HIPAA Policy
Effective date: August 19, 2026
1. Scope of this Notice
The DNA Company resells genetic testing kits supplied and processed by independent third-party laboratories and provides consultations concerning test results. This Notice applies to personal information that The DNA Company collects or controls in connection with those services, including order information, information you provide before or during a consultation, and genetic test reports or interpretations that we receive or maintain.
Some information we maintain may be “protected health information” (“PHI”) governed by the Health Insurance Portability and Accountability Act and its implementing regulations (“HIPAA”). HIPAA applies only when The DNA Company is acting as a HIPAA covered entity or business associate with respect to the information at issue. Information collected in a consumer transaction may not be PHI merely because it relates to health or genetics. Consumer genetic data that is not PHI may instead be protected by state genetic privacy, consumer privacy, data security, and breach-notification laws. We apply the provisions of this Notice according to the law that applies to the particular information and, when laws overlap, will follow the rule that provides greater protection unless prohibited by law.
Independent laboratories and kit manufacturers may collect information or biological samples directly from you and may maintain the laboratory record. Their own notices, consent forms, and retention practices also apply. This Notice describes The DNA Company’s practices and does not replace an independent laboratory’s notice.
2. Information We Collect
Depending on how you use our services, we may collect or receive:
-
identifiers and contact information, including name, mailing address, email address, telephone number, date of birth, account identifiers, and identity-verification information;
-
transaction and payment-related information, including kit orders, shipping and fulfillment details, consultation purchases, and payment status (payment-card data may be processed directly by our payment processor);
-
health and consultation information you choose to provide, including personal and family health history, symptoms, medications, goals, questions, consultation notes, and communications;
-
genetic information, including test status, laboratory reports, variants, traits, raw or interpreted genetic data, and conclusions or recommendations derived from test results;
-
consent records and your privacy choices;
-
website, device, and security information, such as IP address, browser or device information, login activity, and information reasonably needed to operate and secure our website and services; and
-
other information you submit to us or authorize another person or laboratory to provide to us.
We do not perform the laboratory analysis of your biological sample. The laboratory identified when you order or register a kit is responsible for its laboratory testing and for its custody, retention, or destruction of the sample. Contact that laboratory directly regarding sample status unless your consent materials state that The DNA Company will submit a request on your behalf.
3. How We Use and Disclose Information
A. Treatment and consultations
When HIPAA applies, we may use and disclose PHI to provide, coordinate, or manage your consultation and related health care. This may include reviewing your test report, preparing an interpretation, communicating with you, and, at your direction or as otherwise permitted by law, coordinating with a laboratory or another health care professional.
B. Kit ordering, testing, and fulfillment
We may disclose information needed to order, register, ship, process, and support a kit to the third-party laboratory, kit manufacturer, fulfillment provider, carrier, or other service provider involved in the service you requested. Genetic data or a biological sample will be transferred to a third party beyond service providers only with the separate express consent required by applicable law, unless a disclosure is otherwise required or expressly permitted by law.
C. Payment
When HIPAA applies, we may use and disclose PHI to bill and collect payment for covered services and to support payment activities. We may also provide transaction information to payment processors, accounting providers, or other vendors that help complete and document your purchase. We do not disclose genetic data to a health plan for payment unless the disclosure is permitted by applicable law and consistent with your instructions and consent.
D. Health care and business operations
When HIPAA applies, we may use and disclose PHI for lawful health care operations, such as quality assessment, training, credentialing, compliance, auditing, legal services, fraud prevention, security, and business management. We may use other personal information for corresponding business purposes that are reasonably necessary and proportionate to operate and improve the services.
Vendors that handle PHI for us must enter into a HIPAA business associate agreement when required. Other service providers and contractors must be contractually limited to specified services and required to protect personal information as applicable.
E. Communications about services
We may contact you about orders, test status, consultations, privacy or security matters, and products or services that are part of your care or are reasonably related to the services you requested. Where required, we will obtain your consent before sending marketing communications. You may opt out of non-transactional marketing using the instructions in the communication or by contacting us.
We will obtain your written HIPAA authorization for uses or disclosures of PHI for marketing when HIPAA requires one. We will obtain separate express consent before marketing to you based on your genetic data or facilitating marketing by a third party based on your purchase or use of a genetic testing product or service, as required by California law.
F. Family, caregivers, and personal representatives
With your agreement, at your direction, or when otherwise permitted by law, we may disclose relevant information to a family member, caregiver, personal representative, or another person involved in your care or payment. We verify authority as appropriate and limit the information disclosed to what is relevant.
G. Legal, public-interest, and safety disclosures
We may use or disclose information when permitted or required by applicable law, including for public health activities; health oversight; reports of abuse, neglect, or domestic violence; judicial or administrative proceedings; law enforcement; workers’ compensation; organ or tissue donation; coroners, medical examiners, or funeral directors; specialized government functions; or to avert a serious and imminent threat to health or safety. When HIPAA applies, we will meet the conditions and limits imposed by HIPAA. More protective genetic privacy laws may require your consent or a qualifying court order even when another rule would permit a disclosure.
H. Research
The DNA Company does not sell clients’ identifiable personal information, identifiable genetic data, or biological samples for research purposes. We will not use or disclose identifiable genetic data, identifiable health information, or a biological sample for research beyond the service you requested without obtaining any separate express consent or authorization required by applicable law or another legally valid basis.
We may use genetic, phenotypic, health, demographic, and other information for research, scientific analysis, product development, validation, quality improvement, and related purposes when the information has been deidentified so that it does not reasonably identify you. Deidentified information may be analyzed individually or combined with deidentified information from other clients to identify patterns, associations, trends, or other research findings.
We may also collaborate with qualified researchers, academic institutions, health care organizations, or other research partners using deidentified information, subject to applicable law and appropriate privacy and data-security safeguards. The DNA Company will not attempt to reidentify deidentified information, and we will require recipients not to attempt to reidentify you where required by law or agreement.
Where applicable law requires notice, consent, authorization, or another legal basis for research involving deidentified genetic, health, phenotypic, demographic, or other information, The DNA Company will comply with those requirements.
I. Sale and advertising
The DNA Company does not sell clients’ identifiable personal information, identifiable genetic data, or biological samples. We do not disclose genetic data to an entity in its capacity as an employer or as a decision-maker or adviser concerning health, life, long-term-care, or disability insurance, except where a disclosure is expressly permitted by applicable law and all required conditions and consents are satisfied.
We do not sell PHI. Most uses and disclosures of PHI for marketing, and any sale of PHI, require your written HIPAA authorization. If our general website practices constitute “sharing” of non-genetic personal information or targeted advertising under an applicable state privacy law, we will provide the required notice and opt-out mechanism. We will not use cross-context behavioral advertising technologies on pages or portals where genetic data or PHI is entered or displayed unless the practice has been specifically reviewed and is permitted by law.
J. Other uses and disclosures
Uses and disclosures of PHI not described in this Notice will be made only with your written authorization unless otherwise permitted by law. You may revoke an authorization in writing at any time. Revocation will not affect action already taken in reliance on the authorization.
4. Special Rules for Genetic Data and Biological Samples
When applicable law requires it, The DNA Company will obtain your separate, affirmative, express consent for:
-
collecting, using, and disclosing your genetic data for specified purposes, including an explanation of who may access it;
-
storing a biological sample after the testing you requested is complete;
-
each use of genetic data or a biological sample beyond the primary testing or consultation purpose and inherent contextual uses;
-
each transfer or disclosure of genetic data or a biological sample to a third party other than a service provider, including the third party’s name; and
-
marketing based on genetic data or facilitating third-party marketing based on your purchase or use of a genetic testing product or service.
A privacy notice is not a substitute for a legally required consent. You may revoke consent by emailing clientcare@thednacompany.com or writing to the address in Section 11. We will honor a California genetic-data consent revocation as soon as practicable and no later than 30 days after receipt. If The DNA Company controls a biological sample covered by that request, we will destroy it within the period required by law. For Delaware residents, we will cease processing sensitive data after revocation as soon as practicable and within 15 days when the Delaware Personal Data Privacy Act applies. A laboratory that controls the sample or laboratory record may require a direct request and may retain information when legally required.
We maintain procedures designed to let you access genetic data we control, delete your account and genetic data subject to legal exceptions, and request destruction of a biological sample we control. We do not discriminate against you for exercising a genetic privacy right.
For an identifiable Delaware resident’s genetic information, we obtain informed consent before obtaining or retaining the information, subject to legal exceptions. We do not disclose identifiable genetic information unless you provide informed consent describing the information and recipient or another statutory exception applies. A sample from which genetic information was obtained will be destroyed promptly unless retention is authorized by you or otherwise permitted by Delaware law.
5. Your HIPAA Rights
When The DNA Company maintains PHI about you as a HIPAA covered entity, you have the following rights, subject to HIPAA’s conditions and exceptions:
-
Inspect and obtain a copy. You may inspect or receive a paper or electronic copy of PHI in a designated record set and may direct us to send a copy to another person where permitted. We generally act within 30 days. We may charge only a reasonable, cost-based fee permitted by law and will tell you the cost in advance when required.
-
Request a correction. You may ask us to amend PHI you believe is incorrect or incomplete. We may deny the request for a reason permitted by law, but we will explain the denial in writing and describe your right to submit a statement of disagreement.
-
Request confidential communications. You may ask us to contact you in a particular way or at a particular location. We will accommodate reasonable requests as required by law.
-
Request restrictions. You may ask us to limit certain uses or disclosures for treatment, payment, or health care operations, or disclosures to persons involved in your care. We generally are not required to agree. If you pay in full out of pocket for a health care item or service and ask us not to disclose related PHI to a health plan for payment or operations, we will agree unless disclosure is required by law.
-
Receive an accounting of disclosures. You may request a list of certain disclosures made during the six years before your request. One accounting in a 12-month period is free; we may charge a reasonable, cost-based fee for another after giving you advance notice and a chance to withdraw or modify the request.
-
Receive notice of a breach. We will notify you following a breach of unsecured PHI as required by law.
-
Receive this Notice. You may request a paper copy at any time, even if you agreed to receive it electronically.
-
Choose someone to act for you. A personal representative may exercise your rights if the person has legal authority to act for you. We may verify that authority before acting.
We may deny or limit a request when the law permits. If a denial is reviewable, we will explain how to request review by an independent licensed health care professional.
6. Substance Use Disorder Records
If The DNA Company receives records protected by 42 C.F.R. Part 2 concerning substance use disorder diagnosis, treatment, or referral, additional protections apply. Such records generally may not be used or disclosed in civil, criminal, administrative, or legislative proceedings against you without your specific written consent or a qualifying court order. A consent for use or disclosure in such a proceeding must be separate from consent for another use or disclosure. We will obtain specific consent for uses or disclosures of separately maintained substance use disorder counseling notes when required. You may complain to The DNA Company or the Secretary of the U.S. Department of Health and Human Services about a suspected Part 2 violation, and we will not retaliate against you.
7. State Consumer Privacy Rights
State consumer privacy laws may provide rights in personal information that is not PHI. Depending on your residence and whether a law applies to The DNA Company, you may have the right to:
-
confirm whether we process your personal information and access or obtain a portable copy;
-
know the categories or specific pieces of personal information collected, the sources and purposes, and categories of recipients;
-
correct inaccurate personal information;
-
delete personal information, subject to legal exceptions;
-
obtain a list of the categories of third parties to which personal data was disclosed, where applicable;
-
opt out of sale, sharing, targeted advertising, or qualifying profiling;
-
limit certain uses or disclosures of sensitive personal information; and
-
appeal our refusal to act on a request and exercise your rights without discrimination or retaliation.
California residents also have the genetic-data rights described in Section 4. If the California Consumer Privacy Act applies to The DNA Company, requests will be handled under its verification, timing, frequency, and exception rules. Delaware residents covered by the Delaware Personal Data Privacy Act may exercise applicable rights through the contact methods below. We generally respond to Delaware requests within 45 days and will explain any extension. A Delaware resident may appeal a denial by replying to the denial or using the same request method with the subject “Privacy Appeal.” If we deny the appeal, we will explain how to contact the Delaware Department of Justice.
To submit a request, email clientcare@thednacompany.com with the subject “Privacy Request” or write to the address in Section 11. Describe the right you wish to exercise and the information or account involved. We will use information reasonably necessary to verify your identity and authority. You may use an authorized agent where applicable; we may request proof of authority and identity verification. You do not need to create a new account to make a request.
8. Retention and Deletion
We retain each category of information only for as long as reasonably necessary and proportionate to fulfill the disclosed purposes, provide the requested services, maintain the integrity of consultation and transaction records, comply with legal and regulatory obligations, resolve disputes, enforce agreements, and protect security. The applicable period depends on the type of record, your relationship with us, consent choices, the sensitivity of the information, limitation periods, and mandatory health, tax, accounting, or compliance requirements.
In general:
-
order, fulfillment, payment-status, and customer-service records are retained for the period needed to complete the transaction and satisfy tax, accounting, warranty, dispute, and legal obligations;
-
consultation records and PHI are retained for the period required by applicable health-record and HIPAA documentation rules;
-
genetic reports or interpretations controlled by us are retained while needed to provide your requested service and thereafter only as required or permitted by law, unless you request deletion and no exception applies;
-
consent, authorization, revocation, and privacy-request records are retained for the period required to demonstrate compliance;
-
website security logs are retained for a limited period based on security, fraud-prevention, and troubleshooting needs; and
-
backup copies are deleted or overwritten on our ordinary backup cycle after information is deleted from active systems, unless preservation is legally required.
Independent laboratories establish their own retention and deletion schedules for laboratory records and biological samples. A deletion request does not require us or a laboratory to delete information that applicable law requires or permits to be retained.
9. Security and Breach Notification
We use reasonable and appropriate administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of PHI, genetic data, and other personal information. No system is completely secure. If a breach occurs, we will investigate and provide notice to affected individuals, regulators, and others as required by HIPAA and applicable state law.
10. Our Duties
When HIPAA applies, The DNA Company is required by law to maintain the privacy and security of PHI, provide this Notice of our legal duties and privacy practices, notify affected individuals following a breach of unsecured PHI, and follow the Notice currently in effect.
We may change this Notice and our privacy practices. A revised Notice may apply to information we already hold as well as information received in the future, to the extent permitted by law. We will post the current Notice prominently on our website and make it available on request. A material revision will state a new effective date.
11. Questions, Requests, and Complaints
Contact The DNA Company’s Privacy Officer/HIPAA Compliance contact at:
The DNA Company
Privacy Officer / HIPAA Compliance
650 E. Parkridge Ave., Suite 109
Corona, CA 92879
Email: clientcare@thednacompany.com
You may complain to us if you believe your privacy rights were violated or disagree with a decision about your information. You may also file a HIPAA or Part 2 complaint with the Secretary of the U.S. Department of Health and Human Services, Office for Civil Rights, through https://www.hhs.gov/ocr/privacy/hipaa/complaints/ or by mail to 200 Independence Avenue, S.W., Washington, D.C. 20201.
California consumers may report an alleged violation of California’s Genetic Information Privacy Act to the California Attorney General through https://oag.ca.gov/contact/consumer-complaint-against-business-or-company. Delaware consumers may contact the Delaware Department of Justice, Consumer Protection Unit, through https://attorneygeneral.delaware.gov/fraud/cpu/complaint/.
The DNA Company will not retaliate against you for filing a complaint or exercising a privacy right.
