Two class actions filed in June 2026 allege that genetic testing companies transferred patient data to acquirers without consent, violating state privacy laws. The lawsuits-against Tempus AI and Invitae-expose the legal risks of using healthcare acquisitions to obtain data for AI training.
The cases arrive as companies increasingly buy direct-to-consumer testing firms for their genetic repositories, often to train AI models-a practice scrutinized in AI for Healthcare. In March 2025, 23andMe filed for bankruptcy, and acquirer TTAM Research Institute said it was committed to giving customers "choice and transparency with their data." But no federal law explicitly governs how a company must handle personal health information in such a sale.
HIPAA and FTC Act leave gaps
The Health Insurance Portability and Accountability Act (HIPAA) mandates safeguards for health information transmitted by providers and insurers, but it does not cover direct-to-consumer companies like 23andMe. Section 5 of the FTC Act allows the Federal Trade Commission to pursue "unfair or deceptive acts or practices" if a company misrepresents its privacy practices or fails to use reasonable data security. The FTC sued BetterHelp in 2023 for selling consumers' health information to Facebook despite privacy promises, resulting in a $7.8 million settlement.
State laws become the frontline
In Kreutter v. Tempus AI, Inc., plaintiffs who gave genetic information to Ambry Genetics allege that Tempus AI acquired the company partly to obtain its patient genetic repository and use it for commercial purposes-including training AI models and licensing data-without patients' knowledge or consent. The complaint says the acquisition agreement contemplated transferring sensitive patient data while representing that no additional patient notice or consent was required.
The plaintiffs assert claims under several state statutes, including the Illinois Genetic Information Privacy Act (GIPA), which prohibits disclosure of genetic information without written consent. Other laws cited:
- California Confidentiality of Medical Information Act (CMIA): restricts disclosure of individually identifiable medical information by healthcare providers and other covered entities without authorization.
- Oregon Genetic Privacy Act (GPA): protects genetic information and prohibits disclosure of identifiable HIV-related testing information without authorization.
- New Hampshire Data Privacy Act: limits disclosure and use of genetic information without consent.
- New York General Business Law ยงยง 349 and 350: prohibits deceptive business practices and false advertising, which plaintiffs allege were violated through misleading privacy representations.
The complaint also includes common law claims for negligence and unjust enrichment, alleging Tempus AI improperly benefited from acquiring and commercializing patients' genetic data without required consent.
In a similar case, B.W. v. Invitae Corp., filed in Illinois state court under GIPA, alleges that Invitae unlawfully disclosed patients' genetic information to LabCorp after LabCorp acquired the bankrupt testing company in 2024. These cases test the boundaries of state genetic privacy laws, a topic that legal professionals tracking AI for Legal developments are watching closely.
Why this matters for healthcare professionals
When patient or consumer data is part of an acquisition-especially data originally provided under privacy promises-healthcare executives, compliance officers, and legal teams must confirm that legally effective authorization exists before data changes hands. Without due diligence, acquiring companies risk liability under HIPAA, the FTC Act, state genetic privacy laws, and common law claims. The Tempus AI and Invitae cases signal that plaintiffs are willing to test these obligations in court, making pre-acquisition privacy audits a critical step in any healthcare deal involving sensitive data.
Your membership also unlocks: