Hacker News new | past | comments | ask | show | jobs | submit login

It probably is illegal to disclose it, that data should fall under HIPAA as protected health information. If the data in anonymized, then they could release it (as long as the person gave them permission). However, they couldn't release it with any identifying information attached.

At least, I assume 23andMe would fall under HIPAA regulations, but I'm not so sure. Does anyone know if 23andMe has an IRB?




No mention of HIPAA in their privacy statement. A perfunctory google search found mumblings online about them not being covered by HIPAA.

https://www.23andme.com/about/privacy/#Full




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: