Scope - What This Guide Covers
This guide focuses on Vermont's health-related privacy laws: H.639 (genetic testing regulation) and S.71 (comprehensive privacy law with consumer health data provisions). If your organization collects genetic data from Vermont consumers, processes consumer health data, or uses geofencing near health facilities, understanding these requirements is essential.
This guide doesn't cover Vermont's general consumer privacy provisions unrelated to health data, HIPAA compliance, or de-identified data processing outside these laws' scope.
Key Concepts and Definitions
Direct-to-Consumer Genetic Testing Company under H.639 refers to any entity that:
- Sells or markets consumer-initiated genetic testing products directly to consumers.
- Analyzes genetic data obtained from a consumer (except when performed by licensed healthcare providers for diagnosis or treatment).
- Collects, uses, maintains, or discloses genetic data from direct-to-consumer testing or directly provided by consumers.
Consumer Health Data under S.71 includes any personal data used to identify a consumer's physical or mental health condition, diagnosis, or status. This explicitly covers gender-affirming health data and reproductive or sexual health data.
Neural Data is information generated by measuring central nervous system activity. Vermont joins Montana, Colorado, California, and Connecticut in regulating this emerging data category.
Biometric Data includes standard identifiers (fingerprints, retina scans, face geometry) plus Vermont-specific additions: vein patterns and gait or personally identifying physical movement patterns.
Requirements Breakdown
H.639: Genetic Testing Requirements
Consent Standard (Primary Purpose Rule) You must obtain separate consent for each use of genetic data or biological samples beyond the primary purpose of the genetic testing or service. The enacted version removed the phrase "and inherent contextual uses," tightening the consent scope.
Revocation Mechanism Your consent revocation mechanism must be as easy as the mechanism through which the consumer provided consent. Don't bury the revocation process in account settings if consent was a single click during checkout.
Third-Party Deletion Obligations When a consumer requests deletion of genetic data or destruction of a biological sample, you must notify any third parties to delete or destroy that consumer's data within 30 days of the request. This creates a cascading deletion obligation across your vendor ecosystem.
Contract Termination Requirements When your contract with a service provider ends, the service provider must immediately destroy all genetic data retained during the contractual period. The provider cannot disclose, transfer, or sell genetic data to any third party before destruction.
Government Disclosure Restrictions You cannot disclose any information about a consumer to a government entity (including genetic data or name) unless:
- A court issues a search warrant based on probable cause, or
- The consumer provides express consent after you notify them.
This restriction goes beyond typical law enforcement cooperation provisions in other state privacy laws.
S.71: Consumer Health Data Provisions
Processing Restrictions You cannot:
- Provide consumer health data to employees or contractors unless they're subject to a duty of confidentiality.
- Provide consumer health data to processors unless they comply with S.71's obligations.
- Use geofencing within 1,850 feet of any health care facility (including mental health or reproductive/sexual health facilities) to identify, track, collect data from, or send notifications to consumers regarding their consumer health data.
- Sell or offer to sell consumer health data without obtaining consent.
Applicability Threshold S.71's consumer health data requirements apply to any person conducting business in Vermont or targeting Vermonters, regardless of processing volume. You don't get the threshold exemptions that apply to S.71's other provisions.
Implementation Guidance
For Genetic Testing Companies
Consent Flow Architecture Map every use of genetic data beyond the primary testing purpose. Consider a team that offers ancestry testing but also wants to use samples for drug development research. You'll need separate, explicit consent for the research use, documented independently from the initial testing consent.
Build your consent management system to track purpose-specific authorizations at the individual consumer level. Your database schema should support one-to-many relationships between consumers and consent records.
Vendor Contract Amendments Review every service provider agreement. Add termination clauses requiring immediate data destruction and prohibiting post-termination transfers. Include audit rights to verify destruction. Your contract should specify the technical method of destruction (cryptographic erasure, physical destruction, secure deletion protocols).
Government Request Protocols Establish internal procedures for evaluating government requests. Your legal team needs clear escalation paths and response templates. Document your probable cause assessment for each warrant. If you receive an administrative subpoena without judicial oversight, you'll need to push back or seek consumer consent.
For Organizations Processing Consumer Health Data
Geofence Audit If you use location-based advertising or analytics, audit every geofence. Calculate the distance from health facilities in Vermont. The 1,850-foot restriction creates a meaningful buffer zone that will likely capture adjacent businesses and parking areas.
Maintain a database of Vermont health facility locations and implement real-time distance calculations before deploying any geofence. Don't rely on facility type classifications in third-party data, which may miss mental health or reproductive health facilities.
Confidentiality Obligations Review your employee and contractor agreements. Add specific confidentiality clauses covering consumer health data. Your standard NDA may not satisfy S.71's "duty of confidentiality" requirement if it only protects company trade secrets.
Sensitive Data Classification Update your data classification schema to flag biometric data (including vein patterns and gait recognition) and neural data as sensitive information. These categories trigger heightened obligations under S.71. Your data discovery tools need to identify these data types during processing activities.
Common Pitfalls
Assuming HIPAA Exemption Applies Broadly H.639 exempts HIPAA-covered entities and information, but only when you're actually operating under HIPAA's rules. If you're a direct-to-consumer genetic testing company, you're likely not a covered entity. Don't assume healthcare industry involvement equals HIPAA coverage.
Overlooking Service Provider Obligations If you're a processor receiving genetic data or consumer health data from a Vermont controller, you're bound by these laws' requirements. Your contract doesn't shield you from S.71's processor obligations or H.639's destruction requirements.
Treating Revocation as Opt-Out H.639's "at least as easy" standard means consent revocation can't be harder than consent provision. If consumers consented via a checkbox during account creation, revocation must be equally simple. A five-step account deletion process won't satisfy this standard.
Ignoring the No-Threshold Rule S.71's consumer health data provisions apply regardless of your processing volume. Even if you're a small business processing minimal Vermont consumer data, you're subject to the geofencing restriction, sale prohibition, and confidentiality requirements.
Underestimating Geofence Calculation Complexity 1,850 feet is roughly 0.35 miles. In urban areas, this radius will overlap multiple blocks. Your geofence system needs precise facility location data and real-time distance calculation. Manual review won't scale.
Quick Reference Table
| Requirement | Law | Effective Date | Cure Period | Enforcement |
|---|---|---|---|---|
| Genetic testing consent and deletion | H.639 | July 1, 2026 | Through June 30, 2028 (consumer actions only) | Vermont AG; private right of action |
| Consumer health data restrictions | S.71 | January 1, 2028 | None specified | Vermont AG (exclusive) |
| Geofence prohibition (1,850 ft) | S.71 | January 1, 2028 | None specified | Vermont AG (exclusive) |
| Third-party deletion notification (30 days) | H.639 | July 1, 2026 | Through June 30, 2028 (consumer actions only) | Vermont AG; private right of action |
| Government disclosure restrictions | H.639 | July 1, 2026 | Through June 30, 2028 (consumer actions only) | Vermont AG; private right of action |
| Biometric/neural data as sensitive data | S.71 | January 1, 2028 | None specified | Vermont AG (exclusive) |
Key Dates to Calendar:
- July 1, 2026: H.639 takes effect
- June 30, 2028: H.639 cure period expires; consumer civil actions enforceable
- January 1, 2028: S.71 takes effect
Your compliance timeline should account for vendor contract negotiations, system architecture changes, and staff training well before these effective dates. Start H.639 implementation planning now if you're processing genetic data from Vermont consumers.





