Support for your institution’s verification requirements.
CVENTBIO supports vendor reviews related to state laws, executive orders and institutional research-security policies. If your institution requires verification, contact us for assistance with its specific requirements.
Send the applicable policy or questionnaire, your institution’s name, the service you need and your review deadline. Please do not email patient records or genomic data with your inquiry.
Vendor & supply chain
Discuss ownership, sequencing equipment and software information requested by your procurement team.
Institutional forms
Request assistance with questionnaires and supporting documentation. Any signed representation requires review of the actual requirements.
STATE REFERENCE
Laws, executive orders & legislative status
This page covers the six states listed below. Summaries and status were reviewed September 12, 2026; this is a selected reference, not a survey of every state requirement.
Texas
Enacted · effective September 1, 2025
Texas Genomic Act of 2025 — HB 130
For covered facilities and entities working with human genomes, the Act restricts specified foreign-adversary-linked sequencers and software. It prohibits covered genomic-data storage in foreign-adversary countries and restricts access from those countries, with specified exceptions. It requires reasonable encryption, access controls and other cybersecurity practices; it does not impose a blanket U.S.-only storage rule.
It also restricts certain transfers during bankruptcy or reorganization and requires annual attorney certification. Enforcement includes $10,000 civil penalties per violation and a private action for harmed patients or research subjects.
Review topics: Equipment and software provenance, data locations and access, and applicable certification documentation.
Directs state agencies and public universities to strengthen safeguards against foreign-adversary security threats. Institutions implement their own purchasing and vendor-review procedures. CVENTBIO fully supports your institution’s GA-48 verification process; contact us with its requirements.
Florida Electronic Health Records Exchange Act — § 408.051
Covered health care providers using certified electronic health record technology must maintain patient information stored offsite, including in third-party cloud environments, in the continental United States, its territories or Canada under the current statutory text. This provision is specific to covered providers and records; it is not a blanket rule for every sequencing project involving a Florida resident.
Review topics: Whether the project involves covered health records, hosting locations and subcontracted storage.
Directs action to strengthen cybersecurity against foreign adversaries, including state procurement safeguards. Applicable agency rules and institutional purchasing policies should guide a vendor review.
Review topics: Technology providers, software and relevant procurement restrictions.
Restricts specified foreign-adversary-linked genetic sequencers and operational or research software at covered medical and genomic research facilities. It addresses human genomic data storage, remote access and security, with exceptions. The enacted text sets an initial sworn compliance statement deadline of December 31, 2028 and specified fine enforcement beginning May 1, 2028.
Review topics: Equipment and software provenance, data storage and remote access, and preparation for future requirements.
An act relating to genetic data privacy — H.639 / Act 135
Establishes requirements for direct-to-consumer genetic testing companies and their service providers, including consent, privacy and deletion rights. Covered genetic data and biological samples cannot be stored in specified sanctioned or foreign-adversary countries; transfer or storage outside the U.S. requires express consumer consent. The Act includes exemptions for specified HIPAA-regulated information and entities and qualifying research activities.
Review topics: Consent requirements, access and disclosure practices, sample retention and applicable data-handling requirements.
These bills are included to clarify their status. They are not executive orders and do not themselves establish current vendor requirements. Your institution may have separate policies.
Virginia
Not enacted · 2026 session
HB 685 — genetic sequencing provisions
The proposal included restrictions on certain genetic sequencing equipment, software and data storage at medical care facilities. It was left in the House Health and Human Services Committee. It should not be described as an enacted law or executive directive.
Support: Send any separate Virginia institutional policy that applies to your purchase so we can review the requested verification.
This bill proposed restrictions on certain genetic sequencing software and equipment and storage of human genetic sequencing data. The governor vetoed it; it is not an enacted requirement or executive order.
Support: We can discuss verification requested under your institution’s existing procurement or data-security policies.