Direct-to-Consumer Genomic Testing Clinical Validity Gaps
Companies market genetic tests with confidence that science hasn't earned yet.

Direct-to-consumer genomic tests are sold with a confidence the underlying science doesn't support, and the gap is widest exactly where these companies advertise the most: polygenic risk and ancestry-linked health traits. Between 33 million tests performed in 2022 and roughly 50 million total customers since the industry started, the science of detecting a variant has outpaced the science of knowing what that variant means. That's not a rounding error. It's the central defect in how this industry sells itself, and it deserves to be named as one before anything else gets said about market size or growth.
What analytical validity and clinical validity actually measure, and why confusing them matters
The FDA judges DTC tests on two separate axes, and mixing them up is the single most common error a consumer makes before opening a report. Analytical validity asks whether the test accurately detects the genetic variant it claims to detect. Clinical validity asks something harder: whether carrying that variant is actually tied to the health outcome the company says it's tied to. Authorized DTC tests have to clear 99% accuracy and 99% reproducibility on the analytical side, and SNP microarray technology genuinely earns that bar. Detecting the variant is the easy part.
Knowing what the variant means for a given body is the hard part, and DTC reports routinely present both as if they were the same achievement. A test can flag a caffeine-metabolism variant with total analytical confidence while the clinical relevance of that variant to how the body actually processes caffeine remains unsettled. Many DTC panels test a curated slice of known variants rather than sequencing the whole genome, so a clean result rules out only what was looked for, not everything that could be there. The report itself rarely marks any of this. Both kinds of claims, the well-established and the still-uncertain, show up in the same confident tone, and that flattening is where most misreading starts.
Where analytical accuracy breaks down: false positives in raw DTC data
The false-positive problem concentrates around rare variants, and the mechanism is straightforward once you see it. SNP arrays are built and tuned to catch common variants well, so when one flags something rare as disease-causing, that flag is likely wrong, according to a September 2025 joint position statement from the British Society for Genetic Medicine (BSGM). Tandy-Connor and colleagues at Ambry Genetics found that 40% of variants reported in DTC raw data, across the sample of genes they examined, turned out to be false positives. The finding has been disputed within the industry, and that dispute matters on its own terms.
The problem gets worse once raw data leaves the company that generated it. Consumers download their raw files and upload them to third-party interpretation services carrying no accreditation at all, and any error already baked into the raw data just rides along into the new interpretation. Services without appropriate expertise produce interpretations that can trigger real medical anxiety or push people toward decisions they never needed to make. The ACMG classification system is the accepted standard for single-gene disease variants, but nothing comparable exists for the statistical associations coming out of genome-wide association studies, so third-party tools fill that gap inconsistently, each running its own logic. BSGM's statement doesn't hedge on this: clinicians shouldn't take reports from non-accredited labs or third-party services at face value, full stop.
Polygenic risk scores: the sharpest point of the clinical validity gap
Polygenic risk scores add up the small effects of many variants scattered across the genome into a single number, and the statistics behind that idea hold up fine. What doesn't hold up, at least not yet, is handing that number to someone with no clinical background and calling it useful, as professional guidance on polygenic risk scores has made clear. A professional medical genetics body laid out the limits in 2023, and the limits are blunt: a PRS is not a diagnosis. A high score doesn't guarantee disease, a low score doesn't guarantee safety, and the tool performs worse for people of non-European ancestry than for the population it was built on. Evidence for using PRS in actual clinical care remains thin, and no formal guidelines exist for how a doctor should walk a patient through one.
Coronary artery disease is the best-studied case, and even there the payoff is modest. Adding a PRS to standard clinical risk models improves risk-category sorting in some cohorts, but proof that better sorting translates into better outcomes is still limited, as research summarized in PMC has shown. DTC customers rarely arrive at a PRS result with any of that context. They come out of curiosity, or a vague sense that more information is better, and get handed a number with no error bars and no professional interpretation attached, and that gap in context is a central concern raised by genetics researchers. That's the real defect: not the math behind the score, but the total absence of anything telling the customer what the number does and doesn't license them to conclude.
How reference database composition creates validity gaps that vary by ancestry
The science behind these tests was built overwhelmingly on one group of people, and pretending otherwise is the second major mistake this industry makes in its marketing. Roughly 91% of complex-trait genome-wide association studies have been done in populations of European ancestry. East Asian populations make up around 5%, and everyone else barely registers. The imbalance sharpens in specific disease areas: a paper in Frontiers in Genetics found African populations have more than 40 times fewer registered cardiovascular GWAS variants than European ancestry populations do.
That imbalance has a direct, measurable cost. Risk scores built from data skewed toward one ancestral group perform roughly twofold worse in East Asian individuals and 4.5-fold worse in individuals of African ancestry, compared to their performance in the populations they were built from, according to research summarized in PMC. The FDA requires companies to disclose these population limits in labeling, but a disclosure buried in a footnote and a confident headline result land very differently on the person reading them, and only one of the two actually gets read. For a non-European customer, the practical reality is a test with the same polished report and the same confident tone as everyone else gets, built on science that may never have been validated on anyone who looks like them.
What the regulatory framework currently does and does not enforce
The FDA has shown it's willing to act when it has the authority to. In 2013 it ordered 23andMe to stop marketing its Personal Genome Service, citing a lack of evidence for both analytical and clinical validity, and by 2015 it had authorized its first DTC genetic test, for Bloom Syndrome carrier status, as a Class II device with special controls. That precedent still stands. What's gone is the broader structure that would have extended it: the FDA's 2024 rule regulating laboratory-developed tests as medical devices got vacated entirely by a federal district court on March 31, 2025, and the agency followed up on September 19, 2025, with a final rule rescinding its own regulation. A layer of oversight that would have touched a wide range of DTC-adjacent products simply isn't there anymore.
Federal privacy law leaves its own gaps, and they're worth naming precisely. GINA, passed in 2008, blocks genetic discrimination in employment and health insurance but says nothing about life insurance, disability insurance, or long-term care insurance. HIPAA covers health information shared with a doctor's office, but most DTC companies operate outside the scope of that law, which means their customers may carry fewer protections than a patient in a clinical relationship. States have started filling gaps on their own terms: South Dakota's SB 49 takes effect July 2026, Indiana passed HB 1521, Utah's HB 182 restricts foreign-adversary access to genetic sequencing data starting in 2028, and Montana amended its Genetic Information Privacy Act in October 2025 to cover neurotechnology data too. None of this, state or federal, touches clinical validity standards. Privacy law is sprinting ahead while the underlying science sits exactly where it was.
The 23andMe bankruptcy as a clinical trust event, not just a data privacy event
23andMe filed for Chapter 11 in March 2025, and its database, covering more than 15 million people, was bought by TTAM Research Institute, a nonprofit founded by the company's own co-founder and former CEO, for $305 million. The public reaction told you what people actually understood was at stake. Reports from that period show a dramatic surge in traffic to the company's data-deletion pages. People weren't confused about what had happened: they grasped, in that moment, that their genetic data had become a corporate asset that could be sold, something the original marketing had never made clear.
Because HIPAA doesn't apply to DTC companies, those 15 million people had far less legal standing than they would have had as patients in a clinical relationship. The privacy angle absorbed most of the coverage, but the quieter question sits underneath it, and it's a validity question, not just a privacy one. Research-grade insight pulled from a proprietary DTC database depends on that database staying stable and consistently governed. Change who owns it, and you change who controls the evidence base every downstream health claim rests on.
Where genetic counselors currently stand, and why that matters for interpretation
A scoping review by McKinney and colleagues, published in Clinical Genetics in February 2026, looked at 44 publications on how genetic health professionals view DTC testing, split across three areas: attitudes and counseling experiences (30 studies), company-provided counseling (12 studies), and counselor-built tools for DTC consumers (2 studies). Of the studies on professional attitudes, 82% focused on professionals working in clinical settings, not the primary care and community settings where most DTC customers actually show up first, asking questions about a result they don't know how to read.
Genetic health professionals broadly agree that counseling matters for informed consent and for making sense of a result, but many also see DTC counseling as falling outside their job description entirely. Most wanted clearer practice guidelines and more resources, and most were uneasy about the conflict of interest built into a company counseling customers on its own test results, even while wanting that same company to shoulder more of the responsibility. Almost nothing has been published on the actual quality of counseling DTC companies provide directly: 12 papers touch on how much counseling exists, and none look at how good it is. BSGM's September 2025 statement doesn't soften this either: patients who show up with DTC results should get the same standard of care as anyone else, and those results shouldn't open the door to treatments not otherwise indicated for that condition. DTC testing has put genetic data in more hands than ever, but it hasn't put the expertise to read that data in more hands at all, and genetic health professionals, as a group, want more oversight of the industry. That's a professional consensus worth taking at face value.
How consumers and clinicians can read DTC results with appropriate skepticism
Start by asking what kind of claim is actually being made, because treating a monogenic result and a polygenic risk score as equivalent evidence is the mistake that causes the most damage downstream. A result tied to a single, well-understood gene carries a different evidence base than a PRS entirely. A clean result on a monogenic condition only rules out the specific variants that panel checked, nothing more, and a PRS is a probability statement, not a diagnosis, a point the ACMG's 2023 guidance states without qualification.
Ask which population the underlying research was based on, especially for anyone who isn't of European descent, since the accuracy gap across ancestry groups is documented and real. Treat raw data downloads with real suspicion: once that file leaves the original company and lands with a third-party interpretation tool, none of the original analytical checks travel with it, and there's no guarantee the new read is any good at all. Any monogenic finding flagged as medically actionable needs confirmation in a CLIA-certified clinical lab before it changes anything about a patient's care, which is standard guidance, not an extra precaution. For clinicians, BSGM's position from September 2025 draws the line clearly: don't take a non-accredited lab report or a third-party interpretation at face value, and treat the patient in front of you through the same referral pathways as anyone else, DTC result or not.
Genetic data changes hands, and after 2025 that's no longer an abstract risk. The 23andMe bankruptcy made it concrete for millions of people who'd never considered it before that moment. Anyone signing up for a DTC test is agreeing to more than a lab result. They're agreeing to a data relationship whose terms can shift long after the swab's already been mailed back.
Sources
- How Has the Rise of Direct‐To‐Consumer Genetic Testing Impacted Genetic Counselling Practice? A Scoping Review - McKinney - 2026 - Clinical Genetics - Wiley Online Library
- bsgm.org.uk
- Direct-to-Consumer Genetic Testing for Cardiovascular Disease: A Scientific Statement From the American Heart Association | Circulation
- Direct-to-Consumer Genetic Tests: FDA, FTC, Privacy, Clinical Validity, and Claims Control
- Addressing the accuracy of direct-to-consumer genetic testing - Genetics in Medicine
- mediacenter.23andme.com


