Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Illinois Expands Genetic Privacy Law to Biomarkers

By Libbie Canter, Elizabeth Brim & Clare Mathias on August 11, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

The Illinois Governor recently signed SB 2886, which expands the scope of the state’s Genetic Information Privacy Act (“GIPA”) to include “biomarker testing” and “biomarker.” GIPA currently regulates the collection, use, and disclosure of genetic testing information.

The bill defines “biomarker” as “a characteristic that is objectively measured and evaluated as an indicator of normal biological processes, pathogenic processes, or pharmacologic responses to a specific therapeutic intervention,” which “includes, but is not limited to, gene mutations or protein expression.” The bill defines “biomarker testing” as “the analysis of a patient’s tissue, blood, or fluid biospecimen for the presence of a biomarker,” which “includes, but is not limited to, single-analyte tests, multi-plex panel tests, and partial or whole genome sequencing.”

The bill revises the legislative findings to reflect that biomarker testing, like genetic testing, can be “valuable to an individual” and that “public health will be served by facilitating its voluntary and confidential nondiscriminatory use of genetic testing and biomarker testing information.” As a result, SB 2886 extends GIPA’s protections to biomarker data, including:

  • Confidentiality protections: SB 2886 requires that the use of biomarker testing, and the information derived from testing, is confidential and privileged and may be released only to the individual tested and persons specifically authorized in writing by that individual.
  • Insurer prohibitions: The bill prohibits an insurer from seeking information derived from biomarker testing for use in connection with a policy of accident or health insurance (unless the individual voluntarily submits favorable results), for nontherapeutic purposes, or for underwriting purposes.
  • Employer limitations: Under SB 2886, an employer may not solicit, request, or require submission of biomarker information as a condition of employment. Where release of biomarker testing information is authorized, it must comply with the same restrictions that currently govern genetic testing information.
  • Disclosure restrictions: No person may disclose or be compelled to disclose the identity of any person upon whom a biomarker test is performed, or the results of a biomarker test, in a manner that permits identification of the subject, unless an exception applies.
  • Consent requirements: GIPA’s existing written consent requirements for the release of genetic testing information now extend to biomarker testing information.

GIPA has a private right of action, with damages of $2,500 per negligent violation and $15,000 per intentional or reckless violation. GIPA continues to be the basis for a large number of private lawsuits, though many (but not all) of these cases have been brought in the employment context. The amendments to GIPA enacted by SB 2886 take effect on January 1, 2027.

Photo of Libbie Canter Libbie Canter

Libbie Canter represents a wide variety of multinational companies on managing privacy, cyber security, and artificial intelligence risks, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with U.S. and global privacy laws.

Libbie Canter represents a wide variety of multinational companies on managing privacy, cyber security, and artificial intelligence risks, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with U.S. and global privacy laws. She routinely supports clients on their efforts to launch new products and services involving emerging technologies, and she has assisted dozens of clients with their efforts to prepare for and comply with federal and state laws, including the California Consumer Privacy Act, the Colorado AI Act, and other state laws. As part of her practice, she also regularly represents clients in strategic transactions involving personal data, cybersecurity, and artificial intelligence risk and represents clients in enforcement and litigation postures.

Libbie represents clients across industries, but she also has deep expertise in advising clients in highly-regulated sectors, including financial services and digital health companies. She counsels these companies — and their technology and advertising partners — on how to address legacy regulatory issues and the cutting edge issues that have emerged with industry innovations and data collaborations.

Chambers USA 2025 ranks Libbie in Band 3 Nationwide for both Privacy & Data Security: Privacy and Privacy & Data Security: Healthcare. Chambers USA notes, Libbie is “incredibly sharp and really thorough. She can do the nitty-gritty, in-the-weeds legal work incredibly well but she also can think of a bigger-picture business context and help to think through practical solutions.”

Read more about Libbie CanterEmail
Show more Show less
Photo of Elizabeth Brim Elizabeth Brim

Elizabeth Brim is an associate in the firm’s Washington, DC office, where she is a member of the Data Privacy and Cybersecurity and Health Care Practice Groups and advises clients on a broad range of regulatory and compliance issues related to privacy and…

Elizabeth Brim is an associate in the firm’s Washington, DC office, where she is a member of the Data Privacy and Cybersecurity and Health Care Practice Groups and advises clients on a broad range of regulatory and compliance issues related to privacy and health care.

Elizabeth’s practice includes counseling clients on compliance with the complex web of health information privacy laws and regulations, such as HIPAA, the FTC’s Health Breach Notification Rule, and state medical and consumer health privacy laws as well as state consumer privacy and genetic privacy laws. She also advises clients on health care compliance issues, such as fraud and abuse, market access, and pricing and reimbursement activities.

Elizabeth routinely advises on regulatory compliance as part of transactions, clinical trial programs, collaborations and other activities that involve genetic data, and the development and operation of digital health products. As part of her practice, Elizabeth routinely counsels clients on drafting and negotiating privacy and health care terms with vendors and third parties and developing privacy notices and consent forms. In addition, Elizabeth maintains an active pro bono practice.

Elizabeth is an author of the American Health Law Association treatise, Pricing, Market Access, and Reimbursement Principles: Drugs, Biologicals and Medical Devices and the U.S. chapter of the Global Legal Insights treatise, Pricing & Reimbursement Laws and Regulations.

Read more about Elizabeth BrimEmail
Show more Show less
Photo of Clare Mathias Clare Mathias

Clare Mathias is an associate in the firm’s Boston office. She is a member of the Data Privacy and Cybersecurity Practice Group and the Health Care Practice Group.

Clare advises clients on a wide range of privacy and health care issues, including compliance…

Clare Mathias is an associate in the firm’s Boston office. She is a member of the Data Privacy and Cybersecurity Practice Group and the Health Care Practice Group.

Clare advises clients on a wide range of privacy and health care issues, including compliance with federal health care regulations and U.S. state and federal privacy laws.

Clare also maintains an active pro-bono practice.

Email
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Inside Privacy
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo