When a genetic testing company goes bankrupt, its most valuable holding is not its lab equipment. It is the genetic profiles of everyone who ever sent in a saliva sample. That is exactly what played out with 23andMe, whose bankruptcy proceedings put the genetic data of more than fifteen million customers up for sale as a corporate asset, eventually purchased by a research institute founded by the company's former chief executive for several hundred million dollars. Several states objected. A bankruptcy court approved the sale anyway.

That case, alongside a string of recent breaches exposing biometric and health data, points to something worth taking seriously: genetic and biometric information is being treated, legally and financially, as property that can be sold, transferred, or exposed, while the regulatory protections around it remain thinner than most people assume. For anyone thinking about long-term health as an asset worth defending, this is the part of the picture that has nothing to do with medicine and everything to do with ownership.

From the Lab to the Ledger

The core issue is a regulatory gap, not a hypothetical one. HIPAA, the law most people assume protects their health information, generally applies to doctors, hospitals, and insurers, not to direct-to-consumer genetic testing companies or most wearable device makers. That means a company holding a customer's raw DNA sequence, or a wearable maker holding years of heart rate and sleep data, can often share, sell, or lose that data under a much lighter regulatory standard than the one governing a hospital record.

This gap becomes concrete in bankruptcy or acquisition, where a company's data holdings are legally just another asset on the balance sheet, transferable with far less customer consent than most people expect. It also matters after a breach, since genetic and biometric information cannot be changed the way a password or credit card number can. A leaked genetic profile, or a leaked set of fingerprints, stays permanently compromised. Recent incidents, including a large healthcare data breach affecting nearly two million people and a separate exposure of wearable biometric wellness data, both involved exactly this kind of unchangeable personal information.

Bio-Pipeline Ledger

Direct-to-consumer genetic testing data ownership and transfer: largely unregulated at the federal level. The 23andMe bankruptcy demonstrated that genetic data can be sold as a corporate asset during insolvency, with state objections unable to stop the transfer.

HIPAA health data protections: well-established, but narrower than commonly assumed. Covers traditional healthcare providers and insurers, but generally does not extend to wearable device makers or direct-to-consumer genetic and biometric companies.

State-level biometric and wearable privacy laws: emerging and expanding, still inconsistent. A growing number of states now classify biometric and health metrics as sensitive data requiring clear consent before sharing, though coverage and enforcement vary significantly by state.

Federal Trade Commission breach notification and consent rules for health apps and wearables: newly strengthened, narrow in scope. Recent rule updates now treat undisclosed sharing of identifiable health data with third parties, such as advertisers, as a reportable breach, a meaningful but still limited protection.

Data breach response and monitoring services for genetic and biometric exposure: commercially available, imperfect protection. Useful for detecting when personal data appears in a breach, though these services cannot undo the exposure of data that, unlike a password, can never be reset.

The Clinical Reality Check

What is genuinely true today is that the legal protections around genetic and biometric data remain significantly weaker than most people assume, and recent events, from a major bankruptcy sale to multiple biometric data breaches, have made that gap concrete rather than theoretical. This is not a reason to avoid genetic testing or health wearables altogether, both offer real value, but it is a reason to read the actual data policy of any company handling that information before sending in a sample or strapping on a device.

What remains unresolved is the underlying legal framework itself. State laws and federal rules are expanding, but unevenly, and a genetic testing company's bankruptcy filing or corporate sale can still move sensitive data in ways a typical consumer never anticipated. The realistic, actionable step is treating a company's data retention, deletion, and transfer policy as seriously as its product marketing, since that policy, not the marketing, determines what actually happens to a person's genetic and biometric information over the long run.