Theranos: The Billion Dollar Lesson in AI Evidence Gates
Preventive Care

23andMe Breach: A Billion Dollar Procurement Lesson for AI SaMD

Listen to this article · 6 min listen

When credential stuffing hits a consumer genomic database, privacy stops being a policy document and becomes a front-page disaster. This is why you must verify a vendor’s security posture before you sign anything.

Breach Record Analysis

The 23andMe breach was a classic example of this, where attackers gained access to consumer genetic information through credential stuffing, not a direct system hack. This attack showed just how vulnerable large-scale data aggregation is when basic user-side security fails, leading to the exposure of intensely personal and genetic data. The Federal Trade Commission (FTC) jumped in with an investigation FTC statement on data breaches, putting a regulatory spotlight on the security lapse. The financial fallout was severe: 23andMe filed for bankruptcy in March 2025. Then, in July 2026, the company had to pay an $18 million settlement to 41 states and D.C. over the 2023 breach, which also saddled it with new data protection requirements and oversight from a security advisory board. The FTC Chairman didn’t let up during the bankruptcy either, publicly reminding 23andMe of its duty to honor its data privacy and security promises. In a strange final twist, 23andMe’s customer data ended up being sold to TTAM Research, a non-profit formed by the company’s own founder and former CEO.

Regulatory Frameworks and Vendor Accountability

The HIPAA Security Rule sets the floor for protecting electronic protected health information (ePHI), and it requires covered entities to apply these standards to all their vendors, including the AI health tools and platforms popping up everywhere. These rules specify the administrative, physical, and technical safeguards needed to stop unauthorized ePHI access. But just having a Business Associate Agreement (BAA) isn’t enough. Health IT research by Julia Adler-Milstein Julia Adler-Milstein research on health IT governance shows a persistent gap between what security policies say and what health systems actually do. It turns out that corporate governance structures are notoriously bad at judging external vendor risk, which results in sloppy due diligence on security protocols. They get the BAA signed but fail to ask the hard questions.

Comparative Privacy Enforcement Patterns

Look at Cerebral as another case study in privacy enforcement. The company got in hot water for sharing sensitive patient data with third-party advertisers, and the FTC brought an enforcement action against them FTC enforcement action against Cerebral for not getting proper patient consent. By April 2024, Cerebral agreed to a settlement that cost it over $7 million and came with a permanent ban on using health information for most advertising. They were also forced to implement a real privacy and security program and make it easier for customers to cancel, with refunds going out to eligible customers starting in May 2025. Taken together, the 23andMe and Cerebral enforcement actions show that these privacy screw-ups are a systemic problem, not isolated incidents. And all of this happens within the same regulatory world as the FDA’s Center for Devices and Radiological Health (CDRH), where health data often intersects with regulated medical devices. The FDA clearance and approval history for AI health tools is publicly verifiable information, it’s an objective report card on a product’s compliance and safety. A product without that clear regulatory paper trail is a much bigger gamble.

Due Diligence for Trustworthy AI Healthcare Platforms

Vendor due diligence has to go way beyond basic compliance checks. You need to be doing deep dives into a vendor’s security architecture, validating their encryption methods, their access controls, and their entire incident response plan. So, what should privacy officers and data governance leads be asking?

  • What specific security certifications do you actually hold (e.g., HITRUST, SOC 2 Type II)?
  • How are you managing user authentication and authorization for sensitive data access in practice?
  • Show me the documented process for incident detection, response, and notification.
  • Are data minimization principles actually applied to data collection and processing?
  • Can you provide granular audit logs for all data access and modification events?
  • What are your data retention and deletion policies, and how can we audit them?
  • How do you ensure the security of your own third-party sub-processors or partners?

These questions aren’t just for show, they’re designed to probe the real operational security controls of a potential vendor. The public record makes it painfully clear that a vendor’s security posture is verifiable before you sign the contract. If you fail to do this work upfront, the risks are very, very real.

Frequently Asked Questions

What kind of breaches are impacting sensitive consumer genomic data at scale?

Credential-based breaches are exposing sensitive consumer genomic data at scale. The 23andMe incident, for example, involved unauthorized access to consumer genetic information through compromised user credentials, not direct system infiltration. This highlights the critical vulnerabilities in large-scale data aggregation when user authentication is compromised.

What is the role of the HIPAA Security Rule in vendor accountability for health plans?

The HIPAA Security Rule establishes a framework for covered entities, mandating safeguards for electronic protected health information (ePHI). Health plans must apply these standards to all vendors handling protected data, including AI health tools and platforms. Vendor contracts must reflect these requirements through legally binding Business Associate Agreements (BAAs) to ensure compliance with HIPAA provisions.

What are the consequences of inadequate vendor due diligence regarding security protocols?

Inadequate due diligence on security protocols, often stemming from underestimating external vendor risks, can lead to significant privacy lapses and regulatory enforcement actions. The cases of 23andMe and Cerebral illustrate that such failures can result in investigations by the FTC, substantial financial settlements, and mandated implementation of comprehensive privacy and security programs. This demonstrates that failure to conduct thorough due diligence results in demonstrable risks.

What specific security certifications should health plans inquire about from potential vendors?

Health plans should inquire about specific security certifications the vendor holds, such as HITRUST or SOC 2 Type II. These certifications provide an objective measure of a vendor’s regulatory compliance and safety profile, moving beyond superficial assurances to probe their operational security controls. This is part of rigorous security posture assessments that extend beyond basic compliance checks.

Share
Was this article helpful?

Editorial Team

The editorial team behind Trustworthy Health AI.