Evidence: officially disclosed. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 049
- Date / range
- 2021 / 2023 enforcement
- Sector
- Consumer genetics and commercial data
- Genetic asset
- Personal information in an acquired legacy database
- Security principle
- Legacy-System Discovery Failure
Event summary
State attorneys general alleged that DNA Diagnostics Center failed to detect unauthorized access to a legacy database containing information on about 2.1 million people, turning forgotten infrastructure into the breach's central asset.
Source: ohioattorneygeneral.gov — DNA Diagnostics Center 2021 Breach source 1.
The case in context
DNA Diagnostics Center's legacy-system case links an acquisition history to an inventory problem. Regulators alleged that information remained in a database that was not adequately accounted for in the organization's security processes.
Forgotten data remains an asset an intruder may reach. A merger or migration should therefore examine inherited records, logging coverage, and retirement decisions. The company's name is not evidence about which fields were exposed; the enforcement record and notice must supply that scope.
Acquisition and processing
acquired legacy database → incomplete inventory/monitoring → unauthorized access and exfiltration → delayed detection → multistate enforcement
The sequence of events
- acquired legacy database
- incomplete inventory/monitoring
- unauthorized access and exfiltration
- delayed detection
- multistate enforcement
What became inferable or exposed
Personal information in an acquired legacy database
State attorneys general alleged that DNA Diagnostics Center failed to detect unauthorized access to a legacy database containing information on about 2.1 million people, turning forgotten infrastructure into the breach's central asset.
Affected parties and consent
- Direct parties
- People whose records were held in the legacy database
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Security dimensions
Confidentiality
The confidentiality question concerns personal information in an acquired legacy database. The documented scope does not establish disclosure of raw genomic data.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Legacy-System Discovery Failure identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows personal information in an acquired legacy database through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality critical for confirmed fields; integrity unknown; availability low; provenance and asset inventory critical.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-0 unless genetic/kinship data is confirmed. Suggested GPR: score confirmed fields, not branding. Suggested GPI: GPI-1 for system provenance/inventory.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
A DNA-testing company breach is not automatically a DNA-data breach.
Mitigations and lessons
- Merger/acquisition data discovery
- Legacy retirement
- EDR and log coverage
- Segmentation
- Encryption
- Data minimization
- Incident-response testing
- Executive accountability
Primary sources
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-049. DNA Diagnostics Center: The Forgotten Database Behind the Live Network. GeneticSecurity.org. https://geneticsecurity.org/cases/049-dna-diagnostics-center-breach/