Breach & Enforcement2 min readOn reporting by Bleeping Computer

43 State Attorneys General Just Fined a Company HIPAA Doesn't Cover

Bleeping Computer reports that 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 state attorneys general, who alleged the company failed to protect customers' genetic data.

Most coverage will file this under "genetics company gets fined." That misses the part that should worry you.

The enforcement didn't come from where you'd expect

23andMe is a direct-to-consumer genetic testing company. It is, for the most part, not a HIPAA covered entity — it isn't a provider billing insurance, a health plan, or a clearinghouse. The framework everyone associates with health data largely didn't apply.

They got hit anyway. Not by the Office for Civil Rights. Not by a federal privacy regulator. By 43 state attorneys general acting as a coalition, under state consumer-protection and state privacy law.

Why this is the vector nobody models

When we run a gap assessment, teams can usually name their regulator. HealthTech says OCR. Anyone with EU users says the supervisory authorities. SaaS selling upmarket says "our customers' auditors."

Almost nobody says "a bloc of state AGs."

That's the gap. State attorneys general don't need you to be a covered entity. They don't need a federal statute to hook into. They need residents of their state whose data you handled badly — and they increasingly coordinate, which turns fifty separate small risks into one large one.

If your compliance posture is a map of frameworks — SOC 2 here, HIPAA there, GDPR for the EU — you have a blind spot exactly where 23andMe got hit: sensitive data about consumers, held by a company that no single framework clearly claims.

What to actually do about it

Stop scoping by framework. Scope by data. The question isn't "are we a covered entity." It's "whose data do we hold, how sensitive is it, and which states do they live in." That list is your real exposure map, and it's usually broader than your framework list.

Assume the floor is higher than your framework's. State consumer-protection law tends to ask a plain question: were your safeguards reasonable for the sensitivity of the data? You can be fully outside HIPAA and still fail that. "No framework required it" has never been a defense.

Sensitive-but-uncovered is the danger zone. Genetic data, biometrics, precise location, kids' data. If you hold any of it and can't name the framework that governs it, that's not a clean bill of health — that's the 23andMe position.


The lesson here isn't about genetics. It's that being outside a framework's scope is not the same as being outside enforcement's reach.

Reporting on the settlement: Bleeping Computer, July 16, 2026. Analysis ours.


Where you actually stand

If you can't name every category of sensitive data you hold and the law that governs each, a gap assessment answers that in about two weeks.

Schedule a scoping call →

← Back to newsReporting: Bleeping Computer, July 15, 2026