Skip to main content
Category: De-identification and PHI Types

Genetic Information

Also known as: Genetic Data, DNA Information
Simply put

Genetic information refers to data about a person's genes, including DNA, the hereditary material that contains the code for building and maintaining an organism. This can include results from genetic testing that show changes in genes which may affect health. Because such information is personal and can reveal details about a person's health and family, it is treated as sensitive and is protected under certain laws.

Formal definition

Genetic information encompasses data derived from DNA, genes, and genetic testing, where DNA is the hereditary material carrying the code for building and maintaining an organism and genetic testing can reveal DNA changes in genes that may affect health. In the U.S. regulatory context, genetic information is treated as a sensitive category of personal health data; the Genetic Information Nondiscrimination Act (GINA) is a federal law that protects against genetic discrimination in employment and health insurance. Note that GINA and HIPAA impose distinct but sometimes overlapping obligations, and this entry does not fully address how genetic information is defined or regulated under specific provisions of the HIPAA Privacy Rule or the HITECH Act; practitioners should verify the applicable regulatory definitions and requirements, including any additional state-law protections, against current authoritative sources.

Why it matters

Genetic information is among the most sensitive categories of personal health data because it can reveal not only an individual's current health status but also predispositions to future conditions and inherited traits shared with biological relatives. This makes it distinct from many other forms of health data: a single genetic test result can carry implications for family members who never consented to testing, and it cannot be changed or reissued the way a compromised password or account number can. For compliance professionals, this permanence and familial reach raise the stakes for safeguarding and disclosure decisions.

Genetic information also sits at the intersection of multiple legal regimes. The Genetic Information Nondiscrimination Act (GINA) is a federal law that protects against genetic discrimination in employment and in health insurance, addressing concerns that individuals could be treated unfairly based on their genetic makeup. GINA and HIPAA impose distinct but sometimes overlapping obligations, and where genetic information is created or maintained by a covered entity, it may also be handled as protected health information under HIPAA. Practitioners should not assume that compliance with one framework satisfies the other.

Because the precise regulatory treatment of genetic information varies across GINA, the HIPAA Privacy Rule, the HITECH Act, and state law, organizations should verify which definitions and requirements apply to their specific circumstances rather than relying on a general understanding. State laws in particular may impose additional protections beyond the federal baseline, and the applicable definitions should be confirmed against current authoritative sources.

Who it's relevant to

Privacy Officers
Privacy officers should recognize genetic information as a sensitive data category that may trigger obligations under GINA, potentially under HIPAA where held by a covered entity, and under state law. Because these frameworks are distinct but sometimes overlapping, privacy officers should verify which definitions and disclosure rules apply to genetic information within their organization rather than assuming a single standard governs it.
Human Resources and Employment Compliance
Because GINA protects against genetic discrimination in the workplace, professionals responsible for hiring, benefits administration, and workplace policies should understand its restrictions on the use and acquisition of genetic information. This is an area where employment-focused obligations under GINA may apply independently of, or in addition to, health-data protections.
Compliance and Legal Teams
Legal and compliance teams should treat genetic information as an area of layered regulation, where GINA, potentially HIPAA and the HITECH Act, and state-law protections may each impose requirements. They should confirm the applicable regulatory definitions and obligations against current authoritative sources, as this entry does not fully resolve how genetic information is defined under specific HIPAA provisions.
Security Officers
Where genetic information is maintained in electronic form by a covered entity or business associate, security officers should generally apply safeguards appropriate to its sensitivity. Given that genetic data cannot be reissued or changed if compromised, security teams may wish to give particular attention to protecting it, while confirming the specific requirements that apply under the relevant frameworks.

Inside Genetic Information

Genetic Test Information
Information about an individual's genetic tests, which generally reveal information about a person's genotype, chromosomes, genes, and gene products, including inherited or acquired genetic characteristics.
Family Medical History
Information about the manifestation of a disease or disorder in family members of the individual. Under HIPAA, as amended to incorporate GINA-related provisions, this is generally treated as genetic information.
Requests for and Receipt of Genetic Services
Information about an individual's request for, or receipt of, genetic services, as well as participation in clinical research that includes genetic services, is generally encompassed within the definition.
Status as Protected Health Information
Genetic information, when held by a covered entity or business associate and individually identifiable, is generally treated as PHI and is subject to the HIPAA Privacy Rule protections that apply to PHI in all forms, not solely electronic form.
Prohibition on Use for Underwriting
Health plans are generally prohibited from using or disclosing genetic information for underwriting purposes, a restriction reflecting the intersection of HIPAA with the Genetic Information Nondiscrimination Act (GINA). Readers should confirm the specific scope against current regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about Genetic Information.

Is genetic information regulated only under the HIPAA Privacy Rule?
Not exactly. Genetic information is a subset of PHI, so it is covered by the Privacy Rule in all forms (oral, paper, and electronic), while its electronic form (ePHI) is additionally subject to the Security Rule's administrative, physical, and technical safeguards. The Privacy Rule also imposes a specific limitation treating genetic information as health information and generally prohibiting its use or disclosure for underwriting purposes by health plans. Readers should confirm the precise scope against the current regulatory text, and note that the underlying protections derive in part from GINA (the Genetic Information Nondiscrimination Act), which may impose requirements beyond HIPAA.
Does genetic information include only an individual's own DNA test results?
No. As defined in the regulatory text, genetic information is broader than an individual's own genetic test results. It generally also encompasses genetic tests of family members, the manifestation of a disease or disorder in family members (family medical history), and information about requests for or receipt of genetic services. Because it can reach information about relatives, its scope is wider than common usage suggests. Verify the full definition against the current regulation, as certain items such as information about the sex or age of an individual are generally excluded.
How should a covered entity handle family medical history collected during intake?
Family medical history typically falls within the definition of genetic information and should generally be treated as PHI subject to the Privacy Rule, and as ePHI subject to the Security Rule if maintained electronically. Organizations should apply the same use, disclosure, and safeguard controls they apply to other PHI, and be mindful of the specific restriction on using genetic information for underwriting. Confirm handling requirements against current guidance and applicable state law.
What specific restriction applies to health plans regarding genetic information?
The Privacy Rule generally prohibits health plans from using or disclosing genetic information for underwriting purposes. Practically, this means a plan should not incorporate genetic information into eligibility, premium, or contribution determinations. Because this restriction has a specific regulatory meaning and interacts with GINA, organizations should review the precise operative language in the current regulation before designing underwriting workflows.
Do business associates that handle genetic information have obligations for it?
Yes, to the extent genetic information is PHI that a business associate creates, receives, maintains, or transmits on behalf of a covered entity. Those obligations attach through the business associate agreement and flow down to subcontractors through further agreements. The specific limitations that apply to a covered entity, such as underwriting restrictions, remain tied to the covered entity's role, so parties should define responsibilities clearly in their agreements and verify against current requirements.
How does a breach involving genetic information affect notification obligations?
A breach involving genetic information is generally assessed the same way as any breach of unsecured PHI under the Breach Notification Rule, including the applicable risk assessment and notification steps enforced by HHS OCR. There is no separate HIPAA breach standard unique to genetic information, though the sensitivity of the data may inform risk analysis. Note that state laws or GINA may impose additional considerations, and specific thresholds and timelines should be confirmed against current guidance.

Common misconceptions

Genetic information is only protected when it exists in electronic form.
Genetic information that qualifies as PHI is generally protected by the HIPAA Privacy Rule regardless of form, including oral and paper. The Security Rule's safeguards apply specifically to ePHI, but that narrower scope does not limit the Privacy Rule's broader coverage of genetic information.
Genetic information refers only to the results of an individual's own genetic tests.
The concept generally extends beyond a person's own test results to include family medical history and information about the request for or receipt of genetic services. Its scope is broader than the common lay understanding of the term.
Achieving HITRUST CSF certification confirms that an organization is handling genetic information in compliance with HIPAA's requirements.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. Organizations must still meet the applicable HIPAA obligations independent of any certification.

Best practices

Treat genetic information that is individually identifiable and held by a covered entity or business associate as PHI, applying Privacy Rule protections across all forms including oral, paper, and electronic.
For health plans, avoid using or disclosing genetic information for underwriting purposes, and verify the precise scope of that prohibition against the current regulatory text and applicable GINA provisions.
Ensure that family medical history and information about requests for or receipt of genetic services are recognized and handled as genetic information, not just an individual's own test results.
Confirm that business associate agreements appropriately extend obligations to vendors and subcontractors who create, receive, maintain, or transmit genetic information on the entity's behalf.
Check whether state law or the HITECH Act imposes additional requirements beyond HIPAA when handling genetic information, and document those obligations.
Do not rely on HITRUST CSF certification as evidence of HIPAA compliance for genetic information; maintain independent verification of HIPAA obligations against the current regulation.