Evidence: officially disclosed. Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.

Case at a glance

Case number
009
Date / range
2025-04-08
Sector
Security policy
Genetic asset
Bulk genomic and other covered sensitive data
Security principle
Genomic Sovereignty / Strategic Data Security

Event summary

The U.S. Department of Justice Data Security Program took effect April 8, 2025. It restricts or prohibits certain categories of transactions that could provide countries of concern or covered persons access to U.S. government-related data or Americans' bulk genomic and other sensitive personal data.

Source: U.S. DOJ Data Security Program.

Acquisition and processing

Regulation of certain transactions enabling covered access

What became inferable or exposed

Bulk genomic and other covered sensitive data

Genomic security is no longer only a healthcare privacy issue. U.S. policy now treats certain access to Americans' bulk genomic and other sensitive personal data as a national-security concern.

Security dimensions

Confidentiality

Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.

Integrity

No demonstrated data alteration established by the cited material.

Availability

No outage or destruction established in this case.

Provenance

Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.

A policy event changes the questions an organization asks

The case concerns a security-policy development rather than an observed disclosure. Its relevance is the attention it directs toward data access, counterparties, and transactions. The official DOJ program materials provide the controlling detail; this case explains why genomic information belongs in that discussion.

The site's analysis is that a review limited to the individual account can miss the wider access arrangement. For a hypothetical data service, it may be necessary to understand which parties can obtain or process information and through which agreements. That exercise begins with an accurate inventory, not an assumption that every international relationship falls into the same category.

Keep the policy claim narrower than the headline

A headline about genomic data and national security can suggest a universal prohibition. The case should instead direct the reader to the defined activities, data categories, parties, and conditions in the official materials. A short summary is not enough to decide whether a particular arrangement is covered.

Similarly, the existence of a rule does not prove that a named organization has violated it. Any compliance allegation would require a separate factual record and analysis. This entry contains no such finding.

Why no incident score is assigned

Population-scale information can raise broad exposure concerns, but the record does not identify one bounded dataset that was disclosed. A GER or GPR score would therefore describe an invented example rather than the policy event itself. Keeping those fields unassigned is a deliberate editorial choice.

For readers comparing this entry with a breach, the useful contrast is between a framework intended to govern access and evidence that a specific access occurred. Both belong in a research library, but they answer different questions and should not be combined into a single incident count.

GeneticSecurity.org analysis

Genetic Exposure Radius

Not assessed

Not assigned: no bounded observed exposure with sufficient evidence. Scenario scope must be specified before scoring.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Persistence Risk

Not assessed

Not assigned: the information exposed or its retention is insufficiently specified. Biological-resource loss is different from credential persistence.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Provenance Integrity

Not assessed

Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

What this case does not prove

A policy development is not itself a documented breach, and not every genomic transaction is prohibited.

Mitigations and lessons

Map covered data, transaction types, counterparties, jurisdictions, and applicable exceptions using the official rule and guidance.

Primary sources

Secondary sources

No additional source listed. See the evidence notes for limitations.

Policy and standards

Genetic Security Policy and Standards

Review and correction history

Last reviewed: September 19, 2026. Initial source synthesis; no substantive corrections recorded.

Correction policy and log

Cite this case

GS-CASE-009. When Genomic Data Became a National-Security Data-Control Problem. GeneticSecurity.org. https://geneticsecurity.org/cases/009-doj-bulk-genomic-data-national-security/