Illinois Genetic Information Privacy Act (GIPA): Limits on What Clinics Can Do in Pre‑Employment Screening

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Illinois Genetic Information Privacy Act (GIPA): Limits on What Clinics Can Do in Pre‑Employment Screening

Kevin Henry

Data Privacy

August 28, 2026

7 minutes read
Share this article
Illinois Genetic Information Privacy Act (GIPA): Limits on What Clinics Can Do in Pre‑Employment Screening

Illinois law tightly regulates how clinics interact with genetic data in hiring. To maintain Genetic Information Privacy Act compliance, you must not collect, request, disclose, or help employers use genetic test information in pre-employment evaluations. The safest operational rule is simple: no genetics in hiring—ever.

Prohibited Genetic Information Requests

Clinics conducting pre-employment exams may not request, require, or purchase an applicant’s genetic information or genetic test results. These pre-employment genetic screening restrictions apply whether the data comes from a medical lab, a research study, or a direct-to-consumer test kit.

What counts as a “genetic test”

A genetic test analyzes DNA, RNA, chromosomes, or related proteins/metabolites to detect genotypes, mutations, or chromosomal changes. Examples include carrier screens (such as BRCA1/2), pharmacogenomic panels, polygenic risk scores, whole‑exome or whole‑genome sequencing, and ancestry reports that expose raw genetic data.

Requests you must not make

  • Do not ask applicants to provide genetic test results or raw data from consumer services.
  • Do not seek genetic information about family members or relatives, including their test results.
  • Do not infer genetic risk through family history questionnaires during hiring.
  • Do not obtain or analyze a DNA sample as part of any screening panel.
  • Do not browse or harvest publicly posted genetic profiles tied to an applicant.

Activities generally outside “genetic testing”

Routine occupational health services—such as drug screens, vaccinations, vision/hearing checks, and tests assessing current fitness for duty—are typically permissible when they do not reveal genotypes or mutations. Validate each panel with your lab to ensure no genetic markers are included.

Confidentiality and Privilege of Genetic Data

Under Illinois law, genetic information is both confidential and legally privileged. If your clinic encounters such data (for example, because you also treat the individual as a patient), you must maintain strict confidentiality of genetic test results and related interpretations. Disclosure requires the tested individual’s specific, written authorization identifying the information, purpose, recipients, and duration.

Core safeguards for regulated clinics

  • Store any genetic information in a locked, access‑controlled record separate from general occupational health files.
  • Limit access to a minimal set of trained personnel; maintain audit logs for every access and disclosure.
  • Encrypt data at rest and in transit; prohibit downloads or local copies of raw data.
  • Use data minimization and redaction so employer reports never include genetic content.
  • Adopt retention and destruction schedules tailored to employment law genetic data, with documented chain‑of‑custody controls.

Authorization essentials

  • Written, signed, time‑limited, and revocable by the individual at any time.
  • Specifies what genetic information may be disclosed, to whom, and for what purpose.
  • Not a condition of obtaining or keeping employment; refusal cannot affect hiring.

Restrictions on Employment Decisions

Clinics may not assist, directly or indirectly, in hiring, placement, or fitness decisions based on genetic information. Your deliverables to an employer should provide only job‑related, present‑ability findings (for example, “fit,” “fit with restrictions,” or “not fit”), never predictive risk or hereditary markers. This implements the genetic discrimination prohibition at the clinical interface.

Reporting do’s and don’ts

  • Do report functional limitations and required accommodations tied to current health status—without revealing underlying diagnoses or any genetic data.
  • Do provide detailed clinical results only to the applicant unless a valid authorization directs otherwise.
  • Don’t include family history, test names suggestive of genetics, or coded fields that could be decoded into genetic meanings.
  • Don’t transmit lab requisitions or EHR printouts containing genetic flags to the employer.

Pre‑offer vs. post‑offer reality

Even when a post‑offer medical exam is permitted for a job, genetic information remains off‑limits. Ensure your protocols and forms keep genetic content entirely outside the employment process.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Anti-Retaliation Protections

GIPA bars retaliation for refusing genetic testing, withholding genetic information, or exercising rights under the statute. Clinics cannot delay services, mark an applicant as “non‑compliant,” or otherwise disadvantage the person because they declined to disclose genetic data. These retaliation protections under GIPA apply to every stage of pre‑employment screening.

Examples of prohibited retaliation

  • Noting in a report that an applicant “refused family history questions” or “declined DNA test.”
  • Charging additional fees, shortening appointment windows, or cancelling exams due to a refusal to provide genetic information.
  • Communicating a refusal in a way that signals risk or non‑cooperation to the employer.

Neutral handling practices

  • Use standardized language that never mentions genetics in employer‑facing outputs.
  • Route any genetic‑related materials to a segregated clinical record; never to occupational files.
  • Escalate edge cases to compliance or legal, not to the employer.

Compliance Strategies for Clinics

Build compliance into intake, ordering, reporting, and records so regulated clinics’ genetic information never enters the hiring stream.

Policy and training

  • Publish a “no‑genetic‑data in hiring” policy; train all intake, lab, and provider staff on pre‑employment genetic screening restrictions.
  • Embed decision trees clarifying what tests are allowed, conditionally allowed, or prohibited.

Intake and data minimization

  • Remove family history and ancestry prompts from pre‑employment forms.
  • Design lab panels that exclude any analysis capable of revealing genotypes or mutations.
  • Disable EHR fields and auto‑imports that could pull genetic flags into occupational records.

Employer contracting and communications

  • State in service agreements that your clinic will not request, receive, or disclose genetic information and will not assist decisions based on it.
  • Limit reports to functional determinations; prohibit attachments that include lab details.

Documentation and audits

  • Keep written justifications for every test ordered; confirm it cannot reveal genetic markers.
  • Audit a sample of employer reports to ensure no genetic content slips through.
  • Maintain a breach response plan tailored to genetic data.

Violating GIPA can trigger civil lawsuits, injunctions, recovery of actual damages, and attorneys’ fees and costs. Courts may also award statutory, liquidated, or punitive damages in appropriate cases. Because violations can be counted per person and per disclosure, clinics face outsized exposure, including class actions, if genetic information flows into hiring decisions.

Common risk scenarios

  • Including family history questions on pre‑employment forms.
  • Forwarding comprehensive lab results or EHR summaries that contain genetic flags.
  • Conditioning clearance on disclosure of consumer genetic test results.
  • Notating an applicant’s refusal to share genetic data in an employer‑visible report.

Conclusion

To comply with the Illinois Genetic Information Privacy Act, design pre‑employment workflows that never touch genetic data, keep any incidental genetic information confidential and segregated, and limit employer communications to present functional capacity. Doing so protects applicants, reduces liability, and keeps your occupational health program squarely within the law.

FAQs.

What types of genetic information are protected under GIPA?

GIPA protects information derived from genetic testing—analyses of DNA, RNA, chromosomes, or related proteins/metabolites used to detect genotypes, mutations, or chromosomal changes. It covers the individual’s genetic test results, related interpretations, and genetic test results of family members. Treat any document or data revealing hereditary markers as protected genetic information.

How must clinics handle genetic test results during hiring?

Do not request or use them. If your clinic already holds genetic results from non‑employment care, keep them segregated, confidential, and out of the employment file. Disclose only with the individual’s specific written authorization and never include genetic content in employer‑facing reports; limit communications to job‑related functional determinations.

Can clinics use genetic information to deny employment?

No. Clinics may not assist or enable employment decisions based on genetic information. Reports should never include predictive genetic risk or hereditary findings. Clearance decisions must rest on present ability to perform essential job functions, not on genetic predisposition.

What are the penalties for violating GIPA in pre-employment screening?

Violations can result in civil actions seeking injunctive relief, actual damages, statutory liquidated damages assessed per violation, attorneys’ fees and costs, and, in some cases, punitive damages. Beyond monetary exposure, clinics risk reputational harm and parallel claims under other employment and privacy laws.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles