23andMe Pays $18 Million to Settle Multistate Probe Into 2023 Data Breach
A coalition of state attorneys general penalized the genetic testing firm for failing to protect sensitive user information.
Genetic testing company 23andMe has agreed to pay $18 million to resolve a multistate investigation led by a coalition of 42-43 state attorneys general. The probe focused on the company's failure to properly protect sensitive genetic data following a significant security failure in 2023. This settlement is separate from a larger $46.75 million class-action settlement reached for affected U.S. customers.
The investigation stems from a data breach that exposed the genetic profiles and personal information of approximately 6.9 million users. Because genetic data is immutable and uniquely identifying, the breach posed long-term privacy risks that cannot be mitigated by standard security measures like password changes. The scale of the exposure highlighted vulnerabilities in how health-tech firms safeguard biometric information.
State officials emphasized the severity of the lapse, with the Utah Attorney General's Office calling the breach of trust "unacceptable."
Distinct Legal Resolutions
Consumers should note the distinction between the two financial agreements. While the multistate settlement penalizes the company via state regulators, the separate class-action settlement of $46.75 million was designed for direct customer compensation. Eligible U.S. customers were required to submit claims by February 17, 2026, according to settlement administrators. That deadline has now passed.
Funds from the multistate agreement will be distributed among the participating states. North Carolina is expected to receive approximately $666,000, according to the North State Journal. Other states will receive allocations based on their respective involvement and consumer impact.
Regulatory Implications
This case highlights the extreme sensitivity of biometric and genetic data and the legal accountability of companies handling such information. The involvement of dozens of states underscores a coordinated regulatory effort to penalize inadequate security practices in the health-tech sector.
As the North State Journal noted, "Your genetic data is the most personal data you have." The outcome serves as a warning to industry players that failure to secure immutable user data will trigger significant legal and financial consequences. The $18 million penalty reinforces the expectation that genetic testing firms must implement robust security protocols commensurate with the sensitivity of the data they collect.