Is the "reasonable security" bar shifting for health-tech?
The fallout from the 2023 "23andMe" data breach has reached a new turning point. California Attorney General Rob Bonta has officially filed a lawsuit against Chrome Holding Co. (the entity formerly known as 23andMe), signaling a major escalation in how regulators are viewing genetic data protection.
The core allegations are stark:
1- Scale: Nearly 7 million users impacted, including 850,000 Californians.
2- Negligence: Claims that the company ignored known vulnerabilities and failed to prevent a credential-stuffing attack that went undetected for five months.
3- Transparency: Allegations that the company misled consumers regarding the true severity of the exposure.
Why this matters for our industry:
Genetic data is permanent. Unlike a password or credit card number, you cannot change your DNA. This lawsuit highlights that for companies handling biological data, the expectation for security isn't just "standard" it's absolute.
As we push the boundaries of health-tech, we must move beyond compliance and prioritize proactive, threat-informed defense.
Does this lawsuit set a necessary precedent for the industry, or does it risk stifling innovation in the direct-to-consumer health space?
#DataPrivacy #CyberSecurity #HealthTech #23andMe #LegalCompliance #PrivacyEngineering
What's Your Reaction?