{"id":259556,"date":"2026-01-30T16:10:11","date_gmt":"2026-01-30T16:10:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/259556\/"},"modified":"2026-01-30T16:10:11","modified_gmt":"2026-01-30T16:10:11","slug":"popular-online-lab-tests-may-not-be-covered-by-hipaa-protections","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/259556\/","title":{"rendered":"Popular online lab tests may not be covered by HIPAA protections"},"content":{"rendered":"<p>As more Americans sidestep doctors\u2019 offices to order lab tests and genetic screenings online, privacy experts warn that the new trove of sensitive health data could end up in the hands of companies selling certain types of insurance, lenders, employers, or law enforcement.\u00a0<\/p>\n<p>Patients\u2019 health data are typically protected under the Health Insurance Portability and Accountability Act, or HIPAA. But that federal law only applies to hospitals, physician practices, and other entities involved in coordinating or paying for patient care. The new breed of startups that sell blood panels and genetic tests \u2014 typically not covered by health insurance \u2014 directly to consumers aren\u2019t always considered medical providers as defined by the law.<\/p>\n<p>\u201cThese tests kind of feel like medical tests, but they may not always be covered by HIPAA,\u201d said Anna Wexler, an assistant professor of medical ethics at the University of Pennsylvania who <a href=\"https:\/\/jamanetwork.com\/journals\/jamainternalmedicine\/fullarticle\/2809595\" target=\"_blank\" rel=\"noopener nofollow\">has studied direct-to-consumer health companies<\/a>\u2019 privacy practices.\u00a0\u201cMany of these companies do exist outside of the traditional medical environment.\u201d<\/p>\n<p>As more people rush to direct-to-consumer health tests driven by a desire to catch cancer before symptoms emerge or to find out if they are at risk for Alzheimer\u2019s, experts say it\u2019s conceivable that banks and insurers could use any health data they can to mitigate their own risks. That could impact financial products such as loans, life insurance, short-term health insurance used by gig workers and those between jobs, and long-term health insurance that pays for nursing home stays.<\/p>\n<p>\u201cIf you don\u2019t agree [to share the data], you don\u2019t get the policy, you don\u2019t get the bank loan, whatever you\u2019re applying toward,\u201d said Mark Rothstein, director of translational bioethics at UC Irvine.<\/p>\n<p><a href=\"https:\/\/www.statnews.com\/2025\/11\/19\/function-health-300-million-funding-direct-to-consumer-medical-tests\/\" rel=\"nofollow noopener\" target=\"_blank\">Function Health<\/a>, for example, which offers over 100 tests for an annual subscription fee of $365, says on its website that it is \u201cnot a laboratory or medical provider.\u201d The startup, co-founded by health secretary Robert F. Kennedy Jr. ally Mark Hyman, <a href=\"https:\/\/www.functionhealth.com\/legal\/release-of-lab-results\" target=\"_blank\" rel=\"noopener nofollow\">says it<\/a> \u201cdoes not offer medical advice, laboratory services, a diagnosis, medical treatment, or any form of medical opinion, through our services or otherwise,\u201d <\/p>\n<p>If someone\u2019s taken a full-body scan or a genetic risk assessment, for instance, it\u2019s not far-fetched or clearly <a href=\"https:\/\/www.eeoc.gov\/pre-employment-inquiries-and-medical-questions-examinations\" target=\"_blank\" rel=\"noopener nofollow\">illegal for an employer<\/a> conditionally offering a job requiring certain physical traits to \u201cget access to [the test results] and see that their [potential] employee, who they want to hire, is not healthy or has some abnormal scan information,\u201d Wexler said. \u201cThose could be used to make employment decisions.\u201d<\/p>\n<p>\t\t\t<img decoding=\"async\" width=\"768\" height=\"432\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/01\/AdobeStock_366550961-768x432.jpeg\" class=\"attachment-article-main-medium-large size-article-main-medium-large\" alt=\"\" loading=\"lazy\"  \/>\t\t<\/p>\n<p>\t\t\t\t\t\t<a href=\"https:\/\/www.statnews.com\/2026\/01\/09\/patients-ordering-lab-tests-screenings-online-frustrate-doctors\/\" rel=\"nofollow noopener\" target=\"_blank\">As more patients order lab tests online, doctors don\u2019t know what to do with the results<\/a><\/p>\n<p>Function, and other direct-to-consumer health test companies such as Prenuvo and Hims also say in their privacy policies that they\u2019ll share sensitive health records in response to valid requests from law enforcement like a court-ordered subpoena. (At the time of publication, these companies did not clarify which circumstances would be considered valid and which would be denied.)\u00a0<\/p>\n<p>While there haven\u2019t been any recent high-profile instances of health data from direct-to-consumer lab tests and screenings leading to discrimination, experts say it\u2019s still early days.\u00a0<\/p>\n<p>\u201cWe simply do not know how these test results could be used in an unintended way that could lead to discrimination,\u201d said Tara Sklar, faculty director of the Health Law and Policy Program at University of Arizona Law.\u00a0<\/p>\n<p>How at-home tests can drive up insurance\u00a0<\/p>\n<p>Current laws generally stop basic health plans from ratcheting up premiums or denying coverage based on a person\u2019s medical history or genetic risk assessments, and federal health data privacy laws bar doctors and health plans from sharing medical data outside the health care system without permission. <a href=\"https:\/\/www.eeoc.gov\/laws\/guidance\/fact-sheet-genetic-information-nondiscrimination-act\" target=\"_blank\" rel=\"noopener nofollow\">The Genetic Information Nondiscrimination Act also stops basic health plans and employers<\/a> with more than 15 employees from denying or adjusting coverage based on genetic data.\u00a0<\/p>\n<p>However,\u00a0companies selling life insurance, disability insurance, and short- and long-term medical insurance are exempt from those laws, and are allowed to access sensitive health information as part of the policy underwriting process. And these companies are now assessing how they can best use the data from consumer genetic screening and blood tests to better manage their own risk, said Scott Leavitt, president and general agent of Gem State Financial Group, a vendor in Boise, Idaho, that contracts with 45 other insurance companies to sell long-term care, life, and disability insurance.\u00a0<\/p>\n<p>Recent <a href=\"https:\/\/www.statnews.com\/2025\/11\/09\/trump-renews-a-republican-battle-cry-repeal-obamacare\/\" rel=\"nofollow noopener\" target=\"_blank\">congressional efforts to roll back parts<\/a> of the Affordable Care Act could also eliminate or ease privacy protections for health insurance, and as some states push less restrictive privacy laws, people may find their insurance coverage more impacted by the health data they share with consumer companies depending on where they live, legal experts told STAT.<\/p>\n<p>\u201cWe don\u2019t know what the future holds,\u201d Leavitt told STAT. The deluge of new health tests means \u201cwe\u2019re gonna get more data, which is good. However, that data could also affect you [differently] as the rules change and the states change their laws.\u201d<\/p>\n<p>Legally, individual insurance companies can set their own policies on how heavily consumer health tests impact coverage for certain types of insurance, he added. \u201cSome companies are very proactive. Some are more old school, and just say, \u2018We\u2019re going to wait until the law tells us what we can and can\u2019t do.\u2019\u201d\u00a0<\/p>\n<p>The American Academy of Actuaries told STAT that life insurance companies may have access to at-home testing results, including through databases that testing companies may share with insurance companies with permission from customers. Life insurance companies don\u2019t currently use at-home genetic tests for policy underwriting, but any genetic information mentioned in medical records \u2014 which could include discussions customers had with their doctors about commercial test results \u2014 could potentially be used, the group said. (That group also emphasized that life insurance underwriting only takes into account data available at the time of application, and that only data that was hidden or misrepresented can change a policy after it\u2019s issued.)\u00a0<\/p>\n<p>Kelly Loussedes, a senior vice president for public relations for the National Association of Benefits and Insurance Professionals, which represents long-term care insurance professionals, told STAT it was \u201cmonitoring the growing use of direct-to-consumer genetic and biomarker testing and encourages a thoughtful approach that prioritizes consumer protections, privacy, and transparency while ensuring coverage decisions remain fair and evidence-based.\u201d<\/p>\n<p>Several other health, disability, and life insurance industry groups STAT reached out to, such as AHIP, which includes some disability, life, and short- and long-term health insurance plans, either didn\u2019t comment on the use of direct-to-consumer tests in specialty insurance, or directed inquiries to individual companies and trade groups for details on their policies. As of publication, most of those other companies and trade groups had not responded to requests for comment, including Metlife, New York Life, Massachusetts Mutual, and Aflac. Prudential Financial declined to comment, and a John Hancock spokesperson said the company \u201cdoes not require completion of any direct-to-consumer test as a prerequisite of offering any of its products.\u201d<\/p>\n<p>Hims and Prenuvo clarified that they only share data with employers or insurers when authorized by customers.\u00a0<\/p>\n<p>Newer types of tests further complicate privacy protections.\u00a0<\/p>\n<p>As companies combine genetic and non-genetic information into proprietary, integrated risk reports and predictions (Function Health, for instance, sells risk reports for <a href=\"https:\/\/www.functionhealth.com\/biomarker-categories\/heart\" target=\"_blank\" rel=\"noopener nofollow\">heart<\/a> and <a href=\"https:\/\/www.functionhealth.com\/biomarker-categories\/brain-health\" target=\"_blank\" rel=\"noopener nofollow\">brain health<\/a>, combining blood <a href=\"https:\/\/www.functionhealth.com\/what-we-test\" target=\"_blank\" rel=\"noopener nofollow\">biomarkers with genetic assessments<\/a>) \u201cconsumer protections become murkier,\u201d because they\u2019re not explicitly outlined in existing data protection laws, meaning enterprising life, disability, or short-term insurers and some employers could potentially make a case for demanding them from the customers, or the companies selling them, Sklar said. While Function said it does not directly share data with third-party insurers, it did not respond to STAT\u2019s request for clarification on privacy protections for risk scores.<\/p>\n<p>\t\t\t<img decoding=\"async\" width=\"768\" height=\"432\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/01\/GettyImages-2210915691-768x432.jpg\" class=\"attachment-article-main-medium-large size-article-main-medium-large\" alt=\"\" loading=\"lazy\"  \/>\t\t<\/p>\n<p>\t\t\t\t<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.statnews.com\/wp-content\/themes\/stat\/images\/home\/statplus.svg\" width=\"19\" height=\"16\" alt=\"\"\/><br \/>\n\t\t\t\t<a href=\"https:\/\/www.statnews.com\/2025\/11\/19\/function-health-300-million-funding-direct-to-consumer-medical-tests\/\" rel=\"nofollow noopener\" target=\"_blank\">STAT Plus: Wellness startup Function Health raises $300 million as consumer lab testing picks up steam<\/a><\/p>\n<p>\u201cWe live in a rapidly changing legal landscape\u201d for health privacy, said Sara Geoghegan, senior counsel at the Electronic Privacy Information Center, a research and privacy advocacy group. <a href=\"https:\/\/www.kff.org\/womens-health-policy\/litigation-involving-reproductive-health-and-rights-in-the-federal-courts\/\" target=\"_blank\" rel=\"noopener nofollow\">Federal court rulings rejecting additional protections<\/a> for reproductive care data, for instance, already constitute an \u201cattack on health care and health privacy,\u201d she added. <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/special-topics\/reproductive-health\/final-rule-fact-sheet\/index.html\" target=\"_blank\" rel=\"noopener nofollow\">In June, <\/a>the U.S. District Court for the Northern District of Texas declared unlawful some Biden-era HIPAA modifications that would have specifically limited data sharing about reproductive health.\u00a0<\/p>\n<p>Weighing clinical benefits against risks<\/p>\n<p>In their privacy policies and terms and conditions, Function, Prenuvo, and Hims all say that they are not considered medical providers in all circumstances and therefore not legally \u201ccovered entities\u201d under HIPAA \u2014 meaning they are not required to comply with the strict data sharing restrictions outlined in that law. (Some of these companies have established their own medical groups that are governed by HIPAA, but the online platforms that customers order from are not legally considered medical providers. Hims also told STAT the company is technically not considered a covered entity because consumers pay for their services using cash rather than health insurance.)\u00a0<\/p>\n<p>While they also emphasized that they prioritized customers\u2019 privacy, their policies all specified instances in which data may be shared outside the company: <a href=\"https:\/\/www.functionhealth.com\/legal\/consumer-health-data-privacy-policy\" target=\"_blank\" rel=\"noopener nofollow\">Function Health<\/a> said mental and physical history, clinical notes, biomarkers, genetic data, and other sensitive factors may be shared with corporate affiliates, and via lawful requests from law enforcement or government agencies when appropriate. Hims and Prenuvo had similar policies. (Health plans and traditional medical providers <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/faq\/disclosures-for-law-enforcement-purposes\/index.html\" target=\"_blank\" rel=\"noopener nofollow\">are also allowed to share sensitive data<\/a> with outside groups in certain circumstances, including some law enforcement requests.)<\/p>\n<p>Taken together with open questions about the validity and accuracy of direct-to-consumer tests \u2014\u00a0especially risk predictions for conditions like Alzheimer\u2019s or cancer, and which often involve proprietary calculations that aren\u2019t clinically validated \u2014\u00a0genetic counselors and doctors tell STAT they\u2019re advising consumers to weigh the benefits of ordering their own health tests against the potential insurance impact.\u00a0<\/p>\n<p>Tyler Stokes, a genetic counselor at the University of Maryland Medical Center\u2019s Greenebaum Comprehensive Cancer Center, said she typically informs patients considering services like 23andMe that specialty insurance plans can currently use genetic tests to determine eligibility. \u201cFor someone who is healthy, who does not have cancer or does not have this increased, heightened risk, it might be worth taking that into consideration prior to doing a genetic test,\u201d she said.\u00a0<\/p>\n<p>\u201cWill you be OK if you can\u2019t buy additional life insurance because something is found?\u201d said Carolyn Applegate, a genetic counselor at the Johns Hopkins School of Medicine. \u201cExactly how far those protections go, and exactly what is and isn\u2019t allowed under different circumstances\u201d hasn\u2019t really \u201cbeen tested,\u201d she added.\u00a0<\/p>\n<p>This story is part of a reporting fellowship managed by the\u00a0Association of Health Care Journalists,\u00a0with support from The Commonwealth Fund.<\/p>\n","protected":false},"excerpt":{"rendered":"As more Americans sidestep doctors\u2019 offices to order lab tests and genetic screenings online, privacy experts warn that&hellip;\n","protected":false},"author":2,"featured_media":259557,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[6784,134,5568,527,111,139,69,6293],"class_list":{"0":"post-259556","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-healthcare","8":"tag-diagnostics","9":"tag-health","10":"tag-health-tech","11":"tag-healthcare","12":"tag-new-zealand","13":"tag-newzealand","14":"tag-nz","15":"tag-patients"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/259556","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=259556"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/259556\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/259557"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=259556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=259556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=259556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}