Privacy Policy

This Privacy Policy was last updated: June 30, 2023

At GeneDx, LLC, an affiliate, we take our responsibility to protect patient rights very seriously. This privacy policy (this “Privacy Policy”) explains what information GeneDx, LLC (“GeneDx”, “we” or “us”) collects from you when you use our website, online provider portal (which is available to health care providers), and applications (collectively, the “Website”), including without limitation, or interact with our third-party partners (“Partners”), as applicable. Please take a moment to review this information.

The collection, use and disclosure of protected health information through the Website, or that is accessed via the Website, in our capacity as a HIPAA covered entity is subject to our HIPAA Notice of Privacy Practices, which can be found here, and not this Privacy Policy.

We may revise this Privacy Policy from time to time. If we decide to change our Privacy Policy, we will post the revised policy here. If changes are significant and materially affect your rights under this Privacy Policy, we will make reasonable attempts to notify you before the changes become effective. In certain cases, we may also provide email notification of the revised Privacy Policy and either seek your consent or give you the right to opt out from our use of your Personal Information in accordance with the revised Privacy Policy. However, because we may make changes at any time without notifying you, we suggest that you periodically consult this Privacy Policy. Please note that our rights to use any information collected will be based on the privacy policy in effect at the time the information is used.

1. How we protect your information

GeneDx is committed to protecting your privacy.  We employ a range of physical, technical and administrative safeguards to secure the personally identifiable information (“Personal Information”) you entrust to us and protect it from loss, misuse, unauthorized access, disclosure, alteration, corruption or destruction. We take reasonable measures to protect your Personal Information to prevent against unauthorized use, access, disclosure, and destruction. Your name and email address, along with other information that can be used to identify you, constitute your Personal Information. Please be aware that, despite our best efforts, security measures are not impenetrable, and we can’t guarantee against misuse.

2. What information we collect and how we collect it

Contact Information

If you choose to contact us through the Website, we’ll collect your contact information, such as your name and email address, postal address, or phone number so we can communicate with you. If you write a message, we will store the message so we can reference it to tailor our responses to you.

Website Visitor or User Data

Directly or through the use of third-party data analytics services (including Google Analytics), we collect visitor or user information, including your IP address and server log data (the address of the web page you visited before using the Website, your browser type and settings, the date and time of your use of the Website, language preferences). We may gather your information about the device you are using to access our Website, including what type of device it is, what operating system you are using, device settings, application IDs, location, unique device identifiers, and crash data. Other data is collected, including data generated by your use of the Website and links you interact with. Further information on how Google uses data collected by Google Analytics can be found at https://support.google.com/analytics/answer/6004245?hl=en. Information about how to opt out of Google Analytics can be found at https://tools.google.com/dlpage/gaoptout/.

Account and Interaction Data

We may collect additional Personal Information that you voluntarily submit to us through the Website for other purposes, including information needed to open an account if you choose to do so. This information may include (1) user name and password; (2) name, email address, telephone number, home address, business address, occupation; (3) personal interests or concerns; (4) registration information pertaining to an educational program or event; or (5) answers to an online form or survey.

3. How we use your information

  • We may use your Personal Information, including any information you share with us, to provide and improve our programs and services. We share this information with third-party service providers or Partners upon your request, or our service providers or Partners to the extent necessary to provide you with our Services.
  • If you are a patient, we may use your Personal Information to contact you about research opportunities, clinical trials, or clinical treatments for you, as permitted by law and by your consent. You can opt out of being contacted for research participation by submitting this form.
  • If you choose to participate in a research project, we share your Personal Information for those research purposes as permitted and in compliance with applicable laws, and in accordance with your consent.
  • We create de-identified and aggregated data from your Personal Information and may use and disclose the de-identified data, as permitted by law and by your consent.
  • We use your information to operate, manage, and improve our Website, and for marketing and administrative purposes.
  • If you communicate with us, we may send you newsletters and marketing information, until you decide to opt out. We may also send you notifications, updates, and changes about our Website and contact you to provide customer service and support.
  • We may use your information to comply with legal or regulatory requirements, to respond to lawful requests, court orders and legal process, to enforce our rights, to prevent fraud, to protect the security of the Website and for safety.
  • We may use your IP address and location data to analyze usage, administer our Website, and gather demographic information for aggregate use.
  • With your consent, we may use your Personal Information in other ways.

4. How we share your information

We do not knowingly sell, trade or otherwise share your Personal Information with any third parties without your consent, except as disclosed in this Privacy Policy, as required by law, and when we reasonably believe it is necessary to prevent or take action regarding illegal activities, suspected fraud, or to protect the safety of any person.

We may share Personal Information in collaboration with our Partners, including companies that assist with health records collection, business analytics, data processing, customer and user management, and other services. We instruct these parties to use your Personal Information only to the extent necessary to provide the services we have requested. Although we take reasonable steps to ensure that Partners receiving your information are bound by privacy restrictions as restrictive as those set forth in this Privacy Policy, we are not responsible for any issues that may arise regarding the privacy policies or practices of any of Partners.

In the event we go through a business transition, including without limitation any merger, acquisition, partnership, business reorganization, debt finance, or sale of association assets, or in the event of an insolvency, bankruptcy, or receivership (together a “Business Transition”), we may use information collected in accordance with this Privacy Policy and subject to its restrictions, as part of any such Business Transition. In such instances, your information can be part of the assets transferred.

5. Social media

If you click on our social media links (such as Twitter, Facebook, Instagram, YouTube, and LinkedIn), you will be directed to a third-party platform, and any information you share on those websites will be covered by their privacy policies, not this Privacy Policy.

6. Cookies and other technologies

What are cookies?

A cookie is a small file that can be placed on your computer’s hard disk or on a website server. Cookies do not retrieve information stored on your hard drive and do not corrupt or damage your computer or computer files. For those using our Website, we may link cookie information to your email address to maintain and recall your preferences within the Website.

Why we use cookies

We may use cookies and similar tracking technologies to improve or administer the Website, analyze trends, track users’ movements around the Website, support security features on the Website, and to gather demographic information about our user base.

How to manage cookie preferences

Depending on their purpose, some cookies will only operate for the length of a single browsing session, while others have a longer life span to ensure that they fulfill their longer-term purposes. Your web browser can be set to allow you to control whether you will accept cookies or reject cookies, to notify you each time a cookie is sent to your browser, or to delete cookies that have already been set. If your browser is set to reject cookies, certain aspects of the Website that are cookie-enabled will not recognize you when you return to the Website, and some Website functionality may be lost. The “Help” section of your browser may tell you how to prevent your browser from accepting cookies. You can update your cookie preferences on our Website by clicking on the cookie settings link found on the bottom of every Website page.

7. Opt-in /opt-out of communications

By using our Website, you expressly allow us to contact you and use your information as set forth in this Privacy Policy. You may opt-out of receiving marketing emails anytime by clicking the “unsubscribe” link in the email that contains the marketing communication. If you are a health care provider using our Provider Portal, you may change your preferences to receive Provider Portal email notifications about your orders by updating your notification preferences within your Provider Portal profile.

8. Links

The Website may contain links to other third-party websites. Please be aware that we are not responsible for the privacy practices of third parties and their other websites. This Privacy Policy applies only to the information we collect on or through the Website. We encourage you to read the privacy policies of other websites you link to or otherwise visit them.

9. Your choice to access, edit, or delete information

Whenever reasonably possible, we strive to provide you with choices and control regarding your Personal Information. Upon receiving your request, we will make reasonable efforts, subject to applicable laws, to provide you with access to your Personal Information or to correct, delete, and/or block your Personal Information from further use to the extent it remains in our possession. If you have questions or requests in connection with your Personal Information or this Privacy Policy, please contact us as noted below.

10. Minors

Our Website is not directed at nor intended for use by individuals under 13. If you learn that a child under 13 has provided us with Personal Information without consent, please contact us. If we become aware that a child under 13 has provided us with his or her Personal Information, we will promptly delete such data.

12. Do-not-track

You may have implemented a “do-not-track” signal through your browser. As there currently is no fixed standard for do-not-track signals, we currently do not respond to do-not-track signals from your web browser.

13. Data retention and destruction

We will retain Personal Information for as long as necessary to accomplish our purposes for such data as set forth in this Privacy Policy. You can request that your information be deleted by contacting us at the address provided at the bottom of this Privacy Policy. At the time your information is deleted, we will destroy your Personal Information using reasonable data destruction practices. We may, however, retain certain information to comply with legal or contract obligations or to facilitate law enforcement requests.

14. Notice to california residents

Certain California residents have additional privacy rights under the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”). Please note that certain information, such as protected health information regulated by HIPAA, is exempt from the CCPA(CPRA). This means that GeneDx and certain service providers or other recipients may not be required to honor the rights described in this section and instead we comply with our obligations under HIPAA. Our collection, use and disclosure of protected health information is subject to our HIPAA Notice of Privacy Practices, which can be found here

When we operate as a “service provider” or “contractor” (as defined under the CCPA/CPRA) for our customers and they provide us with your Personal Information for business purposes under a service contract, the CCPA(CPRA) applies primarily to those customers, not to us.  In such cases, we will direct any requests you send us to exercise your rights under the CCPA(CPRA) to the applicable customer. 

Your Rights Regarding Your Personal Information

The CCPA(CPRA) gives certain rights to California residents regarding their Personal Information.  We summarize below what those rights are and how you may exercise them. You do not need to have an account with us to exercise these rights. 

The CCPA(CPRA) also gives California residents the right to opt out of (or for minors under 16, the ability to opt in to) sales and sharing of their Personal Information. However, we do not and will not sell or “share” (as defined in the CCPA/CPRA) patient Personal Information. If, in the future, we decide to sell or share patient personal information, we will provide you with notice and the right to opt-out of (or for minors, opt-in to) such sales or sharing. 

In the last 12 months, we have sold (within the meaning of CCPA/CPRA) or disclosed deidentified protected health information that was deidentified using the methodology described at 45 CFR 164.514(b)(1) or 45 CFR 164.514(b)(2).

Selling Personal Information 

In the last 12 months we may have sold Personal Information relating to healthcare providers who have ordered genetic tests from GeneDx. We have not sold other personal information, including the PHI of patients, in the preceding 12 months for any monetary value.  

However, our use of certain website cookies may be considered a “sale” of information under California law. In the past 12 months, we may have shared your internet activity or geolocation with third parties whose cookies are on our websites. These cookies are used to analyze usage of our website, as described in Section 6, above. You can opt-out of this “sale” of information by using our “Cookie Settings” link, which can be found at the permanent footer of this website, under ‘PRIVACY.”

Right to Know About the Collection, Use, Disclosure, Sale and Sharing of Personal Information 

Upon providing us with a verified consumer request, you may ask us to disclose certain types of your Personal Information we have collected and used over the 12-month period prior to the date of your request. You may make this request only twice within any 12-month period. You may request: 

  • The categories of Personal Information we collected about you
  • The categories of sources of the Personal Information we collected about you
  • The business or commercial purpose for collecting that Personal Information
  • The categories of third parties with whom we shared that information
  • The specific pieces of Personal Information we collected about you (except to the extent prohibited under CCPA(CPRA) including, for example, disclosure of Social Security numbers or other government, health insurance or medical identification numbers, account passwords)
  • If we disclosed your Personal Information for a business purpose, a list identifying the personal information we disclosed to each category of recipient.

Generally, within the preceding 12 months, GeneDx has collected the categories of Personal Information described in Section 2 above from the sources described in Section 2.

Right to Request Deletion of Personal Information

You have the right to submit a verified consumer request at any time that we delete any of your Personal Information collected and retained by us, unless an exception under the CCPA(CPRA) applies.

If no exception applies, and if we have been able to verify your consumer request, we will delete, aggregate or de-identify your personal information from our records in accordance with the CCPA(CPRA). We will also direct third parties to whom we have disclosed your Personal Information to delete it, although we cannot guarantee that such third parties will comply with our direction.

Please note that we may deny your deletion request based on certain provisions of the CCPA(CPRA), including where it is necessary for us or our service providers to carry out certain business functions, comply with laws or to engage in other internal and lawful uses of the information within the context in which you provided it to us.

Right to Correct Inaccurate Personal Information 

You have the right to submit a verified consumer request at any time that we correct inaccurate Personal Information that we maintain about you, unless an exception under the CCPA(CPRA) applies. 

Right to Opt Out of Sale or Sharing of your Personal Information 

You may have the right to opt out of the sale or sharing of your Personal Information. 

Making a Verified Consumer Request or Opt Out to Us

To make a request to exercise your rights under CCPA(CPRA) described above, including if you are a California ordering provider and would like to opt out of the sale of your Personal Information, please submit a verifiable request to us by either: 

A verifiable consumer request must be made by you or a person registered with the California Secretary of State whom you have authorized to make the request on your behalf. (A representative must be authorized by you in writing or have a valid power of attorney under California probate law.) You may also make a verifiable request to us on behalf of your minor child.

To be considered a proper verified request, your request must:

(1) provide us with sufficient information allowing us to reasonably verify that you are the same person about whom we collected the Personal Information or the authorized representative, and

(2) describe your request in reasonable detail so we can correctly understand, evaluate and respond to the request.

We may ask you for additional information if needed in order to verify your request, but if we do, we will use such additional information only to verify your identity (or the authority of the representative) and for security and fraud-prevention purposes.

We will also ask you to separately confirm any request to delete Personal Information.

Responding to Your Verifiable Consumer Request

We will use reasonable efforts to respond to your verifiable consumer request within 45 days of receiving it. If some cases, we may require more time (up to 90 days). In that is the case, we will communicate to you in writing (by postal mail or electronically, at your option) the reason and the length of anticipated delay. We will not be able to fulfill your request if we cannot verify your identity (or the authority of your representative) and confirm that the Personal Information subject to the request relates to you. A request from a California ordering provider to opt out of the sale of their Personal Information will be responded to within 15 business days of receiving it.

Disclosures we provide in response to a verified consumer request will cover only the 12-month period before we received the request. If your request involves the porting of your Personal Information, we will use a format that is reasonably designed to allow you to transmit the information to another entity. If we deny part or all of a verified consumer request, we will provide a reasonable explanation for the denial.

We do not charge fees for responding to verifiable consumer request unless they are excessive, repetitive or manifestly unfounded. If we determine that a fee is appropriate, we will provide you with an explanation and a cost estimate before we complete your request.

We will keep records of consumer requests and our responses as required under the CCPA(CPRA).

Non-Discrimination

We will not discriminate against you for exercising any of your rights under the CCPA(CPRA). This means that, except where permitted under the CCPA(CPRA). if you make a request for disclosure or to delete your Personal Information, we will not (i) deny you goods or services, (ii) charge you different prices for goods or services (e.g., through penalties or withholding of otherwise available discounts), (iii) giving you a different level of goods or services, or (iv) suggesting to you that we will take any of the actions in (i) through (iii).

Retention 

We retain your Personal Information based on legal requirements or business needs. Generally, we only retain Personal Information for as long as is reasonably necessary for our business purpose or as required by law. Information we retain remains subject to the protections of applicable law and the commitments made by GeneDx in this Privacy Policy. 

15. Contact us

If you have any questions about the Privacy Policy or wish to exercise your rights, please contact us at Privacy@genedx.com and/or (888)729-1206, option 3, or at the mailing address below:

GeneDx
207 Perry Parkway
Gaithersburg, MD 28077

Non-Discrimination