Evidence: officially disclosed. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 011
- Date / range
- 2023
- Sector
- Consumer genetics and commercial data
- Genetic asset
- DNA and health records in cloud storage
- Security principle
- Deletion Integrity and Cloud Exposure
Event summary
The FTC's 1Health/Vitagene matter shows that genetic privacy promises fail when cloud permissions, deletion workflows, vendor access, and public representations do not match operational reality. Genetic security therefore includes not only preventing theft, but proving that promised deletion and access restrictions actually occur.
Source: ftc.gov — 1Health / Vitagene FTC Enforcement source 1.
Source: ftc.gov — 1Health / Vitagene FTC Enforcement source 2.
The case in context
The FTC matter centers on the distance between a privacy promise and the systems expected to carry it out. Its allegations concerned DNA and health information, cloud access, and representations about deletion. The enforcement outcome must be understood as an order resolving charges, rather than a trial establishing every alleged fact.
Deletion is a workflow, not just a button. An assessment needs to follow the consumer's request through the account, laboratory, storage provider, and retained copies. The useful question is whether the organization can demonstrate the result it promised. Access restrictions and deletion records belong in the same lifecycle review.
Acquisition and processing
consumer test → cloud storage/configuration → excessive or public accessibility → persistent data → representations about security/deletion → regulatory action
The sequence of events
- consumer test
- cloud storage/configuration
- excessive or public accessibility
- persistent data
- representations about security/deletion
- regulatory action
What became inferable or exposed
DNA and health records in cloud storage
The FTC's 1Health/Vitagene matter shows that genetic privacy promises fail when cloud permissions, deletion workflows, vendor access, and public representations do not match operational reality. Genetic security therefore includes not only preventing theft, but proving that promised deletion and access restrictions actually occur.
Affected parties and consent
- Direct parties
- Consumers whose testing information was held by 1Health
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Security dimensions
Confidentiality
The confidentiality question concerns dna and health records in cloud storage. Exposure and further inference must be distinguished from the fact of collection or availability.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Deletion Integrity and Cloud Exposure identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows dna and health records in cloud storage through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality high; integrity moderate because deletion-state accuracy is at issue; availability low; provenance moderate; consent high; persistence high; relational exposure depends on data fields.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-1/2. Suggested GPR: GPR-4. Suggested GPI: GPI-1/2 where deletion and custody cannot be independently demonstrated.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
The matter does not establish that every customer genome was public or that all affected records contained the same fields.
Mitigations and lessons
- Private-by-default object storage
- Least privilege
- Continuous configuration monitoring
- Immutable access logs
- Tested deletion attestations
- Backup-expiration rules
- Vendor inventories
- Truthful privacy notices
- Post-deletion sample destruction evidence
Primary sources
- PRIMARY SOURCE ftc.gov — 1Health / Vitagene FTC Enforcement source 1
- PRIMARY SOURCE ftc.gov — 1Health / Vitagene FTC Enforcement source 2
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-011. Vitagene and the FTC: Genetic Data Left in the Cloud. GeneticSecurity.org. https://geneticsecurity.org/cases/011-1health-vitagene-genetic-data-security/