HIPAA only applies to Covered Entities. 23andMe does not meet the HHS definition of a Covered Entity.
https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html
My completely uninformed guess is:
HIPAA only applies to Covered Entities. 23andMe does not meet the HHS definition of a Covered Entity.
https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html