Ordering
Contact, billing and shipping information can be used to process the order, deliver the kit, communicate with you and manage payments or refunds.
An at-home microbiome test involves more than a stool sample and a report. Depending on the service, the testing process can involve your name, contact details, order information, kit registration, a biological sample, laboratory findings, and the report connected with your test.
That makes microbiome test privacy an important part of deciding which testing service to use. Before ordering, you should know what information is collected, who needs access to it, why it may be retained, and which privacy choices or rights may be available to you.
This guide explains privacy using the current published MicrobiomeTest.us policies and U.S. consumer privacy context. It is educational information, not legal advice. Always review the current Privacy Policy before ordering because policies and legal requirements can change.
What happens to your data after a microbiome test? The exact answer depends on the provider. Under the current MicrobiomeTest.us policy, information needed for ordering, kit registration, laboratory processing, customer support, reporting and related services may be collected and processed. Necessary information may also be provided to laboratories or other service providers involved in delivering the test.
Privacy is easier to understand when the information is separated into categories. Not every customer or test necessarily creates every type of record, but the current MicrobiomeTest.us policy describes several categories that may be involved.
Want to understand what the laboratory result looks like? Review the Sample Report and Microbiome Science separately from the privacy questions discussed here.
Thinking about privacy as a data flow is more useful than asking whether a test is simply “private” or “not private.” Different information is needed at different stages.
Contact, billing and shipping information can be used to process the order, deliver the kit, communicate with you and manage payments or refunds.
Registration information and sample identifiers help connect the submitted sample with the correct order and reporting workflow.
Necessary sample, testing, order or consent information may be processed by the laboratory or testing partners involved in providing the service.
Results are returned through the applicable reporting process, while order, sample and support information may continue to be used for customer service and recordkeeping.
A mail-in microbiome test cannot usually be delivered by one organization working completely alone. Laboratories, payment processors, shipping companies and technical service providers may perform different parts of the service.
The current MicrobiomeTest.us policy says necessary customer, order, consent, sample and testing information may be shared with independent laboratories or testing partners to provide the test ordered.
Limited information may be processed by service providers such as fulfilment companies, couriers, payment processors, hosting providers, communication platforms and customer-support systems where needed for their role.
Fraud-prevention, security, legal, accounting and professional advisers may also receive information when reasonably necessary for their applicable function.
The current published Privacy Policy states that MicrobiomeTest.us does not sell biological samples or identifiable laboratory-testing information to data brokers. That statement is different from saying no third party ever processes information: laboratories and service providers may still receive information needed to perform the service.
Not necessarily. A sample identifier can help reduce the need to place a person's name directly on every laboratory record, but a coded sample is not automatically the same thing as fully anonymous or legally de-identified information.
The current MicrobiomeTest.us policy says a laboratory may assign a unique identifier to a sample during testing. At the same time, information still needs to be connected correctly with the order and final reporting process.
This distinction is important because privacy language such as “anonymous,” “coded,” “de-identified,” and “identifiable” should not be treated as interchangeable.
There is not one universal retention period for every category of information in the current MicrobiomeTest.us Privacy Policy.
The policy says retention can depend on factors such as the type of information, the test ordered, laboratory procedures, customer consent, legal requirements, business needs and security needs.
Records may also need to be retained for reasons such as completing the testing service, providing support, maintaining transaction records, processing refunds, resolving disputes, preventing fraud, or maintaining laboratory and quality-control records.
The policy states that biological samples may be retained, destroyed or otherwise handled according to laboratory procedures, applicable consent and legal requirements. If sample retention matters to you, review the current consent and privacy documents before submitting your kit rather than assuming every test follows the same timetable.
Do not assume that every health-related website, wellness service or consumer test is automatically covered by HIPAA.
HIPAA privacy rules generally apply to specific covered entities and their business associates. The exact legal status of a consumer testing service depends on the organization, its relationships and the data flow involved.
That does not mean consumer health information outside HIPAA has no protection. The Federal Trade Commission enforces consumer-protection laws and a Health Breach Notification Rule that can apply to certain non-HIPAA health-data businesses when its legal requirements are met.
This page does not make a legal determination that a particular federal privacy rule applies to every MicrobiomeTest.us transaction. For authoritative background, see the U.S. Department of Health and Human Services HIPAA guidance and the FTC Health Breach Notification Rule guidance.
U.S. consumer privacy rules are not identical in every state. Depending on where you live, the information involved and whether a business falls within a law's scope, state law may provide additional rights concerning consumer health or personal data.
These are examples rather than a complete list of U.S. privacy laws.
Washington has a consumer health-data law designed to address certain personal health information outside traditional HIPAA settings. The law can provide rights such as deletion when its requirements and scope are met.
Nevada law includes requirements for covered regulated entities concerning consumer health-data privacy policies, certain collection and sharing practices, consent, security and consumer requests.
Connecticut's privacy framework gives eligible consumers rights concerning personal data and contains provisions relevant to consumer health data, subject to the law's coverage rules and exemptions.
State privacy laws change over time and can contain thresholds, exemptions and definitions that affect whether a particular provision applies. Location-specific rights should therefore be checked against current law and the provider's current privacy process.
According to the current MicrobiomeTest.us policy, customers may have privacy rights depending on their location and applicable law.
Potential requests may include access, correction, deletion, information about data use or recipients, withdrawal of certain consent, restriction of certain processing, data portability, or an appeal concerning a privacy-request decision.
These rights are not absolute. Information may sometimes need to be kept for legal, laboratory, security, contractual, fraud-prevention or recordkeeping reasons.
A trustworthy privacy decision is easier when you turn a long policy into a few practical questions.
Separate account and shipping information from sample, laboratory and report information.
Look for laboratories, payment processors, hosting providers, couriers and other service providers involved in the workflow.
Check whether the policy gives fixed periods or explains why retention may vary by record or sample type.
Look for access, correction, deletion, consent and other rights that may depend on your location.
Read both the privacy policy and any test-specific consent documentation for sample handling and retention details.
MicrobiomeTest.us uses an online ordering and at-home sample collection model rather than requiring every customer to visit a MicrobiomeTest.us clinic.
That makes your delivery location relevant not only to shipping but potentially to the privacy rights available under applicable state law.
Use the state and city directories for geographic testing information, while using the current Privacy Policy for the site's published data-handling practices.
Privacy content should be tied to published policies and authoritative guidance rather than broad claims about how every testing company operates.
The site's current published policy explains the categories of data that may be collected, testing-partner workflow, service providers, retention, security practices and potential privacy rights. Read the policy .
FTC guidance explains that consumer health information outside HIPAA can still be subject to federal consumer-protection and health-breach requirements when the relevant rules apply. Read FTC guidance .
HHS guidance explains HIPAA requirements for covered entities and business associates and provides resources on privacy, de-identification and health apps. Review HHS guidance .
Direct answers to common questions about samples, laboratory data, retention, HIPAA and privacy rights.
The exact workflow depends on the provider. MicrobiomeTest.us states that it may process contact, order, kit-registration, sample, laboratory and report information and may share necessary information with laboratories and service providers involved in delivering the requested service.
The current MicrobiomeTest.us Privacy Policy states that it does not sell biological samples or identifiable laboratory-testing information to data brokers.
Do not assume HIPAA applies simply because data is related to health. HIPAA generally applies to covered entities and business associates. Consumer health information outside HIPAA may still be affected by other federal or state privacy requirements depending on the service and circumstances.
The current MicrobiomeTest.us policy says customers may have deletion and other privacy rights depending on their location and applicable law. Exceptions can apply where information needs to be retained for legal, laboratory, security, contractual, fraud-prevention or recordkeeping purposes.
The current policy does not state one universal retention period for every record. Retention may vary based on factors including the test, type of information, laboratory procedures, consent, applicable law, business needs and security needs.
They can. U.S. states can have different consumer privacy and consumer health-data requirements. Whether a specific right applies depends on the state, data involved, business and legal scope of the particular law.
Start with the current MicrobiomeTest.us Privacy Policy. You can then review Privacy & Data Security, How It Works, and the Sample Report so you understand both the data workflow and the testing workflow.
Privacy should be part of your comparison before you send a biological sample. Review what information is collected, which organizations may process it, how retention works, what rights may be available, and what the final microbiome report actually contains.
The published Privacy Policy is the primary source for MicrobiomeTest.us data-handling information. This educational article summarizes key questions but does not replace the current policy, consent documents or applicable law.