If all the Court considers is the language of GINA, the undisputed evidence in the record establishes that the DNA analysis at issue here clearly falls within the definition of “genetic test.”Now, a federal jury has awarded $500,000 in compensatory damages and $1.75 million in punitive damages to the two plaintiffs. This case is likely to remain somewhat idiosyncratic in its facts, but it signals a broad interpretation for the protection afforded to employees by GINA, which should insulate them from any attempt by employers to use genetic information for general retainment purposes, even when the DNA information is non-medical in nature. Of course, the plaintiffs alleged that the acquisition of their genetic information for arguably limited purposes still allowed an employer the possibility of testing that DNA sample for other medically-related information, or to keep the sample for such purposes later; one could imagine scenarios where an employer might try to obscure the purpose for testing by hiding behind a forensic pretext. This case makes that less likely. Thus, the case is notable as the first GINA case in federal court to interpret the scope of subject matter encompassed by the statute; its conclusion that GINA is to be read broadly sets a genetic privacy baseline. To date, GINA has been largely been invoked not in private litigation, but in complaints submitted to the Equal Employment Opportunity Commission (EEOC) (see here).
Showing posts with label Genetic Privacy. Show all posts
Showing posts with label Genetic Privacy. Show all posts
June 26, 2015
Federal Court Establishes Broad Scope of Genetic Privacy Under Genetic Information Nondiscrimination Act (GINA)
In a first of its kind case involving the scope of genetic privacy afforded by federal law, a federal court has ruled that an employer violated the Genetic Information Nondiscrimination Act (GINA) when it requested DNA samples from two employees for an internal investigation. In Lowe v. Atlas Logistics Group Retail Services (N.D. Ga) a grocery distributor in Atlanta, Georgia (Atlas) was confronted with several instances where it appeared that an employee had defecated on a grocery warehouse floor. In order to determine the culprit, Atlas requested DNA samples from two employees suspected of committing these acts. The employees provided saliva for the DNA testing, but were excluded as suspects. However, the employees went on to sue the company for violating GINA, the federal law which prohibits employers from using genetic information they may acquire to discriminate in hiring, promotion or firing decisions. Employers are also barred from requesting genetic information of employees except in very limited circumstances. Until this case, there was almost no contemplation of scenarios where an employer might request genetic information for a forensic purpose in the context of actual employment (most allegations of GINA violations concern employer access to medical genetic information). However, the plaintiffs alleged that the Atlas request, albeit for non-medical purpose, violated a general GINA prohibition on employer access to genetic information. Atlas contended that the requested genetic information was not covered by GINA, and that the statute was intended to apply only to the gathering of disease-related medical information. The federal judge disagreed and sided with the plaintiffs, finding that Atlas had indeed violated GINA:
May 16, 2014
FTC Settles Litigation That Targeted Deceptive Marketing of Genetic Tests and Treatments
In its first law enforcement action in the personalized genomics sector, the Federal Trade Commission (FTC) has entered a final consent order against several personal genomics companies for engaging in business practices that deceived consumers. In general, personalized genomics companies follow several business models. A company may offer genetic testing services in which a consumer pays to have her DNA analyzed for mutations that, in the company's claim, are alleged to correlate with various medical conditions or susceptibilities. In another model, genomics companies provide genetic testing and also offer products which are alleged to treat or alleviate the medical conditions identified by the DNA testing. GeneLink, Inc. and its former subsidiary, foru International Corporation, followed the second model and offered what were claimed to be “genetically guided personalization of nutrient and skin care formulations” as part of a general anti-aging portfolio of services and products. The FTC filed a complaint against GeneLink and foru for statements and practices that violate the Federal Trade Commission Act, which prohibits false advertising and “unfair or deceptive trade practices.” The FTC complaint recited promotional materials from GeneLink:
[B]y analyzing and understanding your unique genetic strengths and weaknesses, you can eliminate the guesswork and “genetically guide” the optimal nutritional supplement or skincare formulation to match your LifeMap Healthy Aging Assessment®.The FTC cited the scope of the claims made by GeneLink:
According to ads and other promotional materials, the supplements could treat serious conditions like diabetes, heart disease, arthritis, and insomnia. Claims for the skin serum cited a “double blind, randomized and controlled study” and promised the product would “compensate for particular deficiencies in areas of skin aging, wrinkling, collagen breakdown, irritation, and the skin’s ability to defend against environmental stress.”The violation of the FTC Act was recited in the complaint:
12. Through the means described in Paragraph 11, respondents have represented, expressly or by implication, that genetic disadvantages identified through respondents’ DNA Assessments are scientifically proven to be mitigated or compensated for with nutritional supplementation.
13. In truth and in fact, genetic disadvantages identified through respondents’ DNA Assessments are not scientifically proven to be mitigated or compensated for with nutritional supplementation. Therefore, the representation set forth in Paragraph 12 was, and is, false or misleading.Following a period of public comment, a final consent order was entered to settle the charges brought against the companies. The companies are now prohibited from offering products for purposes not supported by credible scientific data and the level of scientific support required for health-related claims is specified:
“[C]ompetent and reliable scientific evidence” shall consist of at least two adequate and well-controlled human clinical studies.This FTC action no doubt puts the personalized genomics sector on notice that dubious claims for genetic “treatments” will be subject to FTC monitoring and enforcement actions. This action also exemplifies how the FTC, as the federal consumer protection agency, employs its broad mandate to capture many potentially deceptive business practices in a high-technology areas: the companies were also charged with inadequate data security practices with respect to the collection of consumer information, and the consent order further requires the companies to institute appropriate data security measures for any future data collection. More generally for the genomics sector, the FTC action follows the Food and Drug Administration's (FDA) 2013 warning to 23andme, one of the leading providers of personalized DNA testing, that its services constituted the marketing of an unapproved medical device in violation of the Federal Food, Drug and Cosmetic Act; the company then took corrective actions in removing certain health-related reporting from its products.
October 24, 2012
Presidential Commission Advances Privacy Concerns in Genetic Testing
The Presidential Commission for the Study of Bioethical Issues (PCSBI) has issued a report on one of the intersections between genetic testing and privacy. The PCSBI was established by President Obama; to date, their only other report focused on the regulatory landscape for synthetic biology (more here). Now, the Commission has published Privacy and Progress in Whole Genome Sequencing, which examines how the increasing availability of whole genome sequencing (WGS, where the full DNA sequence of a genome is obtained) in both clinical and research settings has to be matched with an attention to how such data is used in a manner that protects the privacy of the patient and/or research subject. The report illustrates the legal complexity of privacy in American law generally – a very mixed portfolio of (sectoral) protections. The legal concerns with the widespread introduction of genetic information into science and medicine are several and concern whether an individual has control of when genetic testing occurs, when genetic information can be disclosed, and how genetic information can be used. With respect to genetic information, much of the legal attention has focused on the issue of genetic discrimination, which concerns use, and has not focused on genetic privacy. Most simply, privacy is concerned with disclosure, while discrimination is concerned with misuse. Can the privacy of “genetic information” be protected with existing law? Is a genomic DNA sequence a category of "personally identifiable information" (PII), meriting special protection from unauthorized disclosure? In general, medical information generated during patient care is protected by the Health Insurance Portability and Accountability Act (HIPAA), which makes a provider accountable for maintaining both patient confidentiality and privacy of medical records. But, as the commission notes, it is not clear whether genetic or genomic information is always included in the protected health information that HIPAA addresses. Since 2008, the U.S. has the Genetic Information Nondiscrimination Act (GINA), which protect individuals from discrimination based on the use of their genetic information in employment and health insurance. Notably, it does not extend to the provision of life, long-term care or disability insurance.
The PCSBI report particularly focuses on how genetic information derived in the research setting will be protected from unauthorized disclosure, a project that not only requires the cooperation of researchers and health institutions, but auxiliary participants, such as database managers. Very generally, the U.S. does have norms for the protection of human subjects generally, most notably the Common Rule, which establishes standards to protect human research subjects and is applicable to all federally-funded research. While a patient can rely on HIPAA for some medical privacy, the research subject needs to be protected against the unauthorized disclosure of personally identifiable genetic information outside the medical care setting. One of its most significant recommendations is that no WGS be conducted without the consent of the individual. While that may sound straightforward and sensible, this point is relevant to the uses of surreptitious genetic testing that occur in criminal law, for example, but could be performed in other contexts (e.g., this issue addressed with the pending California bill on genetic privacy, SB 1267, which would “prohibit any person, as defined, from obtaining, analyzing, or disclosing genetic information without the written authorization of the individual to whom the information pertains”). The report notes a very uneven set of protections against unauthorized genetic testing and disclosure across the states. In total, the report calls attention to the wide array of entities that are involved in the processing of genetic information – not only scientific and medical, but third party data handlers – and calls for standardization of informed consent procedures to protect individual choice regarding genetic testing and its disclosure. It asks funders of such research to monitor privacy protections as a part of their review. While the report did focus on the ethical introduction of WGS into wider use, its recommendations are relevant to all types of genetic information and might serve to incorporate privacy safeguards as a routine dimension of genetically-based medical care and research.
The PCSBI report particularly focuses on how genetic information derived in the research setting will be protected from unauthorized disclosure, a project that not only requires the cooperation of researchers and health institutions, but auxiliary participants, such as database managers. Very generally, the U.S. does have norms for the protection of human subjects generally, most notably the Common Rule, which establishes standards to protect human research subjects and is applicable to all federally-funded research. While a patient can rely on HIPAA for some medical privacy, the research subject needs to be protected against the unauthorized disclosure of personally identifiable genetic information outside the medical care setting. One of its most significant recommendations is that no WGS be conducted without the consent of the individual. While that may sound straightforward and sensible, this point is relevant to the uses of surreptitious genetic testing that occur in criminal law, for example, but could be performed in other contexts (e.g., this issue addressed with the pending California bill on genetic privacy, SB 1267, which would “prohibit any person, as defined, from obtaining, analyzing, or disclosing genetic information without the written authorization of the individual to whom the information pertains”). The report notes a very uneven set of protections against unauthorized genetic testing and disclosure across the states. In total, the report calls attention to the wide array of entities that are involved in the processing of genetic information – not only scientific and medical, but third party data handlers – and calls for standardization of informed consent procedures to protect individual choice regarding genetic testing and its disclosure. It asks funders of such research to monitor privacy protections as a part of their review. While the report did focus on the ethical introduction of WGS into wider use, its recommendations are relevant to all types of genetic information and might serve to incorporate privacy safeguards as a routine dimension of genetically-based medical care and research.
February 3, 2012
Newborn Genetic Testing Programs Confront Genetic Privacy Concerns
One of the flashpoints in ongoing controversies over genetic testing is the state newborn screening programs which mandate the collection of blood samples from babies to be tested for a panel of genetic and congenital disorders. These dried blood samples, which represent a fairly comprehensive biological repository of the population, have been collected since the 1960’s and can be characterized today as a “biobank.” As informational privacy is increasingly recognized as a right in the era of genetic-based medicine, the older newborn screening laws are colliding with modern genetic privacy laws. Many states lack any procedures for obtaining parental consent for the retention or future use of the dried blood samples. This was the basis for two lawsuits, in Minnesota and Texas, in which parents challenged the practice of indefinite retention of the newborn blood samples as a violation of laws guaranteeing genetic privacy or parental consent. Settlement of the Texas lawsuit resulted in the destruction of 5 million samples that had been collected since 2002, but were retained without parental consent. In the Minnesota lawsuit, which pitted the state’s Genetic Privacy Act against the newborn screening law, the court decision will at least result in the destruction of samples that were retained without parental consent since the ruling in 2011, and may result in the destruction of the approximately one million samples stored in the biobank since 1997.
The American College of Medical Genetics (ACMG) has asserted that the newborn samples can be retained with sufficient privacy protections, and that the retention of samples provides a source of material for the development and evaluation of future tests: "Such destruction of dried blood spots would significantly and negatively impact the quality and development of newborn screening programs.” While actual test results are reported to parents, according to the ACMG, the use of these samples for future research in a privacy-protective manner can be done by “use of either anonymized (no individual identifying link is retained) or deidentified (individual identity link retained and privacy and confidentiality maintained under the stewardship of the public health programs) dried blood spots.” But that's the technical implementation. These lawsuits challenge whether parental consent has been obtained and provide a cautionary tale for other jurisdictions. Thus, we may see more attempts by the states to formalize consent protocols in the newborn screening programs in order to capture the emerging concerns over genetic privacy while forestalling the possibility that existing biobanks which developed in an earlier era but hold a wealth of population-wide medical information might be destroyed through court order. It’s clear that the absence of procedural (and now legal) rigor in these programs, coupled with increasing public sensitivity to all kinds of data privacy (including genetic) will undermine confidence and participation in these programs. Moreover, as newborn screening programs present the most ubiquitous contact that the general public has with genetic testing, the care and diligence in their administration certainly shapes the more generalized public view of genetic testing and its promises or drawbacks.
The American College of Medical Genetics (ACMG) has asserted that the newborn samples can be retained with sufficient privacy protections, and that the retention of samples provides a source of material for the development and evaluation of future tests: "Such destruction of dried blood spots would significantly and negatively impact the quality and development of newborn screening programs.” While actual test results are reported to parents, according to the ACMG, the use of these samples for future research in a privacy-protective manner can be done by “use of either anonymized (no individual identifying link is retained) or deidentified (individual identity link retained and privacy and confidentiality maintained under the stewardship of the public health programs) dried blood spots.” But that's the technical implementation. These lawsuits challenge whether parental consent has been obtained and provide a cautionary tale for other jurisdictions. Thus, we may see more attempts by the states to formalize consent protocols in the newborn screening programs in order to capture the emerging concerns over genetic privacy while forestalling the possibility that existing biobanks which developed in an earlier era but hold a wealth of population-wide medical information might be destroyed through court order. It’s clear that the absence of procedural (and now legal) rigor in these programs, coupled with increasing public sensitivity to all kinds of data privacy (including genetic) will undermine confidence and participation in these programs. Moreover, as newborn screening programs present the most ubiquitous contact that the general public has with genetic testing, the care and diligence in their administration certainly shapes the more generalized public view of genetic testing and its promises or drawbacks.
November 6, 2011
Precision Medicine: The Patient as Data Repository
The era of defining the human patient as a data repository continues; this recharacterization represents the convergence of massive molecular (including genetic) data with digital information capacities (electronic medical records), creating an era of “precision medicine.” At the request of the National Institutes of Health, the National Academy of Sciences was tasked to develop an entirely new view of human disease, less informed by a collection of symptoms and a general description of malfunction and centered instead on a molecular-driven profile of a patient. They have issued a report, Toward Precision Medicine: Building a Knowledge Network for Biomedical Research and a New Taxonomy of Disease that proposes a new disease classification system that is informed by the collection of genetic, proteomic, microbial and other biological states – the end result is to more sharply define disease states and allow for treatment that is more personalized, with a higher likelihood of success. As part of this effort, the report calls for the use of existing patient data to build an information commons which provides the intellectual foundation for reunderstanding human medical processes. But how to get there?
The evolving imperative is to integrate patient care and data collection into a giant information commons, where every patient, if you will, is part of the ongoing “clinical trial” that becomes the modern medical enterprise. Of course, actual clinical trials, in which an individual agrees to become a research subject for scientific/medical investigation, are a well-established pillar of medical science and they are conducted using norms of consent, transparency, and privacy; an overview here). What does this mean for the law? The report does note a need to "initiate a process within appropriate federal agencies to assess the privacy issues." Existing legal privacy protections are several (HIPAA, regarding the privacy of medical records, GINA, regarding does provide some assistance as Title I addresses unfair uses of genetic information by health insurers regarding premiums, etc.).The upshot is that rewriting human disease in molecular language is intellectually appealing, but the conversion of patients into information subjects has obvious privacy implications. Treatment consequences include a kind of adverse typecasting with consequences for receiving medical care (or insurance for). The proposed federal initiative is now new. An example of a private effort to integrate patient records into a genetics research program is underway by Kaiser Permanente in California, in which insured patients can consent to having their deidentified patient records entered into their genetic research program. The program provides formal privacy guarantees, and has its own internal Institutional Review Board (IRB) which reviews protocols. As the era of molecular medicine redefines the patient as a data repository, the law must supply the requisite human norms of privacy, risk, and choice to accompany such a transformation.
The evolving imperative is to integrate patient care and data collection into a giant information commons, where every patient, if you will, is part of the ongoing “clinical trial” that becomes the modern medical enterprise. Of course, actual clinical trials, in which an individual agrees to become a research subject for scientific/medical investigation, are a well-established pillar of medical science and they are conducted using norms of consent, transparency, and privacy; an overview here). What does this mean for the law? The report does note a need to "initiate a process within appropriate federal agencies to assess the privacy issues." Existing legal privacy protections are several (HIPAA, regarding the privacy of medical records, GINA, regarding does provide some assistance as Title I addresses unfair uses of genetic information by health insurers regarding premiums, etc.).The upshot is that rewriting human disease in molecular language is intellectually appealing, but the conversion of patients into information subjects has obvious privacy implications. Treatment consequences include a kind of adverse typecasting with consequences for receiving medical care (or insurance for). The proposed federal initiative is now new. An example of a private effort to integrate patient records into a genetics research program is underway by Kaiser Permanente in California, in which insured patients can consent to having their deidentified patient records entered into their genetic research program. The program provides formal privacy guarantees, and has its own internal Institutional Review Board (IRB) which reviews protocols. As the era of molecular medicine redefines the patient as a data repository, the law must supply the requisite human norms of privacy, risk, and choice to accompany such a transformation.