Explore the 65-case collection
The series follows distinct security principles across human genomics, laboratory infrastructure, and non-human genetic resources. Case numbers identify records; they are not severity rankings. Evidence labels separate actual events from capabilities and hypothetical scenarios.
65 case studies
No case studies match. Reset the filters to see the full collection.
Consumer genetics and commercial data
Ambry Genetics Email-Account Breach
Unstructured Communications Are Genetic Data Stores
Veritas Genetics Portal Incident
Interface Exposure Must Be Scoped by Data Class
Consent, ownership, and biospecimens
Moore v. Regents Of The University Of California
Biospecimen Control Is Not One Right
Washington University v. Catalona
Custody, Ownership, and Withdrawal Are Distinct
Greenberg v. Miami Children's Hospital
Participant Contribution and Commercialization Drift
Texas Newborn Blood Spots
Collection Necessity Does Not Authorize Unlimited Reuse
Nuu-Chah-Nulth Blood-Sample Return
Specimen Mobility and Community Control
Association For Molecular Pathology v. Myriad
Ownership Boundaries Around Genetic Information
Re-identification and inference
Law enforcement and forensic genetics
Integrity, provenance, and laboratory failure
Discrimination and institutional use
Burlington Northern Santa Fe Genetic Testing
Genetic Testing as Institutional Power
Lowe v. Atlas Logistics
Genetic Protection Is Not Limited to Disease Risk
Fabricut And The First EEOC GINA Settlement
Family History Is Genetic Information
Norman-Bloodsaw v. Lawrence Berkeley Laboratory
General Consent Is Not Specific Consent
Reproductive and heritable genetics
Jan Karbaat And The Dutch Donor Registry Failure
Genetic Auditability of Reproductive Systems
Genomic cybersecurity and infrastructure
Illumina Local Run Manager Vulnerabilities
Instrument Software Is Part of the Genome
Pathogen and research-data governance
Genetic resources, agriculture, and biodiversity
The Vavilov Collection During The Siege Of Leningrad
Human Custodianship as a Security Control
Pavlovsk Experiment Station Development Threat
Land-Use Governance Can Destroy Genetic Assets
State surveillance and population security
Compare the evidence
Use the database to inspect scope and uncertainty across the collection.
Genetic Security Incident DatabaseHow to read a case
Start with the security principle and event summary. These explain why the case is included. Then look at the affected asset: a family-tree profile is different from a raw genotype file, and both differ from a stored blood sample. The distinction helps put dramatic headlines in proportion.
The evidence label tells you what kind of support exists. It is not a severity grade. A well-documented policy announcement may have no victims to count, while a disputed event may still raise serious questions. Read the limitation section before repeating a case as an example of a broader claim.
Choose a starting point
For an introduction to collection without intentional disclosure, begin with Stranger Visions. For the consequences of genetic relationships, compare the Golden State Killer investigation with the 23andMe incident. Both involve connections between people, but the access pathways and purposes differ substantially.
Havasupai and HeLa are useful together when thinking about time: what changes when specimens remain available and new research becomes possible? The NIST scenario shifts the focus to laboratory operations. The agricultural case then tests whether the same framework still makes sense when the asset is a resource collection rather than a person's profile.
Reading across these cases is more informative than sorting them into a single ranking. Ask which part of the security problem changes when the asset, purpose, or setting changes. That comparison is the main reason to use a shared case format.