Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Orders 1Health.io to Pay $75K for Genetic Data Security and Deception

1Health.ioSeptember 7, 2023Federal Trade Commission

Penalty Amount

$75,000

Summary

The FTC finalized an order against 1Health.io for failing to secure genetic data and unfairly changing its privacy policy. The company must pay $75,000 for consumer refunds, destroy DNA samples, and implement security measures. It deceived consumers about data deletion and shared data without proper consent.

Remedy

1Health.io must pay $75,000 for consumer refunds, instruct third-party laboratories to destroy all consumer DNA samples retained for more than 180 days, prohibit sharing health data without affirmative express consent, notify the FTC about unauthorized disclosures, and implement a comprehensive information security program.

Monetary PenaltyConsumer RefundsData DeletionInjunctionReporting RequirementsCompliance Program

Contract Impact

In-house legal teams should review all vendor and customer agreements, particularly those involving the processing of genetic, health, or biometric data. Focus on clauses governing data security standards (e.g., encryption requirements), privacy policy change mechanisms (including notice and consent provisions), data deletion and destruction obligations, and limitations on data sharing. Given the findings of deceptive practices and inadequate security, contracts must be amended to include explicit, opt-in consent for any retroactive privacy policy changes, mandate specific technical safeguards for sensitive genetic data (like encryption at rest and in transit), and enforce strict, time-bound protocols for the complete destruction of DNA samples and associated data upon request or after analysis. Additionally, ensure data processing addendums for genetic data incorporate these heightened standards and provide clear audit rights.

Contract Search Terms

genetic data security clauseprivacy policy amendment consentdata deletion guaranteeDNA sample destruction protocolretroactive policy change prohibitionsensitive health data sharing consentunencrypted data storage prohibitionconsumer data access and deletion rightssecurity incident notification requirementdata processing addendum for genetic information

Violation Types

Entity Details

Entity

1Health.io

Also known as: 1Health

Industry

Healthcare

Official Sources

Source Evidence

Entity Name
"1Health.io"
Fine Amount
"must pay $75,000"
Violation Types
"charges that the genetic testing firm left sensitive genetic and health data unsecured, deceived consumers about their ability to get their data deleted, and changed its privacy policy retroactively without adequately notifying consumers and obtaining their consent."

Related Enforcement Actions

FTC

1Health.io

$50K

The FTC settled with genetic testing company 1Health.io for failing to secure sensitive genetic and health data, deceiving consumers about data deletion, and unfairly changing its privacy policy without notice or consent. The settlement includes refunds totaling over $49,500 to 2,432 affected consumers.

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.

FTC

Federal Trade Commission

The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.

FTC

Chase Nissan LLC

$4.0M

The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.

FTC

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

FTC

Federal Trade Commission

The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.