Evidence: officially disclosed. Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.
Case at a glance
- Case number
- 009
- Date / range
- 2025-04-08
- Sector
- Security policy
- Genetic asset
- Bulk genomic and other covered sensitive data
- Security principle
- Genomic Sovereignty / Strategic Data Security
Event summary
The U.S. Department of Justice Data Security Program took effect April 8, 2025. It restricts or prohibits certain categories of transactions that could provide countries of concern or covered persons access to U.S. government-related data or Americans' bulk genomic and other sensitive personal data.
Source: U.S. DOJ Data Security Program.
Acquisition and processing
Regulation of certain transactions enabling covered access
What became inferable or exposed
Bulk genomic and other covered sensitive data
Genomic security is no longer only a healthcare privacy issue. U.S. policy now treats certain access to Americans' bulk genomic and other sensitive personal data as a national-security concern.
Affected parties and consent
- Direct parties
- No individual exposure event is asserted
- Indirect parties
- Potential population-level relevance; no event count assigned
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- Transaction restrictions and coverage depend on the rule
Security dimensions
Confidentiality
Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.
Integrity
No demonstrated data alteration established by the cited material.
Availability
No outage or destruction established in this case.
Provenance
Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.
A policy event changes the questions an organization asks
The case concerns a security-policy development rather than an observed disclosure. Its relevance is the attention it directs toward data access, counterparties, and transactions. The official DOJ program materials provide the controlling detail; this case explains why genomic information belongs in that discussion.
The site's analysis is that a review limited to the individual account can miss the wider access arrangement. For a hypothetical data service, it may be necessary to understand which parties can obtain or process information and through which agreements. That exercise begins with an accurate inventory, not an assumption that every international relationship falls into the same category.
Keep the policy claim narrower than the headline
A headline about genomic data and national security can suggest a universal prohibition. The case should instead direct the reader to the defined activities, data categories, parties, and conditions in the official materials. A short summary is not enough to decide whether a particular arrangement is covered.
Similarly, the existence of a rule does not prove that a named organization has violated it. Any compliance allegation would require a separate factual record and analysis. This entry contains no such finding.
Why no incident score is assigned
Population-scale information can raise broad exposure concerns, but the record does not identify one bounded dataset that was disclosed. A GER or GPR score would therefore describe an invented example rather than the policy event itself. Keeping those fields unassigned is a deliberate editorial choice.
For readers comparing this entry with a breach, the useful contrast is between a framework intended to govern access and evidence that a specific access occurred. Both belong in a research library, but they answer different questions and should not be combined into a single incident count.
GeneticSecurity.org analysis
Genetic Exposure Radius
Not assigned: no bounded observed exposure with sufficient evidence. Scenario scope must be specified before scoring.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Not assigned: the information exposed or its retention is insufficiently specified. Biological-resource loss is different from credential persistence.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
What this case does not prove
A policy development is not itself a documented breach, and not every genomic transaction is prohibited.
Mitigations and lessons
Map covered data, transaction types, counterparties, jurisdictions, and applicable exceptions using the official rule and guidance.
Primary sources
- PRIMARY SOURCE U.S. DOJ Data Security Program
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Last reviewed: September 19, 2026. Initial source synthesis; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-009. When Genomic Data Became a National-Security Data-Control Problem. GeneticSecurity.org. https://geneticsecurity.org/cases/009-doj-bulk-genomic-data-national-security/