Illinois Genetic Information Privacy Act (GIPA) Compliance Requirements for Genetic Testing Labs
Confidentiality and Written Consent
Under the Illinois Genetic Information Privacy Act, genetic testing and information derived from genetic testing are confidential and privileged. A lab may release results only to the individual tested and to persons the individual specifically authorizes in writing; otherwise, disclosure is prohibited except as the Act allows. GIPA also aligns permitted uses and disclosures with HIPAA’s “minimum necessary” rule, so you must limit access and sharing to what is needed for the purpose at hand. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
GIPA requires a “specific written, legally effective authorization” to disclose identifiable genetic information to third parties. Your authorization should clearly identify the recipient(s) and be executed by the patient or their legally authorized representative; even then, you must confine any release to people with a need to know, and no further re-disclosure is permitted beyond what GIPA authorizes. These core genetic information confidentiality obligations sit alongside your HIPAA processes and should be reflected in your consent and authorization templates. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
Note: GIPA does not impose a universal consent-to-test mandate on clinical labs. However, in employment contexts (for example, wellness programs or genetic monitoring), employers can only proceed with written authorization compliant with Section 30, and results shared back to employers must be aggregated/de-identified. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
Employer Restrictions on Genetic Information
Employers, employment agencies, labor organizations, and licensing agencies may not solicit, request, require, or purchase genetic information, nor require genetic testing as a condition of employment, membership, or licensure. They may not take adverse actions, classify, limit, or retaliate against an individual based on genetic testing or genetic information. Agreements that trade employment benefits for taking a genetic test are likewise prohibited. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35&Print=True))
Narrow exceptions exist. For example, employer-run wellness programs or genetic monitoring related to workplace exposures require the employee’s written authorization under Section 30, strict notice and confidentiality safeguards, and only aggregate reporting back to the employer. Even where genetic data are lawfully obtained in these settings, employers still may not use or disclose the data in violation of GIPA. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
Insurer Limitations on Genetic Data
For accident and health insurance, GIPA bars insurers from seeking genetic testing information for nontherapeutic or underwriting purposes. If an individual voluntarily submits genetic test results and those results are favorable, an insurer may consider them for accident and health coverage; otherwise, the statute restricts use and re-disclosure. ([ilsos.gov](https://www.ilsos.gov/content/dam/publications/pdf_publications/2001_session_laws.pdf?utm_source=openai))
Illinois’s Second District Appellate Court held in February 2025 that GIPA’s underwriting prohibition in Section 20(b) applies to health insurance underwriting and not to life insurance underwriting; monitor ongoing litigation and legislation for any change. ([law.justia.com](https://law.justia.com/cases/illinois/court-of-appeals-second-appellate-district/2025/2-24-0399.html))
Separately, companies providing direct-to-consumer genetic testing may not share genetic test information with any health or life insurer without the consumer’s written consent—an important coordination point if your lab provides DTC services or integrates with DTC platforms. ([ilga.gov](https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K20.htm?utm_source=openai))
Disclosure Limitations
GIPA tightly limits who may receive identifiable genetic information: the patient (or legally authorized representative); persons specifically named in a written authorization; and certain health care personnel who need the information to conduct tests or deliver care. For minors, limited provider-to-parent/guardian notifications are permitted in the child’s best interests. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
Records held by State agencies are confidential and exempt from disclosure under the Freedom of Information Act, with narrow exceptions; when a disclosure is permitted, it must be limited to those with a need to know, and no additional disclosures may be made. Disclosures made by insurers in compliance with Article XL of the Illinois Insurance Code are deemed compliant with Section 30. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
Health information exchanges: a covered entity may, without patient consent, disclose a patient’s identity and genetic information to an HIE if the disclosure is otherwise permitted by GIPA (for example, a required or permitted disclosure to a business associate). Align your HIE participation and opt-out workflows with these allowances. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35&Print=True))
Law enforcement: where a biological sample is legally obtained by a peace officer for a criminal investigation or prosecution, genetic information from that sample may be used for identification purposes and admitted as evidence, subject to statutory safeguards. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
No redisclosure: anyone who receives genetic test results may not re-disclose them unless authorized by GIPA. Build contractual controls and downstream obligations around this no-redisclosure rule. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk AssessmentPenalties for GIPA Violations
GIPA provides a private right of action. For each violation, a prevailing plaintiff may recover $2,500 or actual damages (whichever is greater) for negligent violations; $15,000 or actual damages (whichever is greater) for intentional or reckless violations; reasonable attorneys’ fees and costs; and injunctive or other appropriate relief. For insurer violations of Section 30, Article XL of the Illinois Insurance Code supplies the exclusive remedy. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35&Print=True))
Implementing Compliance Procedures
Translate genetic information confidentiality into daily practice. Map where genetic data originate, flow, and are stored; segregate identifiers; and embed “minimum necessary” logic into your LIS/EHR routing, portals, and reporting. Standardize your genetic data disclosure authorization to capture recipient identity and scope, and verify identity before release. Train staff on Genetic information confidentiality, Informed consent requirements, and Genetic data disclosure authorization workflows. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35&Print=True))
Operationalize Employment genetic testing restrictions and Insurance genetic data prohibitions with clear SOPs: reject employer requests for identifiable results absent a qualifying exception; send employers only aggregate wellness-program summaries; and require written consumer consent before any DTC-to-insurer sharing. Conduct Genetic privacy compliance audits at least annually to test access controls, authorizations, HIE exchanges, and vendor handling; remediate promptly and document corrective actions. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
Track near-term statutory changes. Public Act 104-642, effective January 1, 2027, will integrate “biomarker” and “biomarker testing” throughout GIPA, expanding several provisions. Begin impact assessments now so your lab is ready before the effective date. ([ilga.gov](https://ilga.gov/Legislation/PublicActs/View/104-0642?utm_source=openai))
Authorized Access Controls
Implement role-based access tied to job duties, enforcing “need to know” at every step—collection, analysis, interpretation, transmission, and reporting. Use unique credentials, multi-factor authentication, and session timeouts for staff accessing genetic results; log all accesses and disclosures, and review audit logs on a risk-based cadence.
Encrypt genetic data in transit and at rest. Isolate raw sequence files and variant call data; segregate research and clinical datasets; and apply data loss prevention to e-mail and file shares. Vet vendors and HIEs with security due diligence and business associate agreements that mirror GIPA’s no-redisclosure rule and minimum-necessary standards.
Harden printers, fax/scan workflows, and physical storage for printed reports. Adopt least-retention principles for identifiable genetic data, with secure destruction when retention periods end. Test your incident response plan with scenarios involving misdirected results, unauthorized portal access, and vendor handling errors, and incorporate GIPA-specific notification and containment steps.
Conclusion
For Illinois genetic testing labs, GIPA centers on strict confidentiality, specific written authorization for disclosures, narrow exceptions, and meaningful enforcement. By operationalizing these requirements—especially around employer and insurer boundaries—and by hardening access controls, you can protect patients, meet statutory duties, and reduce litigation risk while staying ahead of forthcoming biomarker-related updates.
FAQs
What are the consent requirements under GIPA?
GIPA requires a specific written, legally effective authorization to disclose identifiable genetic information to third parties. While GIPA does not create a universal consent-to-test rule for labs, it does require written authorization for employment wellness or monitoring programs, and DTC testing companies must have written consumer consent before sharing with health or life insurers. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
How must genetic testing labs handle disclosure of genetic information?
Disclose only to the patient (or authorized representative), to specifically named recipients in a valid authorization, or to care team members who need the information. State-agency records are confidential; HIE disclosures without consent are allowed only as GIPA permits; recipients may not re-disclose unless GIPA authorizes it; and limited law-enforcement uses are permitted for identification. Apply HIPAA’s “minimum necessary” to each disclosure. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35))
What penalties apply for GIPA non-compliance?
Individuals can sue. Remedies include $2,500 or actual damages (negligent), $15,000 or actual damages (intentional or reckless), attorneys’ fees and costs, and injunctive relief; for insurer violations of Section 30, Article XL of the Insurance Code controls. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35&Print=True))
Are employers allowed to request genetic test results?
No. Employers and related entities may not solicit, request, require, purchase, or condition employment on genetic testing or genetic information. Limited exceptions (e.g., wellness programs or genetic monitoring) require written authorization and strict safeguards, and any employer-facing outputs must be aggregate only. ([ilga.gov](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=1567&ChapterID=35&Print=True))
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk Assessment