1. Compliance Overview
Gene Matrix LLC is committed to maintaining the highest standards of data protection and privacy compliance. We adhere to both the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the General Data Protection Regulation (GDPR) in the European Union.
Our Commitment:
- Full compliance with HIPAA Privacy and Security Rules
- GDPR compliance for all EU residents and data subjects
- Regular third-party audits and certifications
- Continuous monitoring and improvement of security measures
- Transparent data handling practices
- Respect for individual privacy rights
We understand that your genetic and health information is among the most sensitive data you possess. Our compliance framework ensures this information is protected with the highest level of security and privacy.
2. HIPAA Compliance
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law that establishes national standards for protecting sensitive patient health information.
Our HIPAA Compliance Measures:
Privacy Rule Compliance:
- Minimum necessary standard for data access
- Individual rights to access and amend health information
- Authorization requirements for data disclosure
- Notice of Privacy Practices provided to all users
- Designated Privacy Officer overseeing compliance
Security Rule Compliance:
- Administrative safeguards: Security management processes, workforce training
- Physical safeguards: Facility access controls, workstation security
- Technical safeguards: Access controls, audit controls, encryption
- Regular risk assessments and security updates
Breach Notification Rule:
- Immediate investigation of suspected breaches
- Notification to affected individuals within 60 days
- Reporting to HHS for breaches affecting 500+ individuals
- Documentation and analysis of all security incidents
Business Associate Agreements:
All third-party service providers who handle PHI sign Business Associate Agreements (BAAs) ensuring they maintain HIPAA compliance standards.
3. GDPR Compliance
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that gives individuals control over their personal data.
Our GDPR Compliance Measures:
Lawful Basis for Processing:
- Explicit consent for genetic data processing
- Legitimate interest for service delivery
- Legal obligation for regulatory compliance
- Vital interests for health and safety
Data Subject Rights:
- Right to access: Request copies of your data
- Right to rectification: Correct inaccurate data
- Right to erasure: "Right to be forgotten"
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive data in machine-readable format
- Right to object: Opt out of certain processing activities
- Rights related to automated decision-making
Data Protection Principles:
- Lawfulness, fairness, and transparency
- Purpose limitation: Data used only for stated purposes
- Data minimization: Collect only necessary data
- Accuracy: Keep data up-to-date and correct
- Storage limitation: Retain data only as long as necessary
- Integrity and confidentiality: Secure data processing
- Accountability: Demonstrate compliance
International Data Transfers:
- Standard Contractual Clauses (SCCs) for EU-US transfers
- Adequacy decisions where applicable
- Additional safeguards for sensitive data transfers
Data Protection Officer:
We have appointed a dedicated Data Protection Officer (DPO) available at dpo@genematrix.io for all privacy-related inquiries.
4. Security Measures
Technical Security Controls:
Encryption:
- AES-256 encryption for data at rest
- TLS 1.3 for data in transit
- End-to-end encryption for sensitive communications
- Encrypted backups with separate key management
Access Controls:
- Multi-factor authentication (MFA) required for all accounts
- Role-based access control (RBAC) for internal systems
- Principle of least privilege access
- Regular access reviews and revocations
- Automatic session timeouts
Network Security:
- Firewall protection and intrusion detection systems
- DDoS protection and rate limiting
- Network segmentation and isolation
- Regular penetration testing
- 24/7 security monitoring
Application Security:
- Secure software development lifecycle (SDLC)
- Regular security code reviews
- Automated vulnerability scanning
- Web application firewall (WAF)
- Input validation and sanitization
Physical Security:
- CLIA-certified, CE-IVD Certified laboratory facilities
- Biometric access controls
- 24/7 video surveillance
- Secure sample storage and handling
- Controlled environment monitoring
Organizational Security:
- Comprehensive security policies and procedures
- Regular employee security training
- Background checks for all personnel
- Confidentiality agreements
- Incident response plan and team
5. Data Handling Practices
Data Collection:
We collect only the minimum data necessary to provide our services:
- Personal identifiers: Name, email, date of birth
- Contact information: Address, phone number
- Payment information: Processed by PCI-DSS compliant providers
- Health information: Medical history, family history
- Genetic data: DNA samples and analysis results
Data Processing:
- Samples processed in secure, certified laboratories
- Genetic data analyzed using proprietary algorithms
- Results generated and stored in encrypted databases
- Access limited to authorized personnel only
- Audit logs maintained for all data access
Data Storage:
- Primary storage in secure, encrypted databases
- Redundant backups in geographically distributed locations
- Separate encryption keys for different data types
- Regular backup testing and verification
- Secure deletion protocols for data removal
Data Retention:
- Account data: Retained while account is active + 7 years
- Genetic data: Retained indefinitely unless deletion requested
- Test results: Minimum 10 years per CLIA requirements
- Biological samples: Destroyed within 60 days unless consent given
- Audit logs: Retained for 7 years
Data Deletion:
Upon request, we will:
- Delete your account and personal information
- Remove your genetic data from active systems
- Destroy biological samples if still retained
- Maintain only what's legally required
- Provide confirmation of deletion
Note: Some data may be retained for legal, regulatory, or legitimate business purposes even after deletion requests.
6. Your Privacy Rights
How to Exercise Your Rights:
You can exercise your privacy rights by:
- Logging into your account and using privacy settings
- Emailing privacy@genematrix.io
- Calling 1-800-GENE-MTX (1-800-436-3689)
- Writing to our Privacy Office
Right to Access:
Request a copy of all personal and genetic data we hold about you. We will provide this within 30 days in a commonly used electronic format.
Right to Correction:
Request correction of inaccurate or incomplete information. We will update your data within 30 days and notify any third parties who received the incorrect data.
Right to Deletion:
Request deletion of your data, subject to legal retention requirements. We will confirm deletion within 30 days.
Right to Restrict Processing:
Request that we limit how we use your data while you contest its accuracy or object to processing.
Right to Data Portability:
Receive your data in a structured, machine-readable format (JSON, CSV, or PDF) for transfer to another service.
Right to Object:
Object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds.
Right to Withdraw Consent:
Withdraw consent for data processing at any time. This does not affect the lawfulness of processing before withdrawal.
Right to Lodge a Complaint:
File a complaint with your local data protection authority if you believe your rights have been violated.
Response Timeline:
We respond to all rights requests within:
- 30 days for standard requests
- 45 days for complex requests (with notification)
- Immediate action for urgent security concerns
7. Breach Response Protocol
Our Commitment:
In the unlikely event of a data breach, we have comprehensive procedures to protect your information and notify you promptly.
Detection and Assessment:
- 24/7 security monitoring and alerting
- Immediate investigation of suspected incidents
- Assessment of breach scope and impact
- Containment measures activated within 1 hour
- Forensic analysis to determine cause
Notification Timeline:
GDPR Requirements (EU Residents):
- Data Protection Authority: Within 72 hours
- Affected individuals: Without undue delay if high risk
- Documentation: Maintained for all breaches
HIPAA Requirements (US Residents):
- Affected individuals: Within 60 days
- HHS: Within 60 days (500+ individuals) or annually (fewer)
- Media: Within 60 days (500+ individuals in same state)
What We'll Tell You:
- Nature of the breach and data affected
- Likely consequences of the breach
- Measures taken to address the breach
- Recommendations to protect yourself
- Contact information for questions
Remediation Actions:
- Immediate containment and system isolation
- Password resets and credential revocation
- Enhanced monitoring for affected accounts
- Free credit monitoring services (if applicable)
- System security enhancements
- Third-party security audit
Prevention Measures:
- Regular security assessments
- Penetration testing and vulnerability scans
- Employee security training
- Incident response drills
- Continuous security improvements
8. Contact Our Compliance Team
Privacy and Compliance Inquiries:
Data Protection Officer (DPO):
Email: dpo@genematrix.io
Phone: 1-800-GENE-MTX ext. 701
Privacy Office:
Email: privacy@genematrix.io
Phone: 1-800-GENE-MTX ext. 702
Security Team:
Email: security@genematrix.io
Phone: 1-800-GENE-MTX ext. 703
Mailing Address:
Gene Matrix LLC
Compliance Department
123 Genomics Way
San Francisco, CA 94105
United States
EU Representative:
Gene Matrix EU Ltd.
GDPR Compliance Office
Dublin, Ireland
Email: eu-privacy@genematrix.io
Response Times:
- General inquiries: 2-3 business days
- Rights requests: Within 30 days
- Security concerns: Within 24 hours
- Breach reports: Immediate response
Office Hours:
Monday - Friday: 8:00 AM - 5:00 PM CT
Emergency security line: 24/7
We are committed to addressing all privacy and compliance concerns promptly and thoroughly.
Questions about compliance?
Our compliance team responds to every privacy and security inquiry โ general questions within 2-3 business days, security concerns within 24 hours.