You can change your password. You can cancel a credit card. You can even abandon the wellness app that keeps scolding you for missing leg day.
Your DNA, however, is permanent.
Genetic testing services, fitness trackers and wellness apps can provide fascinating—and sometimes genuinely useful—information. They might uncover distant relatives, estimate health risks, track reproductive health or calculate whether last night’s sleep qualified as actual rest. But these conveniences also create enormous collections of deeply personal data.
Recent health data privacy news has shown just how valuable—and vulnerable—that information can be.
Your Saliva Sample Is a Data Set
A consumer genetic test can reveal much more than your ancestry. Depending on the service, genetic data may offer clues about health predispositions, physical traits and biological relationships.
Unlike an email address, DNA also connects you to other people. Your results may reveal information about parents, siblings, children and relatives who never submitted a sample themselves.
The risks became impossible to ignore after the 2023 23andMe breach exposed information connected to approximately 6.9 million people. Privacy concerns intensified when the company entered bankruptcy proceedings in 2025, raising questions about whether its enormous genetic database could be transferred to a buyer. In July 2026, a multistate coalition announced a $150 million settlement addressing claims related to the breach.
That is quite a journey for something that started with a little tube of saliva.
Your Wellness App May Not Be HIPAA-Protected
Many consumers assume that anything involving health information is protected by HIPAA. That is not necessarily true.
HIPAA primarily applies to covered healthcare providers, health plans and their business associates. A standalone sleep, fertility, nutrition or fitness app may operate outside that system—even when it collects extremely sensitive information.
The Federal Trade Commission has expanded its Health Breach Notification Rule to make it clear that many health apps, connected devices and similar products must notify consumers when identifiable health information is exposed. That is progress, but notification generally happens after something has already gone wrong.
Legal Protection Has Some Blind Spots
The Genetic Information Nondiscrimination Act, or GINA, restricts employers and health insurers from discriminating based on genetic information. However, its federal protections generally do not extend to life, disability or long-term care insurance.
State protections vary, which means the rules surrounding genetic information can depend partly on where you live.
Give Your Data a Checkup
Before submitting DNA or connecting another app to your health information, investigate what you are agreeing to.
Read how the company stores, shares and sells data. Check whether you can delete your account, genetic records and physical sample. Decline optional research or advertising permissions you do not understand. Use a unique password and enable multifactor authentication whenever it is available.
Review connected apps periodically, too. That medication app you tried twice in 2022 probably does not still need access to your health profile.
DNA tests and wellness technology can be useful tools. Just remember that when a service is learning about your body, habits and family, you should learn a little about the service first.
With LibertyID’s Proactive Detection, including continuous monitoring and instant alerts, you can act quickly to stop identity theft or fraud before it causes serious damage. But when identity theft strikes, people need more than a solution—they need someone they can trust. LibertyID delivers “peace of mind restoration” with every call, helping clients move from stress to strength.
