Is Your Vendor Risk Problem.
- Rick Moore

- 4 days ago
- 5 min read
The $18 million multistate settlement reached between 23andMe and a coalition of 42 state attorneys general deserves more than a news cycle. For healthcare executives, it is a signal that the regulatory terrain around genomic and sensitive health data has permanently shifted, and most organizations are not positioned to respond.
Background: Genomics Has Entered the Care Delivery Stack
The 23andMe breach originated in October 2023 through a credential stuffing attack that exposed genetic ancestry and health predisposition data on approximately 6.9 million users. The company later filed for bankruptcy in 2025, and its assets, including those genetic profiles, were acquired by Chrome Holding Co. The 42-state AG coalition that drove this settlement did not wait for federal HIPAA enforcement to move. They coordinated, they acted, and they extracted accountability from an entity that federal oversight was unlikely to reach in any meaningful timeframe.
This matters to health plans and providers because genomics is no longer a consumer novelty. Precision medicine programs, pharmacogenomics initiatives at integrated delivery systems, payer-sponsored preventive health offerings, and population health platforms are all integrating genomic data into clinical and administrative workflows. In my work with health systems and plans, I have seen genomics vendors move from pilot programs to embedded components of care pathways with minimal corresponding evolution in the governance frameworks around them. The 23andMe settlement is the first clear signal that this gap carries a price tag.
What Most Organizations Are Getting Wrong
The standard healthcare security program was built around HIPAA. That is not a criticism. HIPAA's Security Rule, when implemented with the rigor that HITRUST CSF demands, is a serious framework. But HIPAA was not designed with genomic data permanence in mind, and it was not designed for the multistate enforcement landscape this settlement represents.
What I see consistently in assessments of health plan and provider security programs: business associate agreements with genomics vendors that mirror standard BAA templates developed for EHR integrations. Those templates address data use limitations, breach notification timelines, and minimum necessary access. What they almost never address is what happens to genetic data in a change-of-control event. What happens when the vendor is acquired, merged, or liquidated? Who controls the genomic profiles of your patients or members at that point?
Chrome Holding Co. now holds the genetic data of millions of individuals. Whether those individuals are also your plan members or patients is not a hypothetical. The reality is that genomic data, unlike a compromised password or a stolen credit card number, cannot be rotated. Once exposed, it is exposed permanently. The liability that attaches to that permanence follows the data, not the original vendor relationship.
NIST CSF 2.0's Govern function speaks directly to this. Supply chain risk management is not a technical checklist item. It is a governance obligation that requires your legal, compliance, and security teams to think prospectively about vendor failure scenarios, not just breach scenarios.

Strategic Implications for Healthcare Executives
The 42-state AG coalition changes the calculus in ways that most healthcare security teams have not yet internalized. HIPAA enforcement through HHS OCR has historically been slow, selective, and financially limited in ways that large organizations can absorb. Multistate AG enforcement is faster, broader, and politically motivated in ways that generate the kind of press coverage that board members and plan sponsors notice.
The organizations I have advised that understand this are already asking a different set of questions. Not just "are we compliant with HIPAA?" but "which state AG offices have active health data enforcement programs, and do our vendor contracts, breach notification procedures, and data retention policies satisfy the most demanding of those state standards?" California, New York, Connecticut, and Illinois have all enacted genetic privacy statutes that sit above HIPAA's federal floor. If your genomics vendor operates in those states, you are operating under those laws whether your legal team has reviewed them or not.
From my time at NCQA, I also want to flag the quality measure dimension. Genomic testing is entering HEDIS and value-based care frameworks as a recommended or required screening element for certain populations. As payers begin to incentivize genomic screening through quality programs, the data governance footprint of genomics will expand across the provider network. That is a governance gap that will compound if CIOs and CISOs do not get ahead of it now.
What Leaders Should Do
First, audit every genomics and precision medicine vendor relationship against a change-of-control standard. Your existing BAAs need a specific rider addressing what happens to patient or member genomic data in the event of the vendor's acquisition, bankruptcy, or dissolution. If your vendor will not agree to data destruction or return in those scenarios, that is a risk acceptance decision that should sit at the board level, not in your IT procurement process.
Second, map your multistate regulatory exposure. If you are a regional health plan or an integrated delivery system operating across state lines, your breach notification obligations and genetic data privacy requirements are not uniform. HHS 405(d)'s Health Industry Cybersecurity Practices are useful baseline guidance, but they do not substitute for a state-by-state legal review of genetic privacy statutes. Commission that review.
Third, apply NIST CSF 2.0 supply chain risk management to your genomics vendor portfolio specifically. Tier vendors by the sensitivity and permanence of the data they hold, not just by their network access. A vendor holding genomic profiles is a Tier 1 risk regardless of their technical footprint inside your environment.
Fourth, brief your board. The 23andMe settlement is a board-level event, not a compliance team event. Your risk committee should understand that genetic data exposures are permanent, that multistate AG enforcement now moves faster than federal enforcement, and that standard cyber insurance policies are unlikely to fully cover the liability profile that a genomics breach creates.
The Path Forward
Healthcare data governance has entered a new phase. The federal compliance floor that most organizations have optimized around is no longer the ceiling. State attorneys general, genetic privacy statutes, and the permanent nature of genomic data have created a risk profile that demands a different kind of security leadership.
Experience has taught me that organizations treating this as a legal and compliance matter will be perpetually behind. Strategic leaders recognize that genomic data governance is an enterprise risk question, and the time to build the framework is before the next vendor fails and the next coalition of 42 AGs decides who is accountable.
MTC Group works with health plans, providers, and health IT organizations on vendor risk governance, genomic data program assessments, and multistate regulatory exposure analysis. If your organization has genomics partnerships and you want to understand your current exposure, the conversation is worth having now, before a settlement makes it necessary.
Sources & Further Reading
HHS OCR Breach Portal, U.S. Department of Health & Human Services, Office for Civil Rights
HIPAA Security Rule, HHS Office for Civil Rights
NIST Cybersecurity Framework 2.0, National Institute of Standards and Technology
Health Industry Cybersecurity Practices (HICP), HHS 405(d) Task Group



Comments