CA-C-001149
23andMe — 23andMe Privacy Statement
Entity
Date detected
March 23, 2026
Effective date
March 23, 2026
Severity
Direction
Negative
Affected users
all users telehealth service users
Taxonomy
Transparency removal
Changes
−1 sentence removed · 2 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch 23andMe Get alerts when this policy changes.
Watch — Free

Event Summary

23andMe removed a reference to its Research Institute from the opening scope statement, changing 'websites owned and operated by 23andMe Research Institute' to 'websites owned and operated by 23andMe'. The company also removed an entire sentence describing a separate Medical Record Privacy Notice for telehealth services and made minor formatting corrections to the contact address. These changes narrow the explicit organizational scope and remove disclosure of a parallel privacy notice that previously applied to certain healthcare-related services.

MEDIUM

Consumer Impact

The updated privacy statement no longer explicitly discloses a separate Medical Record Privacy Notice that previously described how medical information is used, disclosed, and maintained for telehealth services. Users who receive telehealth services coordinated through 23andMe may now lack clear notice of which privacy framework governs their medical records, since the reference to that parallel notice has been removed. The organizational scope change from '23andMe Research Institute' to '23andMe' narrows the explicitly named entities responsible for the policy, though operational impact depends on how these entities actually function.

Governance Analysis

The removal of Medical Record Privacy Notice disclosure eliminates explicit notice to users that their medical records are governed by a separate privacy framework. Under HIPAA and state medical privacy laws, healthcare providers and business associates must clearly disclose privacy practices for protected health information. If 23andMe continues telehealth services, this removal creates regulatory compliance risk and leaves users without clear notice of how medical data is protected.

Available Actions

If you use 23andMe telehealth services, request a copy of the Medical Record Privacy Notice directly from 23andMe to confirm what privacy protections apply to your medical records.

Review whether your own medical provider or health plan references 23andMe's privacy policies in their disclosures to you, and confirm the scope of what privacy rules actually govern your records.

If No Action Is Taken

Without explicit notice of a separate Medical Record Privacy Notice, telehealth users may not understand which privacy rules govern their medical records or how their data differs from genetic data.

If the notice no longer exists or is not accessible, users lack clear disclosure of medical information privacy practices as required by HIPAA and state law.

Key Clauses Affected

Medical Record Privacy Notice disclosure

Removed language stating that a separate Medical Record Privacy Notice describes privacy practices for telehealth services and medical information.

Organizational scope identification

Changed from '23andMe Research Institute' to '23andMe', narrowing explicit organizational identification in policy scope.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch 23andMe — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
b37a75530a5e58b4adb4925d8352285f6cbb8efb8b4d0a5cbee391f80bd40b97
March 19, 2026 14:49 UTC
✓ Verified
Current Version
be863c02dd341ceefbb481ae19e75d132ba37ad264b47f9c54852f31b6a0bcae
March 23, 2026 06:06 UTC
✓ Verified
Change Detected
March 23, 2026 06:06 UTC
Analysis Methodology
✓ Verified
Source Document
https://www.23andme.com/legal/privacy/
Citation Record
Entity: 23andMe
Document: 23andMe Privacy Statement
Record ID: CA-C-001149
Captured: 2026-03-23 06:06:18 UTC
URL: https://conductatlas.com/change/2026-03-23-23andme-23andme-privacy-statement-1149/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
Protection removed
Consumers Removed

Users of telehealth services are no longer explicitly told in the main privacy statement that a separate, more detailed privacy notice describes how their medical records are handled.

For legal and compliance teams

Institutional Analysis

Assessment

23andMe removed explicit reference to a separate Medical Record Privacy Notice that previously disclosed privacy protections for telehealth services. This removal may create regulatory exposure under HIPAA and state medical privacy laws if telehealth services continue and medical records are still collected and maintained. The removal also potentially impacts GDPR and CCPA compliance obligations, which generally require clear notice of separate or parallel processing activities affecting different categories of personal data. A compliance team should verify whether telehealth services remain operational and, if so, confirm that a separate medical privacy notice still exists and is accessible to affected users. If the notice has been eliminated entirely, the policy may no longer adequately disclose medical record handling practices required under applicable law.

Regulatory Exposure

HIPAA, CCPA, GDPR, state medical privacy laws

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001149.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
23andMe Privacy Statement
Entity
23andMe
Captured
March 23, 2026
Source URL
https://www.23andme.com/legal/privacy/
Other changes to 23andMe Privacy Statement
Next change Apr 19, 2026
23andMe updated its Privacy Statement on April 19, 2026 to clarify that the policy applies to websites owned and operated …
Low Neutral
View full version history →
More from 23andMe
May 5, 2026 Medium
23andMe Privacy Statement

23andMe removed a sentence that described separate privacy protections for telehealth services and updated references to the company name in …

May 5, 2026 Medium
23andMe Terms of Service

23andMe restructured the opening section of its Terms of Service on May 5, 2026, making three operational changes: (1) The …

Apr 19, 2026 Low
23andMe Privacy Statement

23andMe updated its Privacy Statement on April 19, 2026 to clarify that the policy applies to websites owned and operated …

Related Analysis
Privacy · April 16, 2026
23andMe Is Bankrupt. What Happens to Your DNA Now?

Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do…

Track 23andMe policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.