CA-C-000062
23andMe — 23andMe Privacy Statement
Entity
Date detected
March 23, 2026
Effective date
March 23, 2026
Severity
Medium
Share 𝕏 Share in Share

What Changed

On March 23, 2026, 23andMe updated their privacy policy with several small but notable changes. The company removed a sentence about a separate Medical Record Privacy Notice for Telehealth Services, changed references from '23andMe Research Institute' to simply '23andMe' in the policy's scope statement, and made a minor formatting adjustment to the mailing address. The removal of the Telehealth notice reference is the most significant change, as users who previously relied on that separate notice for their medical information protections may no longer be clearly directed to those protections.

Why It Matters

The removal of the Telehealth Medical Record Privacy Notice reference means users who have shared sensitive health and medical data through 23andMe's clinical services are no longer explicitly informed of dedicated protections for that data. This is particularly significant given the sensitivity of genetic and medical information and the heightened legal protections that apply to it.

Consumer Impact

23andMe removed explicit mention of a separate Medical Record Privacy Notice that previously informed Telehealth users how their medical information would be used, disclosed, and maintained. This means users who have received or plan to receive Telehealth Services through 23andMe are no longer clearly directed to dedicated medical record privacy protections within this policy. You can contact 23andMe's Privacy Administrator at privacy@23andme.com to ask whether a Medical Record Privacy Notice still exists and how your medical data is being handled.

Institutional Analysis (Compliance & legal intelligence)

Assessment

23andMe removed a sentence explicitly referencing a separate Medical Record Privacy Notice for Telehealth Services on March 23, 2026. This touches HIPAA obligations (45 CFR §164.520 — Notice of Privacy Practices) if 23andMe or its clinical partners qualify as covered entities or business associates. The entity name change from '23andMe Research Institute' to '23andMe' in the policy scope may reflect a corporate restructuring that could affect existing DPAs and vendor contracts. Compliance teams with 23andMe in their vendor stack should verify whether the Telehealth Medical Record Privacy Notice still exists independently and whether any HIPAA NPP obligations remain satisfied.

Regulatory Exposure

1. HIPAA — 45 CFR §164.520: Covered entities and business associates must provide a Notice of Privacy Practices. The removal of the reference to a separate Medical Record Privacy Notice for Telehealth Services raises the question of whether 23andMe or its licensed healthcare provider partners remain compliant with NPP distribution requirements. If clinical services are still offered, the NPP must still exist and be accessible.

🔒

Compliance intelligence locked

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-000062.

Evidence Verification

✓ Verified
Previous Version
b37a75530a5e58b4adb4925d8352285f6cbb8efb8b4d0a5cbee391f80bd40b97
March 19, 2026 14:49 UTC
✓ Verified
Current Version
be863c02dd341ceefbb481ae19e75d132ba37ad264b47f9c54852f31b6a0bcae
March 23, 2026 06:06 UTC
✓ Verified
Change Detected
March 23, 2026 06:06 UTC
✓ Verified
Source Document
https://www.23andme.com/legal/privacy/
How to Cite
ConductAtlas Policy Archive
Entity: 23andMe | Document: 23andMe Privacy Statement | Record: CA-C-000062
Captured: 2026-03-23 06:06:18 UTC
URL: https://conductatlas.com/change/2026-03-23-23andme-23andme-privacy-statement-62/
Accessed: April 4, 2026

Full Changes

-1 sentences removed 3 sentences modified
View complete diff →

Document Context

Document
23andMe Privacy Statement
Entity
23andMe
Captured
March 23, 2026
Source URL
https://www.23andme.com/legal/privacy/
More from 23andMe
Mar 23, 2026 Medium
23andMe Terms of Service

23andMe updated their Terms of Service on March 23, 2026, changing which users these terms apply to. The previous version …

Get alerted when 23andMe changes their policies

Create a free account and add 23andMe to your watchlist. We'll email you the moment something changes.