Skip to main content
Category: Regulatory Framework

Genetic Information Nondiscrimination Act (GINA)

Also known as: GINA, Genetic Information Nondiscrimination Act of 2008
Simply put

The Genetic Information Nondiscrimination Act (GINA) is a U.S. federal law enacted in 2008 that protects people from being discriminated against based on their genetic information. It generally prohibits this kind of discrimination in two main areas: health insurance and employment. In practice, this means that, in most cases, health insurers and employers cannot use a person's genetic information against them.

Formal definition

GINA is a U.S. federal statute enacted in 2008 that prohibits discrimination on the basis of genetic information in two principal domains: health insurance coverage and employment. The employment-related provisions are administered by the Equal Employment Opportunity Commission (EEOC), and the codified employment prohibitions appear at 42 U.S. Code Chapter 21F, which addresses matters such as employment agency practices and the confidentiality of genetic information. GINA is a distinct statute from HIPAA and addresses genetic-information discrimination specifically; it should not be treated as a substitute for, or subset of, HIPAA's Privacy or Security Rule obligations, and practitioners should note that other frameworks, including the HITECH Act and state law, may impose additional or overlapping requirements. The precise scope, definitions, and enforcement details should be verified against the current statutory and regulatory text.

Why it matters

Genetic information is among the most sensitive categories of personal data, and its misuse can affect a person's access to health insurance and employment. GINA, enacted in 2008, was designed to address this specific risk by prohibiting discrimination on the basis of genetic information in two principal domains: health insurance coverage and employment. For compliance professionals, GINA matters because it establishes protections that operate independently of HIPAA. An organization can satisfy HIPAA's Privacy and Security Rule obligations and still face separate legal exposure under GINA if it uses or discloses genetic information in ways the statute prohibits.

GINA is frequently misunderstood as a subset of HIPAA or as duplicative of HIPAA's protections. It is not. GINA is a distinct federal statute focused specifically on genetic-information discrimination, and its employment-related provisions are administered by the Equal Employment Opportunity Commission (EEOC) rather than by HHS OCR, which enforces HIPAA. Practitioners handling genetic information should therefore evaluate their obligations under both frameworks rather than assuming that HIPAA compliance alone addresses GINA's requirements.

Because genetic-information handling can implicate multiple overlapping legal regimes, organizations should also be aware that other frameworks, including the HITECH Act and applicable state laws, may impose additional or overlapping requirements beyond GINA and HIPAA. The precise scope of GINA's protections, its statutory definitions, and its enforcement mechanisms should be verified against the current statutory and regulatory text, as this entry describes the law in general terms only.

Who it's relevant to

Privacy Officers and Compliance Officers
Privacy and compliance professionals need to recognize that GINA imposes protections for genetic information that operate independently of HIPAA's Privacy and Security Rules. Where an organization handles genetic information, GINA obligations should be assessed separately, and satisfying HIPAA alone should not be assumed to address GINA's requirements.
Employers and HR Professionals
GINA's employment-related provisions, administered by the EEOC, prohibit discrimination on the basis of genetic information and address matters such as employment agency practices and the confidentiality of genetic information. Employers and HR teams should evaluate their hiring, employment, and information-handling practices against these prohibitions and confirm specifics against the current statutory text.
Health Insurers and Plan Administrators
GINA generally prohibits discrimination based on genetic information in health insurance coverage. Insurers and plan administrators should understand that these protections are distinct from HIPAA obligations and may coexist with additional requirements under other frameworks and state law.
Legal Counsel Advising Healthcare Organizations
Counsel should treat GINA as a distinct statute rather than a subset of HIPAA, and should account for the possibility that the HITECH Act and state laws impose additional or overlapping requirements. Because the precise scope, definitions, and enforcement details are subject to change, legal advice should be grounded in verification against the current statutory and regulatory text.

Inside GINA

Genetic Information as Protected Health Information
GINA's intersection with HIPAA arises because genetic information is treated as a category of protected health information. A modification to the HIPAA Privacy Rule clarified that genetic information is health information and prohibited most health plans from using or disclosing genetic information for underwriting purposes. Readers should verify the specific regulatory text against the current HIPAA Privacy Rule.
Prohibition on Underwriting Use
Under the HIPAA-GINA relationship, health plans (as covered entities) are generally prohibited from using or disclosing genetic information for underwriting purposes. This restriction applies to the use of genetic information in decisions related to eligibility, benefits, and premiums, subject to the scope defined in the applicable regulation.
Definition of Genetic Information
Genetic information generally includes information about an individual's genetic tests, the genetic tests of family members, and the manifestation of a disease or disorder in family members (family medical history). The precise definition and its boundaries should be confirmed against the current regulatory text, as GINA and HIPAA each carry specific defined meanings that may differ from common usage.
Scope Beyond HIPAA
GINA is a separate federal law with provisions addressing both health insurance (Title I) and employment (Title II). Only the health-information and health-plan-related aspects intersect with the HIPAA Privacy Rule; the employment nondiscrimination provisions are enforced through other authorities and fall outside HIPAA's scope.

Common questions

Answers to the questions practitioners most commonly ask about GINA.

Does GINA mean genetic information is not protected under HIPAA?
No. Genetic information is protected health information (PHI) under the HIPAA Privacy Rule, and GINA reinforced this protection rather than removing it. GINA-related modifications generally clarified that genetic information is treated as health information under HIPAA and, notably, restricted the use and disclosure of genetic information for underwriting purposes by most health plans. GINA and HIPAA operate together here rather than as alternatives, so covered entities and business associates should continue to safeguard genetic information under their existing HIPAA obligations.
Is GINA just a health information privacy law like HIPAA?
Not exactly. GINA is broader than health information privacy and is commonly understood to have two main areas: one addressing genetic information in the context of health coverage, and one addressing genetic information in the employment context. The employment-related provisions of GINA fall outside the scope of the HIPAA rules and are enforced by different authorities. When GINA intersects with HIPAA, it typically does so through the treatment of genetic information as PHI and through limits on underwriting use by health plans. Readers should verify the specific statutory and regulatory provisions against current guidance, as GINA's reach extends beyond HIPAA's framework.
How should a health plan handle GINA's restriction on using genetic information for underwriting?
In most cases, health plans that are HIPAA covered entities should not use or disclose genetic information for underwriting purposes, consistent with the GINA-related provisions incorporated into the HIPAA Privacy Rule. Practically, this generally means reviewing policies, notices of privacy practices, and workflows to confirm that genetic information is not being used in decisions such as eligibility, benefit determinations, or premium setting where underwriting is implicated. Because the precise definition of underwriting and the applicable exceptions carry specific regulatory meaning, organizations should confirm the current regulatory text and any applicable guidance before finalizing procedures.
Does our HIPAA Notice of Privacy Practices need to address genetic information?
Health plans subject to the GINA-related requirements may have specific obligations regarding statements about the use of genetic information for underwriting in their Notice of Privacy Practices. Organizations should review whether their plan type is subject to these requirements and coordinate with counsel or their privacy officer to confirm the correct notice content. The exact wording and applicability depend on the current regulatory text, so verify against current guidance rather than relying on templates that may be outdated.
How does GINA affect how we classify and safeguard genetic information in our systems?
Because genetic information is treated as PHI, it should generally be handled under the same HIPAA Privacy and Security Rule protections that apply to other PHI. Where genetic information exists in electronic form, the Security Rule's administrative, physical, and technical safeguards apply to it as ePHI, including access controls and other safeguards implemented through required and addressable implementation specifications. GINA does not create a separate technical safeguard framework; rather, it reinforces that genetic information warrants the same protective treatment, with the additional underwriting-use restriction for applicable health plans.
If our organization pursues HITRUST CSF certification, does that address GINA-related requirements?
HITRUST CSF certification can help demonstrate that an organization has implemented mapped controls, but certification by itself does not establish legal compliance with GINA or HIPAA, and it is not a legal requirement. GINA's health-coverage provisions, employment provisions, and underwriting restrictions are legal obligations that must be met independently, and the employment provisions in particular fall outside HIPAA's scope entirely. Organizations should treat any framework certification as supporting evidence rather than proof of compliance, and confirm GINA-specific obligations against the current regulatory text, applicable enforcement authority, and legal counsel. State law and other frameworks may also impose additional requirements beyond GINA.

Common misconceptions

GINA and HIPAA are the same law, so complying with HIPAA automatically covers all GINA obligations.
GINA is a distinct federal statute. While it intersects with the HIPAA Privacy Rule by treating genetic information as protected health information and restricting its use for underwriting, GINA also contains employment-related and other provisions that are enforced separately and are outside HIPAA's scope. Compliance with one does not by itself establish compliance with the other.
The HIPAA-GINA underwriting restriction applies to every organization that handles genetic information.
The HIPAA Privacy Rule's underwriting restriction generally applies to health plans acting as covered entities, not to every vendor or organization that touches genetic data. HIPAA obligations attach through defined relationships such as covered entities and business associates, and readers should confirm applicability against the current regulatory text.
Genetic information only means the results of an individual's own genetic test.
Genetic information is generally defined more broadly to include genetic tests of family members and family medical history, in addition to an individual's own genetic tests. The precise boundaries should be verified against the current regulation, as the defined term may differ from everyday usage.

Best practices

Treat genetic information as a sensitive category of protected health information within your HIPAA Privacy Rule policies, and confirm the applicable definitions and restrictions against the current regulatory text.
If your organization operates as a health plan, review underwriting practices to ensure genetic information is not used or disclosed for underwriting purposes, consistent with the HIPAA Privacy Rule modification.
Do not assume HIPAA compliance covers all GINA obligations; assess separately whether GINA's employment and other provisions, enforced by different authorities, apply to your organization.
Clarify through relationships and agreements (such as business associate agreements where applicable) how genetic information flows between covered entities, business associates, and subcontractors.
Consult legal counsel regarding state laws, the HITECH Act, or other frameworks that may impose requirements on genetic information beyond those in HIPAA and GINA.
Periodically re-verify definitions, scope, and enforcement details against current HHS OCR guidance and the applicable regulatory text, since regulatory language and interpretations are updated over time.