Live data from Hacker News

Breach exposed more than one million DNA profiles on a major genealogy database

buzzfeednews.com

361–370 of 424 posts

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#361
post #304

Earlier quoted context omitted.

In the US, Congress has passed a law that explicitly makes that specific practice illegal: https://en.m.wikipedia.org/wiki/Genetic_Information_Nondiscr... What workarounds insurance companies come up with to circumvent the spirit of the law and how well it can be enforced will be interesting.

And George W. Bush, a Republican, signed this into law. I remember thinking that strange at the time because I would have thought insurance companies would want to be able to use DNA information and the Republicans being more of a "big business" party would have supported that. Also, I found out last time this discussion came up on HN that the law prevents it being used for regular insurance but does not apply to lif…

And life insurance could just simply demand a dna sample from you before underwriting a policy just like they might demand a physical so the whole "concern" is entirely moot.

Insurance is highly regulated, insurance companies have specific legal ways to underwrite policies, the idea that life insurance companies are going to secretly use stolen data of uncertain provenance in their underwriting instead of just making you submit a dna sample is, quite frankly, silly.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#362

And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.

Yeah, that was my biggest fear with these services. How do I stop my family members from falling for it? In the end, I can't and just have to live with their mistake (if they used these services).

Data breaches happen, doesn't mean using a service is a mistake.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#363

Earlier quoted context omitted.

Ignorant question here. How is this not regulated through HIPAA? Shouldn't these board members of this company face prison? DNA, a prosecutor could argue is a unique health identifier. "Access to equipment containing health information should be carefully controlled and monitored." https://en.wikipedia.org/wiki/Health_Insurance_Portability_a...

HIPPA only applies to a specific list of covered entities... health providers, insurance, etc. DNA services are not currently considered covered entities. They should be, IMO, but I believe Congress would have to act.

More accurately "Dna services for funsies" are not covered entities. Medical labs that sequence DNA in the realm of actual healthcare (and accept medical insurance) are covered entities.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#364
post #347

Earlier quoted context omitted.

Ignorant question here. How is this not regulated through HIPAA? Shouldn't these board members of this company face prison? DNA, a prosecutor could argue is a unique health identifier. "Access to equipment containing health information should be carefully controlled and monitored." https://en.wikipedia.org/wiki/Health_Insurance_Portability_a...

People think of HIPAA as a generic cover-all medical privacy law for some reason. It's not, not even close, It's a law that very narrowly applies mainly to insurance companies and healthcare entities that accept medical insurance. As a general rule - if insurance is never involved HIPAA doesn't apply. If you got a DNA test prescribed by your doctor for a diagnosis or even for genetic counseling then HIPAA applies. It…

"if insurance is never involved HIPAA doesn't apply."

No. This is just plain false.

HIPAA applies when personally identifiable health information is shared/exchanged. And it applies whether the data is electronic or physical (paper).

(I am NOT saying DNA falls within the HIPAA guidelines.)

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#365

Earlier quoted context omitted.

DNA sequencers are not that expensive [1]. And I’m told the actual lab work is not that hard or dangerous (high school level?). I fact, the database correlating millions of people’s DNA with their medical history and migration history is probably the hardest part. But the potential market is there. I’d gladly play $1000 to have my sequence, even unanalyzed, with the knowledge no one else does. 1 cursory look at eBay.…

I'm assuming that you meant to link a MinION (as it's the only device I know of at that price point). They would be fit for human DNA, though a single flow cell (consumable part that will degrade after X amount of DNA read) might not be quite enough to read a whole human genome with the desired accuracy. So if you purchase all the consumables (flow cells + chemicals) in low quantities, a single human genome will prob…

$1000-2000 seems like the price point I was expecting for a full offline solution. It does seem too high for the mainstream market when 23AndMe kits are going for $99 despite all the privacy concerns.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#366
post #347

Earlier quoted context omitted.

People think of HIPAA as a generic cover-all medical privacy law for some reason. It's not, not even close, It's a law that very narrowly applies mainly to insurance companies and healthcare entities that accept medical insurance. As a general rule - if insurance is never involved HIPAA doesn't apply. If you got a DNA test prescribed by your doctor for a diagnosis or even for genetic counseling then HIPAA applies. It…

"if insurance is never involved HIPAA doesn't apply." No. This is just plain false. HIPAA applies when personally identifiable health information is shared/exchanged. And it applies whether the data is electronic or physical (paper). (I am NOT saying DNA falls within the HIPAA guidelines.)

No, personally identifiable health information can be shared/exchanged without HIPAA applying. For example if I email my grandma information about my cancer diagnosis, Gmail isn't HIPAA compliant and doesn't need to be just because some people might use it to talk about their health. Grandma is also free to share my health information with impunity, she is free to, say, forward it to my boss because grandma doesn't have to abide by HIPAA either because she's a grandma.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#367
post #282

“ As a result of this breach, all user permissions were reset, making all profiles visible to all users ” This seems like the opposite of how a sensible permissioning data model should work.

“But A/B testing showed more ‘user engagement’ when you default to public”

Who are you quoting there?

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#368

This is why I’ve been putting off getting my genome sequenced. One breach and it’s out there forever. I’ve heard good things about nebula[0] as a way to get an anonymous genome but have yet to be motivated enough to take the plunge [0] https://nebula.org/whole-genome-sequencing/

I'm the founder and CEO of Nebula. I think in the not too distant future, everyone will get whole genome sequencing as standard of care. We think it's important to set up the privacy frameworks today around storing and sharing access to DNA. It's interesting because all of the risks of having your DNA data out there are not fully understood yet. And, as a consequence, legislation hasn't caught up to the technology. Should life insurance companies be able to use your DNA? Should schools be able to use it as an admittance criteria? Well, right now the law isn't stopping them from doing so. This hasn't been a huge problem today because, if you're really concerned about DNA privacy, you just won't buy a DNA test. But, sooner than later, you'll need genetic testing to get the right medicines, optimal treatments, best diagnostics, etc. Once whole genome sequencing makes the transition from consumer use cases to clinical ones, many users will be faced with choosing between their health and their privacy. We don't think that's a fair choice and think we need to start working on mitigating the privacy risks today.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#369

And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.

This is exactly how I feel about my friends/family having Facebook apps on their phone. I didn't consent to giving my contact info to Facebook. I wasn't given a choice.

Re: Breach exposed more than one million DNA profiles on a major genealogy database

#370

And half the DNA of all of the siblings and parents of the people that submitted their DNA, a quarter of their grandparents and grandchildren and so on. That's what I really hate about these companies, they get people to submit their DNA and the customers do not realize it isn't a decision that affects just them.

This is exactly how I feel about my friends/family having Facebook apps on their phone. I didn't consent to giving my contact info to Facebook. I wasn't given a choice.

Agreed. But at least I don't leak their data in return. I figure Facebook must have 99%+ coverage of the world's social graph by now, including all the holdouts. You may not have an account, but they know you exist, what you look like, what your phone number is and probably where you are just by observing the nodes that are still 'blank'. Shadow profiles should be assumed to be just as detailed as the rest. It's one reason why there are very few photographs of me online (or elsewhere). I'd like the option to go rogue one day to be open to me ;)
Post reply on HN