23andMe Settles $18 M with 43 States After 2023 Breach Exposing 7 Million Genetic Records
What Happened – In 2023, a security breach at direct‑to‑consumer genetics company 23andMe exposed the genetic information of nearly 7 million customers. The fallout led 43 U.S. states to bring a multistate action, which the company resolved by agreeing to pay an $18 million settlement.
Why It Matters for Compliance & Audit Readiness
- The incident underscores the need for documented privacy‑by‑design controls that protect highly regulated health data under HIPAA, GDPR, and state privacy statutes.
- Continuous evidence of consent management, data‑subject request handling, and data‑retention policies is essential to demonstrate SOC 2 CC6 (Confidentiality) compliance.
- Verisq’s CookiePLUS privacy suite provides the audit‑ready consent logs and DSAR workflow evidence that regulators and state attorneys general expect in settlement negotiations.
Who Is Affected – Consumer genetics/health‑tech firms, biotech SaaS providers, and any organization handling large volumes of sensitive health or biometric data.
Recommended Actions –
- Map the breach to SOC 2 CC6 controls (privacy, data classification, retention, and DSAR processes).
- Deploy a consent‑management platform that captures granular opt‑in/opt‑out records and can produce immutable audit trails.
- Conduct a privacy impact assessment (PIA) and update breach‑response playbooks to include genetic data specifics.
Source: TechRepublic
Technical Notes – The public filing does not disclose the exact attack vector, but the breach resulted in confirmed exposure of raw genotype files, health‑related phenotype data, and personally identifiable information. Source: [TechRepublic]