Evidence: historical governance case. Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.
Case at a glance
- Case number
- 004
- Date / range
- 1990s–2010
- Sector
- Research governance
- Genetic asset
- Retained blood samples and secondary research uses
- Security principle
- Purpose Drift / Secondary-Use Consent Failure
Event summary
Havasupai Tribe members provided blood in the context of research focused on type 2 diabetes. The samples were later used in additional research involving topics including schizophrenia, migration, and inbreeding. Litigation followed. A 2010 settlement included monetary compensation and return of blood samples.
Source: ASU repository: Havasupai research ethics resource.
Source: Havasupai research-consent analysis.
Acquisition and processing
Research reuse beyond the diabetes-focused collection context
What became inferable or exposed
Retained blood samples and secondary research uses
Consent to collect a biological sample for one understood research purpose does not automatically resolve the ethical and governance questions around later unrelated genetic research.
Affected parties and consent
- Direct parties
- Participating Havasupai Tribe members
- Indirect parties
- The identifiable community and its members
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- Disputed scope of consent and later secondary use
Security dimensions
Confidentiality
Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.
Integrity
No demonstrated data alteration established by the cited material.
Availability
No outage or destruction established in this case.
Provenance
Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.
Follow the permission as well as the sample
This case invites a different question from a conventional intrusion report. The issue is not simply whether researchers could reach stored material. It is whether later uses matched the purposes participants understood and authorized. A complete security review therefore needs a record of permitted use alongside a record of custody.
Those records answer different questions. Custody can establish who held a specimen and when. It does not, by itself, establish that every analysis performed by that holder was appropriate. Conversely, an approved research purpose does not prove that labels, transfers, or digital outputs were handled reliably.
Why community context belongs in the analysis
The proposed GER-4 classification reflects the community-level implications described in the case. It should not be read as a measured count of people exposed or a declaration that every participant experienced the same consequence. Individual experiences and collective concerns can coexist without being interchangeable.
A careful account also avoids turning the dispute into a generic story about stolen samples. Doing so erases the specific governance issue that makes the case instructive: material supplied in one research context remained available for other questions. Understanding that distinction helps a reader recognize similar problems even when there is no computer intrusion.
A practical governance question
For a hypothetical new study using an existing collection, ask what evidence connects the proposed analysis to the permitted purposes of the original collection. Who can review an ambiguous request, and how is that decision communicated? If permission is uncertain, technical access should not be treated as the answer.
These questions are the site's lessons from the case. They do not replace the historical sources, speak for the community, or claim that a single consent procedure resolves every research relationship.
GeneticSecurity.org analysis
Genetic Exposure Radius
Analysis: The identifiable community and its members. The rating describes possible scope, not harm or a count of affected people.
Confidence: moderate. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Not assigned: the information exposed or its retention is insufficiently specified. Biological-resource loss is different from credential persistence.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
What this case does not prove
This was a dispute over consent and secondary use, not evidence of a conventional computer intrusion.
Mitigations and lessons
Track permitted research purposes; involve community governance; make sample return, secondary-use review, and retention decisions auditable.
Primary sources
No additional source listed. See the evidence notes for limitations.
Secondary sources
- SECONDARY SOURCE Havasupai research-consent analysis
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Last reviewed: September 19, 2026. Initial source synthesis; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-004. Havasupai: When a Genetic Sample Outlived the Consent That Collected It. GeneticSecurity.org. https://geneticsecurity.org/cases/004-havasupai-secondary-use-consent/