CA-C-001624
23andMe — 23andMe Privacy Statement
Entity
Date detected
May 5, 2026
Effective date
May 5, 2026
Severity
Direction
Negative
Affected users
all users us users telehealth service users
Taxonomy
Transparency removal
Changes
−1 sentence removed · 2 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch 23andMe Get alerts when this policy changes.
Watch — Free

Event Summary

23andMe removed a sentence that described separate privacy protections for telehealth services and updated references to the company name in the scope statement and contact section. The removed language previously directed users to a separate Medical Record Privacy Notice for telehealth-related medical information. The updated privacy statement no longer explicitly references this separate notice or explains how medical information collected through telehealth services is handled under different privacy rules.

MEDIUM

Consumer Impact

The updated privacy statement no longer explicitly directs users to a separate Medical Record Privacy Notice for telehealth services or explains that medical information collected through telehealth is governed by different privacy rules. Previously, the policy stated that users choosing telehealth services coordinated through 23andMe would find healthcare privacy protections described in a separate notice. That reference is now absent from the main privacy statement. Users seeking privacy information specific to telehealth services will need to determine independently whether a separate notice exists or contact 23andMe directly using the provided contact information.

Governance Analysis

The updated policy removes explicit guidance that medical information collected through telehealth services is governed by separate privacy terms. This affects how users understand the scope of privacy protections applicable to healthcare information, and may create ambiguity about whether the main privacy statement or separate healthcare-specific terms govern medical records collected through telehealth. Organizations using 23andMe telehealth services should verify whether separate healthcare privacy protections remain in effect and how they are now disclosed.

Available Actions

Contact 23andMe using privacy@23andme.com or 1-800-239-5230 to request clarification on whether a separate Medical Record Privacy Notice for telehealth services remains in effect and where to find it.

Review any separate healthcare privacy documentation 23andMe provides for telehealth services to understand medical information protections.

If No Action Is Taken

Users may not realize that medical information collected through telehealth services may be subject to different privacy rules than the main privacy statement describes.

Disputes about medical information privacy handling may arise if the applicable privacy terms are unclear or no longer referenced in the main policy.

Historical Context

This is the 2nd significant Transparency Removal change 23andMe has made since ConductAtlas began monitoring.

ConductAtlas has recorded 2 material changes to this document over 43 days of monitoring (since March 2026). An additional minor or cosmetic changes were excluded.

Across all monitored documents, 23andMe has made 5 significant changes.

3 of 23andMe's significant changes have been classified as negative for consumers.

Key Clauses Affected

Scope of Privacy Statement application

Removed language stating that users of telehealth services are covered by a separate Medical Record Privacy Notice, creating ambiguity about privacy protections for healthcare information.

Company name references

Updated references from '23andMe Research Institute' to '23andMe' in scope statement and contact information, a minor organizational clarification.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch 23andMe — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
4851ad5bc2887091dff5a5fdc05b1c8baf2f5ae01a36da01d5f8c2bc3e1ced68
April 19, 2026 06:10 UTC
✓ Verified
Current Version
63c2151dde4633ecb5dd07963f13c680243c0545eff1c5db6595cc32e105ce41
May 5, 2026 08:13 UTC
✓ Verified
Change Detected
May 5, 2026 08:13 UTC
Analysis Methodology
✓ Verified
Source Document
https://www.23andme.com/legal/privacy/
Citation Record
Entity: 23andMe
Document: 23andMe Privacy Statement
Record ID: CA-C-001624
Captured: 2026-05-05 08:13:40 UTC
URL: https://conductatlas.com/change/2026-05-05-23andme-23andme-privacy-statement-1624/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
Protection removed
Consumers Removed

Users can no longer find in the main privacy policy an explanation that medical information from telehealth services is covered by separate privacy rules.

For legal and compliance teams

Institutional Analysis

Assessment

23andMe removed language that previously directed users to a separate Medical Record Privacy Notice for telehealth services. This creates potential clarity and disclosure issues: users engaging telehealth services may no longer understand that healthcare information may be subject to separate privacy terms, and the main privacy policy no longer explains the scope of protections for medical records. If telehealth services remain subject to HIPAA or state healthcare privacy laws, the removal of this reference may obscure how those legal obligations differ from 23andMe's general privacy statement. Organizations relying on 23andMe's services through business partnerships should verify whether this removal affects how health information privacy is disclosed to their own users or customers.

Regulatory Exposure

HIPAA, state healthcare privacy laws (medical records), FTC Act Section 5 (unfair or deceptive practices if material privacy protections are not disclosed)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001624.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
23andMe Privacy Statement
Entity
23andMe
Captured
May 5, 2026
Source URL
https://www.23andme.com/legal/privacy/
Other changes to 23andMe Privacy Statement
Previous change Apr 19, 2026
23andMe updated its Privacy Statement on April 19, 2026 to clarify that the policy applies to websites owned and operated …
Low Neutral
View full version history →
More from 23andMe
May 5, 2026 Medium
23andMe Terms of Service

23andMe restructured the opening section of its Terms of Service on May 5, 2026, making three operational changes: (1) The …

Apr 19, 2026 Low
23andMe Privacy Statement

23andMe updated its Privacy Statement on April 19, 2026 to clarify that the policy applies to websites owned and operated …

Apr 19, 2026 High
23andMe Terms of Service

23andMe restructured its Terms of Service on April 19, 2026, making several material changes to scope and dispute resolution. The …

Related Analysis
Privacy · April 16, 2026
23andMe Is Bankrupt. What Happens to Your DNA Now?

Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do…

Track 23andMe policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.