US-based DNA Diagnostics Center settled two AG lawsuits last week after hackers stole 2.1M users' data in 2021 from a “legacy” database the company forgot about
Jude Karabus / The Register :
Context & Ripple Effects
This settlement closes the loop on a breach pattern the coverage has tracked across the consumer-genomics industry for years: MyHeritage exposed account info for 92M+ users back in 2018, LabCorp and Quest lost patient records in a shared 2019 breach, and 23andMe saw hackers leverage access to ~14K accounts into ancestry data on 6.9M customers in late 2023.
What distinguishes DNA Diagnostics Center is the cause — attackers pulled 2.1M users' data from a 'legacy' database the company had simply forgotten it owned — and the enforcer: two state attorneys general rather than a class action. The related filing shows where this enforcement path leads, with 23andMe agreeing to pay $30M over its own breach.
First-order effects
- Two state attorneys general extract settlements from DNA Diagnostics Center, adding direct financial and compliance costs on top of a 2021 breach the company disclosed years ago.
- The finding that the stolen data sat in an abandoned database puts DDC's entire data-retention practice under regulator scrutiny, not just its perimeter security.
Second-order effects
- Consumer-genomics peers now have a documented price for negligent retention of genetic data, with the 23andMe settlement as the visible benchmark — raising the incentive to audit and decommission forgotten data stores before, not after, an AG inquiry.
- State AGs gain a repeatable template: multi-state legal action against genetic-data holders converts breach disclosures into enforceable remediation commitments.
Third-order effects
- If forgotten-database breaches keep surfacing, genetic-testing companies face structural pressure toward aggressive data minimization — deleting legacy archives becomes cheaper than carrying them as unpriced regulatory liability.
- Enforcement of genetic-privacy norms consolidates at the state level through coordinated AG settlements, filling the gap left by the absence of a dedicated federal genetic-privacy regime.
The trend: State attorneys general are becoming the de facto enforcement mechanism for genetic-data security, pricing each successive breach settlement higher for consumer-genomics firms.