[
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Selected-marker analysis and speculative computational portraiture",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection did not involve intentional sample submission",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": "Immediate kin / direct network",
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": "moderate",
    "ger_notes": null,
    "gpr_label": "Durable derivative",
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": "low",
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-001",
    "case_number": "001",
    "slug": "/cases/001-stranger-visions/",
    "title": "Stranger Visions: What a Cigarette Butt Revealed About Genetic Surveillance",
    "short_title": "Stranger Visions",
    "summary": "Artist Heather Dewey-Hagborg's Stranger Visions project collected discarded biological material such as cigarette butts, chewing gum, and hair, extracted DNA, examined selected markers, and used genetic inferences plus computational interpretation to create speculative 3D portraits. The important security lesson is not that DNA can perfectly reconstruct a face. It cannot. The lesson is that discarded biological material can become an input to genetic analysis without the source person intentionally submitting a sample.",
    "direct_answer": "Humans routinely leave biological material in public without intending to disclose genetic information.",
    "event_label": "2012–2013",
    "sector": "Art / public space",
    "event_type": "documented_event",
    "genetic_asset_type": "Discarded biological material and selected marker-derived traits",
    "ger_level": 1,
    "gpr_level": 2,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "artist",
      "nhpr"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Unintentional Genetic Disclosure",
    "processing": "Selected-marker analysis and speculative computational portraiture",
    "direct_parties": "Passersby whose discarded material was collected",
    "indirect_parties": "Relatives could share markers; no measured indirect exposure count",
    "consent_status": "Collection did not involve intentional sample submission",
    "mitigations": "Limit specimen collection; document purpose, retention, and marker selection. Distinguish trait inference from identity verification.",
    "limitations": "It does not prove that a discarded cigarette can yield a photographically accurate face from DNA alone.",
    "ger_basis": "Analysis: Relatives could share markers; no measured indirect exposure count. The rating describes possible scope, not harm or a count of affected people.",
    "gpr_basis": "Only limited marker-derived traits are established here. Retention of a full identifying genotype is not assumed.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-001",
    "family_codes": [
      "RI"
    ],
    "family": "Re-identification and inference",
    "primary_query": "Unintentional Genetic Disclosure",
    "status": "documented_event",
    "jurisdictions": [],
    "asset_classes": [
      "Discarded biological material and selected marker-derived traits"
    ],
    "threat_codes": [
      "Unintentional Genetic Disclosure"
    ],
    "imported": false,
    "clusters": [
      "Collection and inference"
    ],
    "related_case_ids": [
      "GS-CASE-007",
      "GS-CASE-011"
    ],
    "related_comparisons": [
      {
        "case_number": "007",
        "text": "Compare Forensic DNA phenotyping for genetic inference. This case focuses on unintentional genetic disclosure."
      },
      {
        "case_number": "011",
        "text": "Compare 1Health / Vitagene FTC Enforcement for deletion integrity and cloud exposure. This case focuses on unintentional genetic disclosure."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The important boundary is before the portrait",
        "text": "The portrait is the memorable output, but the security question begins earlier: biological traces became material for analysis without an intentional submission by their sources. Keeping that step in view helps explain the project even when a reader is skeptical of the resulting likenesses. The acquisition question and the prediction question do not depend on the same evidence.  A useful way to read the case is to separate collection, extraction, marker analysis, interpretation, and presentation. Each stage adds assumptions. A displayed face combines analytical choices with a visual form that can appear more certain than the underlying inference. Its apparent realism is not a measure of identification accuracy."
      },
      {
        "heading": "An incomplete result can still raise a privacy question",
        "text": "In the site's analysis, a limited or uncertain inference can matter without identifying the source. Information may be unwanted, misleading, or taken out of context. That possibility does not establish that a specific person was harmed by this project; it explains why “not an exact face” is an important limitation rather than a complete answer to the collection issue.  The assigned persistence level is deliberately bounded to the information described. If a different event involved retained identifying profiles or extensive sequence data, it would need a fresh assessment. The existence of biological material alone does not tell us which digital artifacts were retained or how they could later be used."
      },
      {
        "heading": "A useful comparison",
        "text": "Compare this case with forensic phenotyping. Both concern inference from a sample, but this project foregrounds the circumstances of acquisition. When discussing either, specify whether the claim concerns collecting material, predicting traits, or establishing identity. Combining those three claims into one makes the technology sound more capable and the evidence less precise than it is."
      }
    ]
  },
  {
    "event_date_start": "2018-04-24",
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Genealogy comparison, family-tree research, candidate narrowing, and direct DNA confirmation",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Uploading relatives and the investigated individual have different consent relationships",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": "Genealogical / network scale",
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": "moderate",
    "ger_notes": null,
    "gpr_label": "Persistent genetic profile",
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": "low",
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-002",
    "case_number": "002",
    "slug": "/cases/002-golden-state-killer-genetic-genealogy/",
    "title": "The Relative Who Never Consented: Genetic Genealogy and the Golden State Killer Investigation",
    "short_title": "Golden State Killer",
    "summary": "Investigators used crime-scene genetic information with genealogy matching, distant-relative relationships, family-tree research, demographic filtering, and later direct DNA comparison to identify Joseph James DeAngelo. The site's focus is not the crimes themselves; it is the architecture of relational genetic identification.",
    "direct_answer": "A person does not necessarily need to have personally uploaded DNA to a genealogy database for relatives' genetic data to help investigators narrow identity.",
    "event_label": "2018",
    "sector": "Law enforcement",
    "event_type": "documented_event",
    "genetic_asset_type": "Crime-scene genetic profile and genealogical relationships",
    "ger_level": 3,
    "gpr_level": 3,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "genome",
      "genealogy"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Kinship Leakage",
    "processing": "Genealogy comparison, family-tree research, candidate narrowing, and direct DNA confirmation",
    "direct_parties": "Crime-scene source and database participants involved in matching",
    "indirect_parties": "Extended relatives used to narrow a family tree",
    "consent_status": "Uploading relatives and the investigated individual have different consent relationships",
    "mitigations": "Constrain database access; separate investigative leads from identification; require independent confirmation and documented authority.",
    "limitations": "A distant cousin match does not automatically identify a person. Genealogical and investigative work plus confirmatory evidence are required.",
    "ger_basis": "Analysis: Extended relatives used to narrow a family tree. The rating describes possible scope, not harm or a count of affected people.",
    "gpr_basis": "The described profile can remain useful for identification or comparison; retention and future linkability remain uncertain.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-002",
    "family_codes": [
      "LE"
    ],
    "family": "Law enforcement and forensic genetics",
    "primary_query": "Kinship Leakage",
    "status": "documented_event",
    "jurisdictions": [],
    "asset_classes": [
      "Crime-scene genetic profile and genealogical relationships"
    ],
    "threat_codes": [
      "Kinship Leakage"
    ],
    "imported": false,
    "clusters": [
      "Genealogy governance"
    ],
    "related_case_ids": [
      "GS-CASE-006",
      "GS-CASE-012",
      "GS-CASE-030",
      "GS-CASE-031"
    ],
    "related_comparisons": [
      {
        "case_number": "006",
        "text": "Compare GEDmatch for governance as a security control. This case focuses on kinship leakage."
      },
      {
        "case_number": "012",
        "text": "Compare GEDmatch 2020 Permissions Breach for consent-state integrity. This case focuses on kinship leakage."
      },
      {
        "case_number": "030",
        "text": "Compare FamilyTreeDNA And FBI Matching for material policy change. This case focuses on kinship leakage."
      },
      {
        "case_number": "031",
        "text": "Compare Buckskin Girl / Marcia King for restorative identification. This case focuses on kinship leakage."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "A relative match is the beginning of a lead",
        "text": "The security principle here is the path from one person's genetic information to a question about someone else. A genealogy comparison can point toward relationships that become useful when combined with other records. It should not be described as a database producing a complete identity from a single distant match.  This distinction matters for privacy and for the quality of an investigation. A lead can be useful while remaining uncertain. Confirmation has a different purpose: testing whether the candidate actually matches the relevant evidence. Readers should resist collapsing the entire chain into the phrase “DNA identified him,” which hides the intermediate reasoning."
      },
      {
        "heading": "Why the radius extends beyond the uploader",
        "text": "The proposed GER classification concerns the connected family network used to narrow possibilities. It does not mean that every member of the family was identified, investigated, or harmed. Those would be separate claims requiring evidence about the actual investigation.  Nor does the classification resolve whether a particular access was lawful or ethically justified. It describes the mechanism of relational exposure. The purpose of the investigation, the applicable rules, and the interests of people whose data contributed to a lead all deserve their own analysis."
      },
      {
        "heading": "What a careful account should preserve",
        "text": "When explaining a similar investigation, identify the comparison service, the type of profile, the role of family research, and the independent confirmation described by the sources. If the public record does not disclose a stage, leave the gap visible. A plausible reconstruction of a workflow should not be presented as an investigator's documented account.  That discipline makes the case transferable: it helps readers understand the relationship between matching and identification without teaching them to assume that every genealogy search follows exactly the same procedure."
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Credential stuffing followed by access to connected profile features",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Unauthorized access; feature participation is not consent to attacker access",
    "law_enforcement": false,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": "Genealogical / network scale",
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": "moderate",
    "ger_notes": null,
    "gpr_label": "Durable derivative",
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": "low",
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-003",
    "case_number": "003",
    "slug": "/cases/003-23andme-genetic-graph-amplification/",
    "title": "23andMe 2023: When Account Compromise Reached a Genetic Network",
    "short_title": "23andMe 2023",
    "summary": "23andMe disclosed that a small percentage of user accounts were accessed through credential stuffing, while approximately 5.5 million DNA Relative profiles and approximately 1.5 million Family Tree profiles connected to those accounts were accessed.",
    "direct_answer": "The impact of a compromised account may extend beyond the account owner when genetic-relative and family-tree features connect that account to other people.",
    "event_label": "2023",
    "sector": "Consumer genetics",
    "event_type": "documented_event",
    "genetic_asset_type": "Account information, DNA Relatives profiles, and Family Tree profiles",
    "ger_level": 3,
    "gpr_level": 2,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 1,
    "sources": [
      "sec"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Genetic Graph Amplification",
    "processing": "Credential stuffing followed by access to connected profile features",
    "direct_parties": "Compromised account holders and profiles connected through sharing features",
    "indirect_parties": "Additional relatives potentially inferable from relationships; count unknown",
    "consent_status": "Unauthorized access; feature participation is not consent to attacker access",
    "mitigations": "Require strong authentication, detect credential reuse attacks, limit automated enumeration, and review the reach of sharing features.",
    "limitations": "The disclosure does not establish that 5.5 million whole genomes were stolen. Distinguish account/profile information, genetic-relative information, and raw genomic data.",
    "ger_basis": "Analysis: Additional relatives potentially inferable from relationships; count unknown. The rating describes possible scope, not harm or a count of affected people.",
    "gpr_basis": "This rating covers persistent profile and relationship information. It does not assert whole-genome disclosure.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-003",
    "family_codes": [
      "CG"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "Genetic Graph Amplification",
    "status": "documented_event",
    "jurisdictions": [],
    "asset_classes": [
      "Account information, DNA Relatives profiles, and Family Tree profiles"
    ],
    "threat_codes": [
      "Genetic Graph Amplification"
    ],
    "imported": false,
    "clusters": [
      "Breach classification"
    ],
    "related_case_ids": [
      "GS-CASE-013",
      "GS-CASE-048",
      "GS-CASE-049",
      "GS-CASE-050"
    ],
    "related_comparisons": [
      {
        "case_number": "013",
        "text": "Compare MyHeritage 2018 Breach: A Negative Control for exposure classification accuracy. This case focuses on genetic graph amplification."
      },
      {
        "case_number": "048",
        "text": "Compare Ambry Genetics Email-Account Breach for unstructured communications are genetic data stores. This case focuses on genetic graph amplification."
      },
      {
        "case_number": "049",
        "text": "Compare DNA Diagnostics Center 2021 Breach for legacy-system discovery failure. This case focuses on genetic graph amplification."
      },
      {
        "case_number": "050",
        "text": "Compare Veritas Genetics Portal Incident for interface exposure must be scoped by data class. This case focuses on genetic graph amplification."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "Count accounts, profiles, and people separately",
        "text": "The disclosed profile counts describe different features. They should not be added together and announced as a verified count of unique people without evidence about overlap. Likewise, an account used as an entry point is not the same unit as every profile accessible through that account.  This is the central analytical lesson of the case. An incident can begin with a limited set of credentials yet reach information shared through connected features. Describing only the entry accounts can understate the reachable data; describing every reachable profile as a stolen genome can overstate what the data contains."
      },
      {
        "heading": "Containment has two boundaries",
        "text": "At the account boundary, the aim is to stop unauthorized sign-in and misuse of an authenticated session. At the sharing boundary, the question is what that session can retrieve about other users. Reviewing one boundary without the other can leave an important part of the exposure unexplained.  As a hypothetical design review, ask what a legitimate user needs to see about a genetic relative and whether the same information can be collected repeatedly at scale. The answer should guide access limits and monitoring. This is a proposed review exercise, not a claim about controls that were or were not present during the incident."
      },
      {
        "heading": "Why a lower GPR does not mean “unimportant”",
        "text": "The provisional GPR-2 assessment is scoped to the profile and relationship information described here. It does not score every possible artifact in every affected account. A dataset can expose private relationships without being a high-fidelity sequence file. Its consequences still depend on the fields, the people involved, and how information is combined later.  Readers comparing incidents should preserve that scope. A count and a score are useful only when the record explains what each one measures."
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Research reuse beyond the diabetes-focused collection context",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Disputed scope of consent and later secondary use",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": "Population / community scale",
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": "moderate",
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-004",
    "case_number": "004",
    "slug": "/cases/004-havasupai-secondary-use-consent/",
    "title": "Havasupai: When a Genetic Sample Outlived the Consent That Collected It",
    "short_title": "Havasupai",
    "summary": "Havasupai Tribe members provided blood in the context of research focused on type 2 diabetes. The samples were later used in additional research involving topics including schizophrenia, migration, and inbreeding. Litigation followed. A 2010 settlement included monetary compensation and return of blood samples.",
    "direct_answer": "Consent to collect a biological sample for one understood research purpose does not automatically resolve the ethical and governance questions around later unrelated genetic research.",
    "event_label": "1990s–2010",
    "sector": "Research governance",
    "event_type": "documented_event",
    "genetic_asset_type": "Retained blood samples and secondary research uses",
    "ger_level": 4,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 0,
    "sources": [
      "asu",
      "havasupai"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Purpose Drift / Secondary-Use Consent Failure",
    "processing": "Research reuse beyond the diabetes-focused collection context",
    "direct_parties": "Participating Havasupai Tribe members",
    "indirect_parties": "The identifiable community and its members",
    "consent_status": "Disputed scope of consent and later secondary use",
    "mitigations": "Track permitted research purposes; involve community governance; make sample return, secondary-use review, and retention decisions auditable.",
    "limitations": "This was a dispute over consent and secondary use, not evidence of a conventional computer intrusion.",
    "ger_basis": "Analysis: The identifiable community and its members. The rating describes possible scope, not harm or a count of affected people.",
    "gpr_basis": "Not assigned: the information exposed or its retention is insufficiently specified. Biological-resource loss is different from credential persistence.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-004",
    "family_codes": [
      "CO"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Purpose Drift / Secondary-Use Consent Failure",
    "status": "documented_event",
    "jurisdictions": [],
    "asset_classes": [
      "Retained blood samples and secondary research uses"
    ],
    "threat_codes": [
      "Purpose Drift / Secondary-Use Consent Failure"
    ],
    "imported": false,
    "clusters": [
      "Consent and biospecimens"
    ],
    "related_case_ids": [
      "GS-CASE-005",
      "GS-CASE-014",
      "GS-CASE-015",
      "GS-CASE-016"
    ],
    "related_comparisons": [
      {
        "case_number": "005",
        "text": "Compare Henrietta Lacks / HeLa for familial genomic consent. This case focuses on purpose drift / secondary-use consent failure."
      },
      {
        "case_number": "014",
        "text": "Compare Moore v. Regents Of The University Of California for biospecimen control is not one right. This case focuses on purpose drift / secondary-use consent failure."
      },
      {
        "case_number": "015",
        "text": "Compare Washington University v. Catalona for custody, ownership, and withdrawal are distinct. This case focuses on purpose drift / secondary-use consent failure."
      },
      {
        "case_number": "016",
        "text": "Compare Greenberg v. Miami Children's Hospital for participant contribution and commercialization drift. This case focuses on purpose drift / secondary-use consent failure."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "Follow the permission as well as the sample",
        "text": "This case invites a different question from a conventional intrusion report. The issue is not simply whether researchers could reach stored material. It is whether later uses matched the purposes participants understood and authorized. A complete security review therefore needs a record of permitted use alongside a record of custody.  Those records answer different questions. Custody can establish who held a specimen and when. It does not, by itself, establish that every analysis performed by that holder was appropriate. Conversely, an approved research purpose does not prove that labels, transfers, or digital outputs were handled reliably."
      },
      {
        "heading": "Why community context belongs in the analysis",
        "text": "The proposed GER-4 classification reflects the community-level implications described in the case. It should not be read as a measured count of people exposed or a declaration that every participant experienced the same consequence. Individual experiences and collective concerns can coexist without being interchangeable.  A careful account also avoids turning the dispute into a generic story about stolen samples. Doing so erases the specific governance issue that makes the case instructive: material supplied in one research context remained available for other questions. Understanding that distinction helps a reader recognize similar problems even when there is no computer intrusion."
      },
      {
        "heading": "A practical governance question",
        "text": "For a hypothetical new study using an existing collection, ask what evidence connects the proposed analysis to the permitted purposes of the original collection. Who can review an ambiguous request, and how is that decision communicated? If permission is uncertain, technical access should not be treated as the answer.  These questions are the site's lessons from the case. They do not replace the historical sources, speak for the community, or claim that a single consent procedure resolves every research relationship."
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Whole-genome sequencing transformed the informational significance of retained cells",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Original tissue collection without her knowledge or consent; subsequent controlled-access governance",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": "Extended kinship",
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": "moderate",
    "ger_notes": null,
    "gpr_label": "Persistent + network amplified",
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": "low",
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-005",
    "case_number": "005",
    "slug": "/cases/005-henrietta-lacks-hela-genomic-consent/",
    "title": "Henrietta Lacks: When One Cell Line Became a Family Genomic Privacy Question",
    "short_title": "Henrietta Lacks / HeLa",
    "summary": "HeLa cells were derived from Henrietta Lacks' tumor tissue in 1951 without her knowledge or consent. In 2013, after publication of HeLa whole-genome sequence information raised family privacy concerns, NIH and members of the Lacks family reached an agreement establishing controlled access to NIH-supported HeLa whole-genome sequence data.",
    "direct_answer": "Genomic information derived from a long-established research cell line can reveal information relevant to biological relatives, raising privacy and governance questions that extend beyond the original specimen source.",
    "event_label": "1951 / 2013",
    "sector": "Biomedical research",
    "event_type": "documented_event",
    "genetic_asset_type": "HeLa whole-genome sequence information and a persistent cell line",
    "ger_level": 2,
    "gpr_level": 5,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 1,
    "sources": [
      "nih"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Familial Genomic Consent",
    "processing": "Whole-genome sequencing transformed the informational significance of retained cells",
    "direct_parties": "Henrietta Lacks as the original tissue source",
    "indirect_parties": "Biological relatives with shared inherited variation",
    "consent_status": "Original tissue collection without her knowledge or consent; subsequent controlled-access governance",
    "mitigations": "Review new uses as analytical capability changes; govern access and include affected family perspectives.",
    "limitations": "The agreement is not blanket permission for every use of every HeLa-derived artifact.",
    "ger_basis": "Analysis: Biological relatives with shared inherited variation. The rating describes possible scope, not harm or a count of affected people.",
    "gpr_basis": "Whole-genome information can retain future inference value and familial relevance.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-005",
    "family_codes": [
      "CO"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Familial Genomic Consent",
    "status": "documented_event",
    "jurisdictions": [],
    "asset_classes": [
      "HeLa whole-genome sequence information and a persistent cell line"
    ],
    "threat_codes": [
      "Familial Genomic Consent"
    ],
    "imported": false,
    "clusters": [
      "Consent and biospecimens"
    ],
    "related_case_ids": [
      "GS-CASE-004",
      "GS-CASE-014",
      "GS-CASE-015",
      "GS-CASE-016"
    ],
    "related_comparisons": [
      {
        "case_number": "004",
        "text": "Compare Havasupai for purpose drift / secondary-use consent failure. This case focuses on familial genomic consent."
      },
      {
        "case_number": "014",
        "text": "Compare Moore v. Regents Of The University Of California for biospecimen control is not one right. This case focuses on familial genomic consent."
      },
      {
        "case_number": "015",
        "text": "Compare Washington University v. Catalona for custody, ownership, and withdrawal are distinct. This case focuses on familial genomic consent."
      },
      {
        "case_number": "016",
        "text": "Compare Greenberg v. Miami Children's Hospital for participant contribution and commercialization drift. This case focuses on familial genomic consent."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "Time changes what a specimen can reveal",
        "text": "A stored biological resource can remain in use while analytical methods change around it. The questions that become possible years later may differ from those considered at collection. In this case, the genomic-data issue makes that time dimension visible: long-standing research use did not eliminate the need to examine the implications of a new kind of information.  The site's persistence analysis focuses on that continuing potential for reuse and familial relevance. It is not a claim that every sequence derived from a cell line provides an exact representation of every relative. The asset, the analytical method, and the claimed inference still need to be specified."
      },
      {
        "heading": "Access rules are part of the response",
        "text": "The cited NIH guidance provides a concrete example of governing access to a defined class of genomic data. A reader should preserve that scope rather than treating the arrangement as a universal rule for all HeLa materials, all research outputs, or all historical specimens.  From a security perspective, the useful question is what decisions occur before data is made available: which requests are eligible, which conditions attach to access, and how those conditions are communicated. Governance can establish boundaries even where the underlying biological source cannot be replaced."
      },
      {
        "heading": "The lesson for retained collections",
        "text": "For another collection, a change in analytical capability is a reason to revisit the proposed use. It need not imply that all historical work must be reassessed in exactly the same way. Begin with the actual material, the new output, and the people whose interests could be affected.  That approach keeps the lesson specific. The security problem is the relationship between a persistent resource and changing uses, not an assumption that the passage of time either grants unlimited permission or makes all future research impossible."
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Genetic matching controlled by service rules and kit-level choices",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Settings govern comparisons; relatives may not themselves be users",
    "law_enforcement": true,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": "Genealogical / network scale",
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": "moderate",
    "ger_notes": null,
    "gpr_label": "Persistent genetic profile",
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": "low",
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-006",
    "case_number": "006",
    "slug": "/cases/006-gedmatch-law-enforcement-governance/",
    "title": "GEDmatch: How Database Policy Changes Alter Genetic Exposure",
    "short_title": "GEDmatch",
    "summary": "GEDmatch states that in May 2019 it began an opt-in policy concerning comparison with law-enforcement kits used to identify perpetrators of violent crimes. Current service documentation describes several privacy settings including Private, Personal Research, Opt-in, and Opt-out.",
    "direct_answer": "Genetic exposure is affected not only by encryption or account security but by platform policy, matching rules, consent defaults, and who is allowed to query a genetic database.",
    "event_label": "2019 onward",
    "sector": "Genetic genealogy",
    "event_type": "documented_event",
    "genetic_asset_type": "Uploaded genotype kits and matching relationships",
    "ger_level": 3,
    "gpr_level": 3,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "gedmatch"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Governance as a Security Control",
    "processing": "Genetic matching controlled by service rules and kit-level choices",
    "direct_parties": "People whose kits are compared under platform settings",
    "indirect_parties": "Relatives whose relationships become inferable",
    "consent_status": "Settings govern comparisons; relatives may not themselves be users",
    "mitigations": "Record the applicable policy version and selected settings; distinguish perpetrator searches from unidentified remains; reassess policies over time.",
    "limitations": "A privacy setting does not erase copies already obtained or constitute consent from every genetic relative.",
    "ger_basis": "Analysis: Relatives whose relationships become inferable. The rating describes possible scope, not harm or a count of affected people.",
    "gpr_basis": "The described profile can remain useful for identification or comparison; retention and future linkability remain uncertain.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-006",
    "family_codes": [
      "CG"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "Governance as a Security Control",
    "status": "documented_event",
    "jurisdictions": [],
    "asset_classes": [
      "Uploaded genotype kits and matching relationships"
    ],
    "threat_codes": [
      "Governance as a Security Control"
    ],
    "imported": false,
    "clusters": [
      "Genealogy governance"
    ],
    "related_case_ids": [
      "GS-CASE-002",
      "GS-CASE-012",
      "GS-CASE-030",
      "GS-CASE-031"
    ],
    "related_comparisons": [
      {
        "case_number": "002",
        "text": "Compare Golden State Killer for kinship leakage. This case focuses on governance as a security control."
      },
      {
        "case_number": "012",
        "text": "Compare GEDmatch 2020 Permissions Breach for consent-state integrity. This case focuses on governance as a security control."
      },
      {
        "case_number": "030",
        "text": "Compare FamilyTreeDNA And FBI Matching for material policy change. This case focuses on governance as a security control."
      },
      {
        "case_number": "031",
        "text": "Compare Buckskin Girl / Marcia King for restorative identification. This case focuses on governance as a security control."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "A setting is a rule about a particular action",
        "text": "Privacy settings are easiest to understand when connected to a concrete comparison. Which kit may be compared with which other kit, for what purpose, under which version of the service's rules? A broad label such as “private” can obscure those questions if the reader assumes it covers every possible action.  The case therefore treats platform documentation as a source that must be dated and read in context. A statement about an earlier policy cannot automatically establish how a current setting works. Likewise, an explanation of one kind of law-enforcement comparison should not be extended to every investigative or identification use."
      },
      {
        "heading": "Participation and family exposure are different",
        "text": "A user's decision can change how their uploaded information is used within a service. It cannot make that person the decision-maker for every genetic relative. The proposed exposure radius reflects this relational feature, while the consent discussion asks whose choices are actually represented.  This does not mean settings are ineffective. They can establish meaningful boundaries on permitted comparisons. The limitation is that a service-level control should be described according to what it governs, without promising that it retracts information already obtained elsewhere or resolves every question about relatives."
      },
      {
        "heading": "What to record in a review",
        "text": "For a hypothetical audit, preserve the policy date, the relevant setting, the described comparison purpose, and the account or kit to which the setting applies. Then distinguish the documented rule from evidence about its implementation. If the review examines deletion, state which stored items and future actions the documentation addresses.  A clear record is more useful than a general verdict that a database is either safe or unsafe. It allows readers to see which decision changes exposure and what the available evidence leaves unanswered."
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Probabilistic prediction of selected visible traits; not direct identification",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Authorization depends on collection and investigative context",
    "law_enforcement": true,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": "Direct / isolated",
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": "moderate",
    "ger_notes": null,
    "gpr_label": "Persistent genetic profile",
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": "low",
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-007",
    "case_number": "007",
    "slug": "/cases/007-forensic-dna-phenotyping/",
    "title": "Forensic DNA Phenotyping: When DNA Becomes a Description",
    "short_title": "Forensic DNA phenotyping",
    "summary": "Genetic data can support probabilistic inference about externally visible traits and ancestry-related characteristics even when no direct identity match exists.",
    "direct_answer": "Genetic data can support probabilistic inference about externally visible traits and ancestry-related characteristics even when no direct identity match exists.",
    "event_label": "Research capability",
    "sector": "Forensic science",
    "event_type": "research_capability",
    "genetic_asset_type": "Genetic markers used for trait inference",
    "ger_level": 0,
    "gpr_level": 3,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "nij"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Genetic Inference",
    "processing": "Probabilistic prediction of selected visible traits; not direct identification",
    "direct_parties": "The unknown specimen source",
    "indirect_parties": "No indirect party count established for the bounded example",
    "consent_status": "Authorization depends on collection and investigative context",
    "mitigations": "Report uncertainty and population limitations; validate each trait model; avoid presenting composites as photographs or identifications.",
    "limitations": "This does not establish that DNA phenotyping can reconstruct a person's exact face with photographic accuracy.",
    "ger_basis": "Analysis: No indirect party count established for the bounded example. The rating describes possible scope, not harm or a count of affected people.",
    "gpr_basis": "The described profile can remain useful for identification or comparison; retention and future linkability remain uncertain.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-007",
    "family_codes": [
      "RI"
    ],
    "family": "Re-identification and inference",
    "primary_query": "Genetic Inference",
    "status": "research_capability",
    "jurisdictions": [],
    "asset_classes": [
      "Genetic markers used for trait inference"
    ],
    "threat_codes": [
      "Genetic Inference"
    ],
    "imported": false,
    "clusters": [
      "Collection and inference"
    ],
    "related_case_ids": [
      "GS-CASE-001",
      "GS-CASE-011"
    ],
    "related_comparisons": [
      {
        "case_number": "001",
        "text": "Compare Stranger Visions for unintentional genetic disclosure. This case focuses on genetic inference."
      },
      {
        "case_number": "011",
        "text": "Compare 1Health / Vitagene FTC Enforcement for deletion integrity and cloud exposure. This case focuses on genetic inference."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "Read a prediction as a prediction",
        "text": "A trait estimate and an identification claim serve different purposes. A prediction may describe a characteristic that many people share. Even a well-supported estimate does not, on its own, name the source of a sample. Adding several estimates into a composite image does not remove the uncertainty attached to each component.  The visual form matters. People can read a face as a specific person even when the underlying analysis supports only a limited set of probabilistic traits. A responsible presentation should explain which features follow from the analysis and which reflect illustration, modeling choices, or assumptions."
      },
      {
        "heading": "Ask what was actually evaluated",
        "text": "When reading a claim about accuracy, look for the trait being predicted, the data used to evaluate it, and the conditions under which the result was measured. A strong result for one trait does not establish equivalent performance for another. Nor should a general performance statement be taken as certainty about an individual specimen.  These are questions for evaluating an inference, not an assertion that the cited research supplies one answer for every population or method. Where the case does not provide the relevant evaluation details, it should not manufacture a percentage to make the account appear complete."
      },
      {
        "heading": "Keep the scope of the example small",
        "text": "The GER-0 classification describes the bounded example of trait inference about one unknown source. It does not claim that phenotyping can never support broader inferences. If an assessment includes family matching, population characterization, or linked identity records, those additional activities change the scope and need their own rationale.  The practical lesson is to describe the output before scoring it. “A trait prediction from selected markers” tells a reader more than “a face from DNA,” and leaves room to discuss both the usefulness and the limits of the method."
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Remote access and account compromise may provide paths toward data stores",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Unauthorized access is assumed in the modeled attack",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Potential exposure in the model; no observed compromise claimed.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "Ransomware models loss of access; no real outage assigned.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-008",
    "case_number": "008",
    "slug": "/cases/008-genomic-sequencing-ransomware-threat-model/",
    "title": "Sequencer to Datastore: NIST's Ransomware Model for a Genomic Laboratory",
    "short_title": "Genomic laboratory ransomware",
    "summary": "The security boundary includes sequencer remote access, credentials, host software, cluster filesystems, data stores, transfer paths, and administrative interfaces.",
    "direct_answer": "The security boundary includes sequencer remote access, credentials, host software, cluster filesystems, data stores, transfer paths, and administrative interfaces.",
    "event_label": "Threat-model scenario",
    "sector": "Genomic infrastructure",
    "event_type": "threat_model",
    "genetic_asset_type": "Hypothetical sequencing workflow and laboratory datastore",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "threat_model",
    "primary_source_count": 1,
    "sources": [
      "nist"
    ],
    "parent_hub": "/infrastructure/",
    "security_principle": "Genomic Infrastructure Compromise",
    "processing": "Remote access and account compromise may provide paths toward data stores",
    "direct_parties": "No confirmed victims assigned",
    "indirect_parties": "Depends on the hypothetical repository scope",
    "consent_status": "Unauthorized access is assumed in the modeled attack",
    "mitigations": "Segment instrument networks; protect remote access; test offline restoration; pin workflow versions and verify artifact integrity.",
    "limitations": "This is a documented threat-model scenario, not evidence that this exact attack occurred in a real laboratory.",
    "ger_basis": "Not assigned: no bounded observed exposure with sufficient evidence. Scenario scope must be specified before scoring.",
    "gpr_basis": "Not assigned: the information exposed or its retention is insufficiently specified. Biological-resource loss is different from credential persistence.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-008",
    "family_codes": [
      "CY"
    ],
    "family": "Genomic cybersecurity and infrastructure",
    "primary_query": "Genomic Infrastructure Compromise",
    "status": "threat_model",
    "jurisdictions": [],
    "asset_classes": [
      "Hypothetical sequencing workflow and laboratory datastore"
    ],
    "threat_codes": [
      "Genomic Infrastructure Compromise"
    ],
    "imported": false,
    "clusters": [
      "Instrument security"
    ],
    "related_case_ids": [
      "GS-CASE-045",
      "GS-CASE-046",
      "GS-CASE-047"
    ],
    "related_comparisons": [
      {
        "case_number": "045",
        "text": "Compare Illumina Local Run Manager Vulnerabilities for instrument software is part of the genome. This case focuses on genomic infrastructure compromise."
      },
      {
        "case_number": "046",
        "text": "Compare Illumina Universal Copy Service Vulnerability for shared-component blast radius. This case focuses on genomic infrastructure compromise."
      },
      {
        "case_number": "047",
        "text": "Compare DNA-Encoded Malware Proof Of Concept for cross-domain input validation. This case focuses on genomic infrastructure compromise."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "Use the scenario to ask better questions",
        "text": "The value of a threat model lies in the questions it makes concrete. Which remote paths reach an instrument? Which identities can move data into shared storage? What would prevent a compromised account from affecting a larger workflow? These questions can be useful without implying that the scenario records an actual attack.  For a hypothetical workshop, draw the instrument, analysis environment, and data store as separate parts. Mark the access between them and identify who is responsible for each connection. Then examine where an unwanted action could continue beyond its initial entry point. The drawing should describe the real workflow under review, not an assumed generic laboratory."
      },
      {
        "heading": "Restore the workflow, not just the files",
        "text": "An exercise can consider what happens after access is restored. Are the inputs, reference versions, and outputs still trustworthy? Can staff distinguish work completed before the disruption from work that needs review? Could a restored report be associated with the wrong stage of analysis?  These are proposed recovery questions, not reported consequences of the NIST scenario. They help keep integrity and provenance in view alongside availability. A team may need separate evidence that data is readable, that it is the expected version, and that it supports the intended result."
      },
      {
        "heading": "Why the scores remain blank",
        "text": "There is no specified population of confirmed victims or observed set of exfiltrated files in this record. Assigning a numeric exposure radius or persistence level would require additional scenario assumptions. Those assumptions could be useful in a workshop, but they should be written down explicitly.  Leaving the scores unassigned makes that boundary visible. It also prevents someone downloading the database from accidentally treating a modeled pathway as a measured breach. The record is evidence that a threat was analyzed, not evidence that the threat occurred."
      }
    ]
  },
  {
    "event_date_start": "2025-04-08",
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Regulation of certain transactions enabling covered access",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Transaction restrictions and coverage depend on the rule",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-009",
    "case_number": "009",
    "slug": "/cases/009-doj-bulk-genomic-data-national-security/",
    "title": "When Genomic Data Became a National-Security Data-Control Problem",
    "short_title": "DOJ bulk genomic data",
    "summary": "The U.S. Department of Justice Data Security Program took effect April 8, 2025. It restricts or prohibits certain categories of transactions that could provide countries of concern or covered persons access to U.S. government-related data or Americans' bulk genomic and other sensitive personal data.",
    "direct_answer": "Genomic security is no longer only a healthcare privacy issue. U.S. policy now treats certain access to Americans' bulk genomic and other sensitive personal data as a national-security concern.",
    "event_label": "2025-04-08",
    "sector": "Security policy",
    "event_type": "policy_development",
    "genetic_asset_type": "Bulk genomic and other covered sensitive data",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 1,
    "sources": [
      "doj"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Genomic Sovereignty / Strategic Data Security",
    "processing": "Regulation of certain transactions enabling covered access",
    "direct_parties": "No individual exposure event is asserted",
    "indirect_parties": "Potential population-level relevance; no event count assigned",
    "consent_status": "Transaction restrictions and coverage depend on the rule",
    "mitigations": "Map covered data, transaction types, counterparties, jurisdictions, and applicable exceptions using the official rule and guidance.",
    "limitations": "A policy development is not itself a documented breach, and not every genomic transaction is prohibited.",
    "ger_basis": "Not assigned: no bounded observed exposure with sufficient evidence. Scenario scope must be specified before scoring.",
    "gpr_basis": "Not assigned: the information exposed or its retention is insufficiently specified. Biological-resource loss is different from credential persistence.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-009",
    "family_codes": [
      "SV"
    ],
    "family": "State surveillance and population security",
    "primary_query": "Genomic Sovereignty / Strategic Data Security",
    "status": "policy_development",
    "jurisdictions": [],
    "asset_classes": [
      "Bulk genomic and other covered sensitive data"
    ],
    "threat_codes": [
      "Genomic Sovereignty / Strategic Data Security"
    ],
    "imported": false,
    "clusters": [
      "Community and population governance"
    ],
    "related_case_ids": [
      "GS-CASE-018",
      "GS-CASE-019",
      "GS-CASE-029",
      "GS-CASE-065"
    ],
    "related_comparisons": [
      {
        "case_number": "018",
        "text": "Compare Kennewick Man / The Ancient One for ancestral genomic governance. This case focuses on genomic sovereignty / strategic data security."
      },
      {
        "case_number": "019",
        "text": "Compare Chaco Canyon Ancient DNA for community standing survives temporal distance. This case focuses on genomic sovereignty / strategic data security."
      },
      {
        "case_number": "029",
        "text": "Compare Kuwait's Universal DNA Law for population-scale collection limits. This case focuses on genomic sovereignty / strategic data security."
      },
      {
        "case_number": "065",
        "text": "Compare Mass DNA Collection In Xinjiang And Tibet for genetic surveillance of populations. This case focuses on genomic sovereignty / strategic data security."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "A policy event changes the questions an organization asks",
        "text": "The case concerns a security-policy development rather than an observed disclosure. Its relevance is the attention it directs toward data access, counterparties, and transactions. The official DOJ program materials provide the controlling detail; this case explains why genomic information belongs in that discussion.  The site's analysis is that a review limited to the individual account can miss the wider access arrangement. For a hypothetical data service, it may be necessary to understand which parties can obtain or process information and through which agreements. That exercise begins with an accurate inventory, not an assumption that every international relationship falls into the same category."
      },
      {
        "heading": "Keep the policy claim narrower than the headline",
        "text": "A headline about genomic data and national security can suggest a universal prohibition. The case should instead direct the reader to the defined activities, data categories, parties, and conditions in the official materials. A short summary is not enough to decide whether a particular arrangement is covered.  Similarly, the existence of a rule does not prove that a named organization has violated it. Any compliance allegation would require a separate factual record and analysis. This entry contains no such finding."
      },
      {
        "heading": "Why no incident score is assigned",
        "text": "Population-scale information can raise broad exposure concerns, but the record does not identify one bounded dataset that was disclosed. A GER or GPR score would therefore describe an invented example rather than the policy event itself. Keeping those fields unassigned is a deliberate editorial choice.  For readers comparing this entry with a breach, the useful contrast is between a framework intended to govern access and evidence that a specific access occurred. Both belong in a research library, but they answer different questions and should not be combined into a single incident count."
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": null,
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "Preservation, characterization, database management, and breeding support",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access and use are governed by repository arrangements",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.",
    "integrity_impact": "No demonstrated data alteration established by the cited material.",
    "availability_impact": "No outage or destruction established in this case.",
    "provenance_impact": "Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later analytical methods or linked datasets may extract additional information; magnitude unknown.",
    "expected_persistence": "Potentially long-lived; no fixed duration established.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.",
    "correction_status": "none_recorded",
    "id": "GS-010",
    "case_number": "010",
    "slug": "/cases/010-agricultural-genetic-resource-security/",
    "title": "Beyond Human DNA: Why Agricultural Genetic Resources Are Security Assets",
    "short_title": "Agricultural genetic resources",
    "summary": "Genetic security includes preservation, integrity, availability, and governance of crop, livestock, microbial, and other genetic resources on which food production, breeding, biodiversity, and resilience depend.",
    "direct_answer": "Genetic security includes preservation, integrity, availability, and governance of crop, livestock, microbial, and other genetic resources on which food production, breeding, biodiversity, and resilience depend.",
    "event_label": "Ongoing stewardship",
    "sector": "Agriculture",
    "event_type": "resource_stewardship",
    "genetic_asset_type": "Germplasm, accession records, and associated genomic databases",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "usda"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Genetic Resource Resilience",
    "processing": "Preservation, characterization, database management, and breeding support",
    "direct_parties": "No specific repository loss is asserted",
    "indirect_parties": "Breeding programs and resource networks depend on continuity",
    "consent_status": "Access and use are governed by repository arrangements",
    "mitigations": "Maintain redundant preservation, accession identity, documented custody, integrity checks, and recovery plans; test that records resolve to the correct material.",
    "limitations": "The significance of a resource does not establish that a compromise, loss, or manipulation has occurred.",
    "ger_basis": "Not assigned: no bounded observed exposure with sufficient evidence. Scenario scope must be specified before scoring.",
    "gpr_basis": "Not assigned: the information exposed or its retention is insufficiently specified. Biological-resource loss is different from credential persistence.",
    "gpi_basis": "Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.",
    "case_id": "GS-CASE-010",
    "family_codes": [
      "GR"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "Genetic Resource Resilience",
    "status": "resource_stewardship",
    "jurisdictions": [],
    "asset_classes": [
      "Germplasm, accession records, and associated genomic databases"
    ],
    "threat_codes": [
      "Genetic Resource Resilience"
    ],
    "imported": false,
    "clusters": [
      "Genetic-resource resilience"
    ],
    "related_case_ids": [
      "GS-CASE-055",
      "GS-CASE-056",
      "GS-CASE-057",
      "GS-CASE-058"
    ],
    "related_comparisons": [
      {
        "case_number": "055",
        "text": "Compare Svalbard Seed Vault Water Intrusion for environmental assumptions expire. This case focuses on genetic resource resilience."
      },
      {
        "case_number": "056",
        "text": "Compare ICARDA Aleppo And The First Svalbard Withdrawal for genetic-resource disaster recovery. This case focuses on genetic resource resilience."
      },
      {
        "case_number": "057",
        "text": "Compare The Vavilov Collection During The Siege Of Leningrad for human custodianship as a security control. This case focuses on genetic resource resilience."
      },
      {
        "case_number": "058",
        "text": "Compare Pavlovsk Experiment Station Development Threat for land-use governance can destroy genetic assets. This case focuses on genetic resource resilience."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "Preserve the relationship between material and knowledge",
        "text": "The security value of a collection depends partly on knowing what its material is and how it can be used. A specimen without a reliable accession record may still exist physically while becoming difficult to interpret. A catalog without accessible material creates a different kind of limitation.  This is why the case treats the collection and its associated information together. The USDA source establishes the relevance of genetic resources and supporting data to its program. The site's analysis asks how availability, identity, and continuity can be examined across that combined asset."
      },
      {
        "heading": "A hypothetical accession mix-up",
        "text": "Imagine two stored accessions whose labels have been exchanged. No information has necessarily been disclosed, and the storage service may remain fully available. The immediate issue is whether users can rely on the identity of the material they receive. A backup of the same mistaken catalog would not resolve that uncertainty.  A review would examine how the identities could be checked, which records preserve the handling history, and which downstream uses may need re-examination. This is an illustrative scenario, not an allegation about a USDA collection or any other repository."
      },
      {
        "heading": "Resilience needs a defined purpose",
        "text": "Ask what must remain possible after a disruption: locating an accession, recovering its history, obtaining usable material, or continuing a preservation program. Different answers may require different arrangements. Redundancy is useful only when the copies or alternatives preserve the function that matters.  The case does not assign a high exposure score merely because a collection is important. A strategic resource can warrant careful protection without a documented compromise. Describing the asset and the failure that would matter is the starting point; a dramatic score is not a substitute for either."
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "consumer test",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "law_enforcement": false,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns dna and health records in cloud storage. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Deletion Integrity and Cloud Exposure identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows dna and health records in cloud storage through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-011",
    "case_number": "011",
    "slug": "/cases/011-1health-vitagene-genetic-data-security/",
    "title": "Vitagene and the FTC: Genetic Data Left in the Cloud",
    "short_title": "1Health / Vitagene FTC Enforcement",
    "summary": "The FTC's 1Health/Vitagene matter shows that genetic privacy promises fail when cloud permissions, deletion workflows, vendor access, and public representations do not match operational reality. Genetic security therefore includes not only preventing theft, but proving that promised deletion and access restrictions actually occur.",
    "direct_answer": "The FTC's 1Health/Vitagene matter shows that genetic privacy promises fail when cloud permissions, deletion workflows, vendor access, and public representations do not match operational reality. Genetic security therefore includes not only preventing theft, but proving that promised deletion and access restrictions actually occur.",
    "event_label": "2023",
    "sector": "Consumer genetics and commercial data",
    "event_type": "enforcement_action",
    "genetic_asset_type": "DNA and health records in cloud storage",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 2,
    "sources": [
      "case011source1",
      "case011source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Deletion Integrity and Cloud Exposure",
    "processing": "consumer test → cloud storage/configuration → excessive or public accessibility → persistent data → representations about security/deletion → regulatory action",
    "direct_parties": "Consumers whose testing information was held by 1Health",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "mitigations": "Private-by-default object storage, least privilege, continuous configuration monitoring, immutable access logs, tested deletion attestations, backup-expiration rules, vendor inventories, truthful privacy notices, and post-deletion sample destruction evidence.",
    "limitations": "The matter does not establish that every customer genome was public or that all affected records contained the same fields.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-011",
    "family_codes": [
      "CG"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "Vitagene genetic data privacy case",
    "status": "enforcement_action",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "DNA and health records in cloud storage"
    ],
    "threat_codes": [
      "Deletion Integrity and Cloud Exposure"
    ],
    "imported": true,
    "threat_chain": [
      "consumer test",
      "cloud storage/configuration",
      "excessive or public accessibility",
      "persistent data",
      "representations about security/deletion",
      "regulatory action"
    ],
    "controls": [
      "private-by-default object storage",
      "least privilege",
      "continuous configuration monitoring",
      "immutable access logs",
      "tested deletion attestations",
      "backup-expiration rules",
      "vendor inventories",
      "truthful privacy notices",
      "post-deletion sample destruction evidence"
    ],
    "does_not_prove": [
      "The matter does not establish that every customer genome was public or that all affected records contained the same fields."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The FTC matter centers on the distance between a privacy promise and the systems expected to carry it out. Its allegations concerned DNA and health information, cloud access, and representations about deletion. The enforcement outcome must be understood as an order resolving charges, rather than a trial establishing every alleged fact.",
          "Deletion is a workflow, not just a button. An assessment needs to follow the consumer's request through the account, laboratory, storage provider, and retained copies. The useful question is whether the organization can demonstrate the result it promised. Access restrictions and deletion records belong in the same lifecycle review."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity moderate because deletion-state accuracy is at issue; availability low; provenance moderate; consent high; persistence high; relational exposure depends on data fields.",
    "proposed_score_notes": "Suggested GER: GER-1/2. Suggested GPR: GPR-4. Suggested GPI: GPI-1/2 where deletion and custody cannot be independently demonstrated.",
    "clusters": [
      "Collection and inference"
    ],
    "related_case_ids": [
      "GS-CASE-001",
      "GS-CASE-007"
    ],
    "related_comparisons": [
      {
        "case_number": "001",
        "text": "Compare Stranger Visions for unintentional genetic disclosure. This case focuses on deletion integrity and cloud exposure."
      },
      {
        "case_number": "007",
        "text": "Compare Forensic DNA phenotyping for genetic inference. This case focuses on deletion integrity and cloud exposure."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The FTC matter centers on the distance between a privacy promise and the systems expected to carry it out. Its allegations concerned DNA and health information, cloud access, and representations about deletion. The enforcement outcome must be understood as an order resolving charges, rather than a trial establishing every alleged fact.",
          "Deletion is a workflow, not just a button. An assessment needs to follow the consumer's request through the account, laboratory, storage provider, and retained copies. The useful question is whether the organization can demonstrate the result it promised. Access restrictions and deletion records belong in the same lifecycle review."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "platform compromise",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "law_enforcement": true,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns genotype kits and law-enforcement matching permissions. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Consent-State Integrity identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows genotype kits and law-enforcement matching permissions through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-012",
    "case_number": "012",
    "slug": "/cases/012-gedmatch-2020-permissions-breach/",
    "title": "GEDmatch 2020: When a Breach Rewrote Consent",
    "short_title": "GEDmatch 2020 Permissions Breach",
    "summary": "The 2020 GEDmatch incident demonstrates a rare genetic-security failure: an attack did not merely expose accounts; it temporarily changed effective permissions so profiles that had not opted into law-enforcement matching became searchable for that purpose.",
    "direct_answer": "The 2020 GEDmatch incident demonstrates a rare genetic-security failure: an attack did not merely expose accounts; it temporarily changed effective permissions so profiles that had not opted into law-enforcement matching became searchable for that purpose.",
    "event_label": "2020",
    "sector": "Consumer genetics and commercial data",
    "event_type": "confirmed_incident",
    "genetic_asset_type": "Genotype kits and law-enforcement matching permissions",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 2,
    "sources": [
      "case012source1",
      "case012source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Consent-State Integrity",
    "processing": "platform compromise → authorization-state alteration → opted-out profiles become matchable → downstream searches may occur → trust and audit problem",
    "direct_parties": "GEDmatch users whose matching permissions changed",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "mitigations": "Tamper-evident consent logs, immutable authorization history, deny-by-default matching, continuous policy-drift detection, privileged-access isolation, incident-specific query auditing, rapid user notice, and post-incident proof of restored settings.",
    "limitations": "Temporary searchability does not establish that every profile was searched, exported, or used in an investigation.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-012",
    "family_codes": [
      "CG",
      "LE"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "GEDmatch 2020 breach law enforcement opt out",
    "status": "confirmed_incident",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Genotype kits and law-enforcement matching permissions"
    ],
    "threat_codes": [
      "Consent-State Integrity"
    ],
    "imported": true,
    "threat_chain": [
      "platform compromise",
      "authorization-state alteration",
      "opted-out profiles become matchable",
      "downstream searches may occur",
      "trust and audit problem"
    ],
    "controls": [
      "tamper-evident consent logs",
      "immutable authorization history",
      "deny-by-default matching",
      "continuous policy-drift detection",
      "privileged-access isolation",
      "incident-specific query auditing",
      "rapid user notice",
      "post-incident proof of restored settings"
    ],
    "does_not_prove": [
      "Temporary searchability does not establish that every profile was searched, exported, or used in an investigation."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The distinctive failure was a change in the operation of privacy choices. Profiles that were not intended to participate in law-enforcement matching became temporarily searchable for that purpose. That creates an integrity question alongside the confidentiality question: did the system enforce the user's recorded choice?",
          "Temporary searchability is not proof that every profile was viewed or used. A useful incident account separates the changed settings, the period of exposure, and any evidence of actual queries. Restoring a displayed preference is only part of recovery; the authorization paths that apply it also need to be checked."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity critical; availability moderate; provenance moderate; consent critical; persistence high; relational exposure high.",
    "proposed_score_notes": "Suggested GER: GER-3. Suggested GPR: GPR-4. Suggested GPI: GPI-2 because system state and access history require reconstruction.",
    "clusters": [
      "Genealogy governance"
    ],
    "related_case_ids": [
      "GS-CASE-002",
      "GS-CASE-006",
      "GS-CASE-030",
      "GS-CASE-031"
    ],
    "related_comparisons": [
      {
        "case_number": "002",
        "text": "Compare Golden State Killer for kinship leakage. This case focuses on consent-state integrity."
      },
      {
        "case_number": "006",
        "text": "Compare GEDmatch for governance as a security control. This case focuses on consent-state integrity."
      },
      {
        "case_number": "030",
        "text": "Compare FamilyTreeDNA And FBI Matching for material policy change. This case focuses on consent-state integrity."
      },
      {
        "case_number": "031",
        "text": "Compare Buckskin Girl / Marcia King for restorative identification. This case focuses on consent-state integrity."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The distinctive failure was a change in the operation of privacy choices. Profiles that were not intended to participate in law-enforcement matching became temporarily searchable for that purpose. That creates an integrity question alongside the confidentiality question: did the system enforce the user's recorded choice?",
          "Temporary searchability is not proof that every profile was viewed or used. A useful incident account separates the changed settings, the period of exposure, and any evidence of actual queries. Restoring a displayed preference is only part of recovery; the authorization paths that apply it also need to be checked."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "account database exposure",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "law_enforcement": false,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns email addresses and hashed passwords. The documented scope does not establish disclosure of raw genomic data.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Exposure Classification Accuracy identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows email addresses and hashed passwords through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-013",
    "case_number": "013",
    "slug": "/cases/013-myheritage-breach-genetic-data-negative-control/",
    "title": "MyHeritage 2018: A Breach at a DNA Company Is Not Automatically a DNA Breach",
    "short_title": "MyHeritage 2018 Breach: A Negative Control",
    "summary": "MyHeritage reported that a file containing email addresses and hashed passwords for about 92.3 million accounts was found outside the company, while its DNA and family-tree systems were stored separately and it had no evidence at the time that genetic data had been compromised. The lesson is disciplined breach classification.",
    "direct_answer": "MyHeritage reported that a file containing email addresses and hashed passwords for about 92.3 million accounts was found outside the company, while its DNA and family-tree systems were stored separately and it had no evidence at the time that genetic data had been compromised. The lesson is disciplined breach classification.",
    "event_label": "2018",
    "sector": "Consumer genetics and commercial data",
    "event_type": "confirmed_incident",
    "genetic_asset_type": "Email addresses and hashed passwords",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 1,
    "sources": [
      "case013source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Exposure Classification Accuracy",
    "processing": "account database exposure → emails/password hashes → credential cracking or reuse risk → possible future account compromise; no confirmed genetic-data exposure in the original disclosure",
    "direct_parties": "Account holders described in the MyHeritage notice",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "mitigations": "Password hashing resistant to offline attack, MFA, credential-stuffing defenses, network and data-store separation, breach scoping by data class, evidence-preserving investigation, and precise public notices.",
    "limitations": "It does not prove that DNA data was stolen. It also does not prove that separation alone makes a genetic platform secure.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-013",
    "family_codes": [
      "CG"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "was DNA exposed in the MyHeritage breach",
    "status": "confirmed_incident",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Email addresses and hashed passwords"
    ],
    "threat_codes": [
      "Exposure Classification Accuracy"
    ],
    "imported": true,
    "threat_chain": [
      "account database exposure",
      "emails/password hashes",
      "credential cracking or reuse risk",
      "possible future account compromise; no confirmed genetic-data exposure in the original disclosure"
    ],
    "controls": [
      "password hashing resistant to offline attack",
      "MFA",
      "credential-stuffing defenses",
      "network and data-store separation",
      "breach scoping by data class",
      "evidence-preserving investigation",
      "precise public notices"
    ],
    "does_not_prove": [
      "It does not prove that DNA data was stolen. It also does not prove that separation alone makes a genetic platform secure."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "MyHeritage's account of the incident identified email addresses and password hashes while distinguishing its separately stored DNA and family-tree systems. That distinction makes this case a useful counterexample to headlines that treat every breach at a genetics business as a genomic disclosure.",
          "Authentication information can still matter. Compromised credentials may create a path toward other systems, but a possible later account takeover is different from evidence that it happened. The event should be described using the affected data classes in the disclosure, with any further exposure treated as a separate question."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality moderate; integrity low; availability low; consent indirect; persistence of credentials is remediable; genetic persistence not triggered without genetic data.",
    "proposed_score_notes": "Suggested GER: GER-0 for the documented incident; note hypothetical GER expansion only as a separate risk. Suggested GPR: GPR-0/1. GPI: not central.",
    "clusters": [
      "Breach classification"
    ],
    "related_case_ids": [
      "GS-CASE-003",
      "GS-CASE-048",
      "GS-CASE-049",
      "GS-CASE-050"
    ],
    "related_comparisons": [
      {
        "case_number": "003",
        "text": "Compare 23andMe 2023 for genetic graph amplification. This case focuses on exposure classification accuracy."
      },
      {
        "case_number": "048",
        "text": "Compare Ambry Genetics Email-Account Breach for unstructured communications are genetic data stores. This case focuses on exposure classification accuracy."
      },
      {
        "case_number": "049",
        "text": "Compare DNA Diagnostics Center 2021 Breach for legacy-system discovery failure. This case focuses on exposure classification accuracy."
      },
      {
        "case_number": "050",
        "text": "Compare Veritas Genetics Portal Incident for interface exposure must be scoped by data class. This case focuses on exposure classification accuracy."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "MyHeritage's account of the incident identified email addresses and password hashes while distinguishing its separately stored DNA and family-tree systems. That distinction makes this case a useful counterexample to headlines that treat every breach at a genetics business as a genomic disclosure.",
          "Authentication information can still matter. Compromised credentials may create a path toward other systems, but a possible later account takeover is different from evidence that it happened. The event should be described using the affected data classes in the disclosure, with any further exposure treated as a separate question."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / California",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "clinical specimen",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns excised tissue and the mo cell line. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Biospecimen Control Is Not One Right identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows excised tissue and the mo cell line through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-014",
    "case_number": "014",
    "slug": "/cases/014-moore-regents-cell-line-ownership/",
    "title": "Moore v. Regents: Who Controls a Commercial Cell Line?",
    "short_title": "Moore v. Regents Of The University Of California",
    "summary": "Moore v. Regents separated several questions that are often collapsed into one: ownership of removed tissue, a physician's disclosure duties, consent to research, and commercial interests in a resulting cell line. Genetic security must model those rights separately.",
    "direct_answer": "Moore v. Regents separated several questions that are often collapsed into one: ownership of removed tissue, a physician's disclosure duties, consent to research, and commercial interests in a resulting cell line. Genetic security must model those rights separately.",
    "event_label": "1990",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "court_case",
    "genetic_asset_type": "Excised tissue and the Mo cell line",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case014source1",
      "case014source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Biospecimen Control Is Not One Right",
    "processing": "clinical specimen → retained research material → transformed cell line → patent/commercial value → undisclosed interests → litigation",
    "direct_parties": "John Moore and the treating/research institutions",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Specific consent, disclosure of investigator financial interests, material-transfer agreements, specimen ledgers, use-purpose restrictions, commercialization clauses, participant communications, and governance for derived lines and sequence data.",
    "limitations": "It does not create a universal rule for all biospecimens, jurisdictions, contracts, or modern genetic privacy statutes.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-014",
    "family_codes": [
      "CO"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Moore v Regents cell line ownership genetic material",
    "status": "court_case",
    "jurisdictions": [
      "United States",
      "California"
    ],
    "asset_classes": [
      "Excised tissue and the Mo cell line"
    ],
    "threat_codes": [
      "Biospecimen Control Is Not One Right"
    ],
    "imported": true,
    "threat_chain": [
      "clinical specimen",
      "retained research material",
      "transformed cell line",
      "patent/commercial value",
      "undisclosed interests",
      "litigation"
    ],
    "controls": [
      "specific consent",
      "disclosure of investigator financial interests",
      "material-transfer agreements",
      "specimen ledgers",
      "use-purpose restrictions",
      "commercialization clauses",
      "participant communications",
      "governance for derived lines and sequence data"
    ],
    "does_not_prove": [
      "It does not create a universal rule for all biospecimens, jurisdictions, contracts, or modern genetic privacy statutes."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "John Moore's treatment, retained biological material, and the development of a commercial cell line brought several kinds of control into one dispute. The California Supreme Court rejected the conversion claim while allowing claims concerning disclosure and informed consent to proceed. The result was not a universal declaration about who owns all human DNA.",
          "The case is useful because custody, ownership, permission, and financial interests do different work. A laboratory can document how material moved through research without resolving whether a patient received the necessary information. A specimen ledger and a consent process should therefore be connected, but neither can substitute for the other."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality secondary; integrity/provenance high; consent critical; persistence critical because living cell lines propagate; commercial control high.",
    "proposed_score_notes": "Suggested GER: GER-1/2. Suggested GPR: GPR-5 for a durable cell line and sequence-derived information. Suggested GPI: GPI-3 if custody and transformation are documented, while consent can still fail.",
    "clusters": [
      "Consent and biospecimens"
    ],
    "related_case_ids": [
      "GS-CASE-004",
      "GS-CASE-005",
      "GS-CASE-015",
      "GS-CASE-016"
    ],
    "related_comparisons": [
      {
        "case_number": "004",
        "text": "Compare Havasupai for purpose drift / secondary-use consent failure. This case focuses on biospecimen control is not one right."
      },
      {
        "case_number": "005",
        "text": "Compare Henrietta Lacks / HeLa for familial genomic consent. This case focuses on biospecimen control is not one right."
      },
      {
        "case_number": "015",
        "text": "Compare Washington University v. Catalona for custody, ownership, and withdrawal are distinct. This case focuses on biospecimen control is not one right."
      },
      {
        "case_number": "016",
        "text": "Compare Greenberg v. Miami Children's Hospital for participant contribution and commercialization drift. This case focuses on biospecimen control is not one right."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "John Moore's treatment, retained biological material, and the development of a commercial cell line brought several kinds of control into one dispute. The California Supreme Court rejected the conversion claim while allowing claims concerning disclosure and informed consent to proceed. The result was not a universal declaration about who owns all human DNA.",
          "The case is useful because custody, ownership, permission, and financial interests do different work. A laboratory can document how material moved through research without resolving whether a patient received the necessary information. A specimen ledger and a consent process should therefore be connected, but neither can substitute for the other."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Missouri",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "participant donation",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns donated tissue repository and associated records. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Custody, Ownership, and Withdrawal Are Distinct identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows donated tissue repository and associated records through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-015",
    "case_number": "015",
    "slug": "/cases/015-catalona-biobank-sample-custody/",
    "title": "Catalona: When Donors, Researchers, and Institutions Claimed the Same Samples",
    "short_title": "Washington University v. Catalona",
    "summary": "The Catalona litigation shows that donated research specimens can sit inside overlapping relationships among participants, investigators, and institutions. A donor's wish to redirect a specimen does not necessarily determine legal ownership or repository control.",
    "direct_answer": "The Catalona litigation shows that donated research specimens can sit inside overlapping relationships among participants, investigators, and institutions. A donor's wish to redirect a specimen does not necessarily determine legal ownership or repository control.",
    "event_label": "2007",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "court_case",
    "genetic_asset_type": "Donated tissue repository and associated records",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 1,
    "sources": [
      "case015source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Custody, Ownership, and Withdrawal Are Distinct",
    "processing": "participant donation → institutional repository → investigator departure → competing transfer instructions → litigation over control",
    "direct_parties": "Research donors, investigator, and university",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Plain-language repository ownership terms, withdrawal consequences, transfer rules, investigator-departure plans, chain-of-custody, governance committees, and separate treatment of physical samples versus copied data.",
    "limitations": "The outcome does not establish that every institution owns every donated specimen. Consent forms, policy, applicable law, and the case record matter.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-015",
    "family_codes": [
      "CO"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Washington University Catalona tissue repository ownership",
    "status": "court_case",
    "jurisdictions": [
      "United States",
      "Missouri"
    ],
    "asset_classes": [
      "Donated tissue repository and associated records"
    ],
    "threat_codes": [
      "Custody, Ownership, and Withdrawal Are Distinct"
    ],
    "imported": true,
    "threat_chain": [
      "participant donation",
      "institutional repository",
      "investigator departure",
      "competing transfer instructions",
      "litigation over control"
    ],
    "controls": [
      "plain-language repository ownership terms",
      "withdrawal consequences",
      "transfer rules",
      "investigator-departure plans",
      "chain-of-custody",
      "governance committees",
      "separate treatment of physical samples versus copied data"
    ],
    "does_not_prove": [
      "The outcome does not establish that every institution owns every donated specimen. Consent forms, policy, applicable law, and the case record matter."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Catalona dispute concerned a research repository and efforts to move specimens when an investigator changed institutions. The court's treatment of the donations and institutional ownership depended on the documents and circumstances before it. Participants' wishes, the investigator's research plans, and the university's responsibilities did not automatically lead to the same transfer decision.",
          "A repository needs rules for changes in personnel as well as ordinary research use. Clear terms should explain what withdrawal does, who may authorize a transfer, and what happens to information already derived from a sample. Those distinctions help keep scientific continuity from becoming an argument for undefined control."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality moderate; integrity/provenance high; availability high for ongoing research; consent and withdrawal high; persistence high.",
    "proposed_score_notes": "Suggested GER: GER-2/3 due to a large repository. Suggested GPR: GPR-4/5 depending on material and derived data. Suggested GPI: GPI-4 where repository custody is well documented.",
    "clusters": [
      "Consent and biospecimens"
    ],
    "related_case_ids": [
      "GS-CASE-004",
      "GS-CASE-005",
      "GS-CASE-014",
      "GS-CASE-016"
    ],
    "related_comparisons": [
      {
        "case_number": "004",
        "text": "Compare Havasupai for purpose drift / secondary-use consent failure. This case focuses on custody, ownership, and withdrawal are distinct."
      },
      {
        "case_number": "005",
        "text": "Compare Henrietta Lacks / HeLa for familial genomic consent. This case focuses on custody, ownership, and withdrawal are distinct."
      },
      {
        "case_number": "014",
        "text": "Compare Moore v. Regents Of The University Of California for biospecimen control is not one right. This case focuses on custody, ownership, and withdrawal are distinct."
      },
      {
        "case_number": "016",
        "text": "Compare Greenberg v. Miami Children's Hospital for participant contribution and commercialization drift. This case focuses on custody, ownership, and withdrawal are distinct."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Catalona dispute concerned a research repository and efforts to move specimens when an investigator changed institutions. The court's treatment of the donations and institutional ownership depended on the documents and circumstances before it. Participants' wishes, the investigator's research plans, and the university's responsibilities did not automatically lead to the same transfer decision.",
          "A repository needs rules for changes in personnel as well as ordinary research use. Clear terms should explain what withdrawal does, who may authorize a transfer, and what happens to information already derived from a sample. Those distinctions help keep scientific continuity from becoming an argument for undefined control."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Florida",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "community organizing and donations",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns canavan research samples, pedigrees, and discovery rights. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Participant Contribution and Commercialization Drift identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows canavan research samples, pedigrees, and discovery rights through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-016",
    "case_number": "016",
    "slug": "/cases/016-greenberg-canavan-gene-commercialization/",
    "title": "Greenberg: When Patient Families Helped Build a Genetic Discovery",
    "short_title": "Greenberg v. Miami Children's Hospital",
    "summary": "Greenberg v. Miami Children's Hospital illustrates how families can contribute samples, pedigrees, money, and organizing labor to research, yet later contest patenting, licensing, and access decisions surrounding the resulting genetic test.",
    "direct_answer": "Greenberg v. Miami Children's Hospital illustrates how families can contribute samples, pedigrees, money, and organizing labor to research, yet later contest patenting, licensing, and access decisions surrounding the resulting genetic test.",
    "event_label": "2003",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "court_case",
    "genetic_asset_type": "Canavan research samples, pedigrees, and discovery rights",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case016source1",
      "case016source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Participant Contribution and Commercialization Drift",
    "processing": "community organizing and donations → samples/pedigrees → gene discovery → patent/licensing → access and price conflict → litigation/settlement",
    "direct_parties": "Contributing families and research participants",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Community advisory structures, benefit-sharing terms, access and licensing commitments, participant-facing commercialization disclosures, contributor provenance, and post-discovery governance.",
    "limitations": "It does not mean research participants automatically own discoveries or patents. It does show why contribution, expectations, and downstream control must be made explicit.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-016",
    "family_codes": [
      "CO"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Greenberg Canavan disease gene patent research participants",
    "status": "court_case",
    "jurisdictions": [
      "United States",
      "Florida"
    ],
    "asset_classes": [
      "Canavan research samples, pedigrees, and discovery rights"
    ],
    "threat_codes": [
      "Participant Contribution and Commercialization Drift"
    ],
    "imported": true,
    "threat_chain": [
      "community organizing and donations",
      "samples/pedigrees",
      "gene discovery",
      "patent/licensing",
      "access and price conflict",
      "litigation/settlement"
    ],
    "controls": [
      "community advisory structures",
      "benefit-sharing terms",
      "access and licensing commitments",
      "participant-facing commercialization disclosures",
      "contributor provenance",
      "post-discovery governance"
    ],
    "does_not_prove": [
      "It does not mean research participants automatically own discoveries or patents. It does show why contribution, expectations, and downstream control must be made explicit."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Families affected by Canavan disease contributed more than specimens. Their organizing, pedigrees, and support helped make research possible. The later dispute over patenting and licensing exposed a gap between participation in discovery and authority over its commercial use.",
          "Legal claims and their disposition need to be distinguished from the contributors' expectations. Participation does not automatically establish ownership of a discovery, but that does not make expectations about access irrelevant. Research governance can address future licensing and benefit sharing before a result becomes valuable, when the parties still have an opportunity to clarify their commitments."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality moderate; availability and access high; consent high; provenance high; commercialization governance critical.",
    "proposed_score_notes": "Suggested GER: GER-4 because a rare-disease community was affected. Suggested GPR: GPR-4. Suggested GPI: GPI-3/4 for well-documented research lineage.",
    "clusters": [
      "Consent and biospecimens"
    ],
    "related_case_ids": [
      "GS-CASE-004",
      "GS-CASE-005",
      "GS-CASE-014",
      "GS-CASE-015"
    ],
    "related_comparisons": [
      {
        "case_number": "004",
        "text": "Compare Havasupai for purpose drift / secondary-use consent failure. This case focuses on participant contribution and commercialization drift."
      },
      {
        "case_number": "005",
        "text": "Compare Henrietta Lacks / HeLa for familial genomic consent. This case focuses on participant contribution and commercialization drift."
      },
      {
        "case_number": "014",
        "text": "Compare Moore v. Regents Of The University Of California for biospecimen control is not one right. This case focuses on participant contribution and commercialization drift."
      },
      {
        "case_number": "015",
        "text": "Compare Washington University v. Catalona for custody, ownership, and withdrawal are distinct. This case focuses on participant contribution and commercialization drift."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Families affected by Canavan disease contributed more than specimens. Their organizing, pedigrees, and support helped make research possible. The later dispute over patenting and licensing exposed a gap between participation in discovery and authority over its commercial use.",
          "Legal claims and their disposition need to be distinguished from the contributors' expectations. Participation does not automatically establish ownership of a discovery, but that does not make expectations about access irrelevant. Research governance can address future licensing and benefit sharing before a result becomes valuable, when the parties still have an opportunity to clarify their commitments."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Texas",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "mandatory newborn screening",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns residual newborn dried blood spots. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Collection Necessity Does Not Authorize Unlimited Reuse identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows residual newborn dried blood spots through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-017",
    "case_number": "017",
    "slug": "/cases/017-texas-newborn-blood-spots-consent/",
    "title": "Texas Newborn Blood Spots: Mandatory Screening, Secondary Storage",
    "short_title": "Texas Newborn Blood Spots",
    "summary": "Texas's newborn blood-spot controversy shows how a justified clinical collection can become a separate genetic-governance problem when residual samples are retained, distributed, or used beyond the screening purpose without sufficiently clear parental notice or consent.",
    "direct_answer": "Texas's newborn blood-spot controversy shows how a justified clinical collection can become a separate genetic-governance problem when residual samples are retained, distributed, or used beyond the screening purpose without sufficiently clear parental notice or consent.",
    "event_label": "2009–2011",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "historical_case",
    "genetic_asset_type": "Residual newborn dried blood spots",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case017source1",
      "case017source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Collection Necessity Does Not Authorize Unlimited Reuse",
    "processing": "mandatory newborn screening → residual specimen → long-term state retention → secondary research/distribution → litigation → destruction and policy change",
    "direct_parties": "Newborns whose residual specimens were retained and their parents",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Layered consent, short default retention, explicit research opt-in, destruction requests, access logs, external-transfer registers, de-identification risk review, and public retention schedules.",
    "limitations": "The controversy does not negate the benefit of newborn screening or establish that screening requires indefinite secondary use.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-017",
    "family_codes": [
      "CO"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Texas newborn blood spots lawsuit DNA retention",
    "status": "historical_case",
    "jurisdictions": [
      "United States",
      "Texas"
    ],
    "asset_classes": [
      "Residual newborn dried blood spots"
    ],
    "threat_codes": [
      "Collection Necessity Does Not Authorize Unlimited Reuse"
    ],
    "imported": true,
    "threat_chain": [
      "mandatory newborn screening",
      "residual specimen",
      "long-term state retention",
      "secondary research/distribution",
      "litigation",
      "destruction and policy change"
    ],
    "controls": [
      "layered consent",
      "short default retention",
      "explicit research opt-in",
      "destruction requests",
      "access logs",
      "external-transfer registers",
      "de-identification risk review",
      "public retention schedules"
    ],
    "does_not_prove": [
      "The controversy does not negate the benefit of newborn screening or establish that screening requires indefinite secondary use."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Newborn screening supplies a public-health reason to collect material. What happens to the residual blood afterward is a separate question. The Texas controversy brought retention, research, distribution, and destruction into view as decisions that should not be hidden inside the original screening purpose.",
          "The historical dispute should not be used as an undated description of today's program. It illustrates a durable governance problem: a necessary collection can produce a specimen capable of supporting additional uses. The appropriate record connects each later use to its authority and makes the consequences of a destruction request understandable."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity/provenance high; availability beneficial for QA/research; consent critical; persistence high; relational exposure extends to parents and siblings.",
    "proposed_score_notes": "Suggested GER: GER-1/2. Suggested GPR: GPR-5 for retained blood capable of future analysis. Suggested GPI: GPI-3/4 if specimen tracking exists.",
    "clusters": [
      "Consent and biospecimens"
    ],
    "related_case_ids": [
      "GS-CASE-004",
      "GS-CASE-005",
      "GS-CASE-014",
      "GS-CASE-015"
    ],
    "related_comparisons": [
      {
        "case_number": "004",
        "text": "Compare Havasupai for purpose drift / secondary-use consent failure. This case focuses on collection necessity does not authorize unlimited reuse."
      },
      {
        "case_number": "005",
        "text": "Compare Henrietta Lacks / HeLa for familial genomic consent. This case focuses on collection necessity does not authorize unlimited reuse."
      },
      {
        "case_number": "014",
        "text": "Compare Moore v. Regents Of The University Of California for biospecimen control is not one right. This case focuses on collection necessity does not authorize unlimited reuse."
      },
      {
        "case_number": "015",
        "text": "Compare Washington University v. Catalona for custody, ownership, and withdrawal are distinct. This case focuses on collection necessity does not authorize unlimited reuse."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Newborn screening supplies a public-health reason to collect material. What happens to the residual blood afterward is a separate question. The Texas controversy brought retention, research, distribution, and destruction into view as decisions that should not be hidden inside the original screening purpose.",
          "The historical dispute should not be used as an undated description of today's program. It illustrates a durable governance problem: a necessary collection can produce a specimen capable of supporting additional uses. The appropriate record connects each later use to its authority and makes the consequences of a destruction request understandable."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "human remains",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns ancient human remains and sequence data. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Ancestral Genomic Governance identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows ancient human remains and sequence data through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-018",
    "case_number": "018",
    "slug": "/cases/018-kennewick-man-ancient-dna-governance/",
    "title": "The Ancient One: When a Genome Changed a Repatriation Dispute",
    "short_title": "Kennewick Man / The Ancient One",
    "summary": "Genome analysis of the Ancient One, also known as Kennewick Man, contributed evidence of closer affinity to modern Native Americans than to other populations, illustrating how ancient DNA can alter legal, scientific, and cultural claims over human remains.",
    "direct_answer": "Genome analysis of the Ancient One, also known as Kennewick Man, contributed evidence of closer affinity to modern Native Americans than to other populations, illustrating how ancient DNA can alter legal, scientific, and cultural claims over human remains.",
    "event_label": "1996–2017",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "historical_case",
    "genetic_asset_type": "Ancient human remains and sequence data",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case018source1",
      "case018source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Ancestral Genomic Governance",
    "processing": "human remains → contested custody → destructive sampling → genome sequence → population-affinity inference → repatriation consequence",
    "direct_parties": "The Ancient One and communities asserting relationships to the remains",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Tribal consultation before sampling, minimal destructive analysis, CARE and FAIR reconciliation, culturally appropriate data controls, transparent uncertainty, and repatriation-aware research plans.",
    "limitations": "Genetic affinity is not identical to legal tribal membership, cultural identity, or a complete account of ancestry.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-018",
    "family_codes": [
      "CO",
      "RI"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Kennewick Man ancient DNA repatriation genome",
    "status": "historical_case",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Ancient human remains and sequence data"
    ],
    "threat_codes": [
      "Ancestral Genomic Governance"
    ],
    "imported": true,
    "threat_chain": [
      "human remains",
      "contested custody",
      "destructive sampling",
      "genome sequence",
      "population-affinity inference",
      "repatriation consequence"
    ],
    "controls": [
      "tribal consultation before sampling",
      "minimal destructive analysis",
      "CARE and FAIR reconciliation",
      "culturally appropriate data controls",
      "transparent uncertainty",
      "repatriation-aware research plans"
    ],
    "does_not_prove": [
      "Genetic affinity is not identical to legal tribal membership, cultural identity, or a complete account of ancestry."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Ancient One's remains became the subject of competing scientific and tribal claims. Genomic analysis added evidence to the debate about ancestry and affiliation, but a statistical relationship does not answer every question about cultural identity, legal status, or authority over remains.",
          "Ancient DNA brings living communities into a decision about a person who cannot consent. Destructive sampling, publication, and preservation should be considered together. The governance question begins before a sequence is produced: who participates in deciding whether the analysis should happen, and how will its findings and limits be communicated?"
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality unusual but real; integrity and provenance critical; consent impossible individually; community governance central; persistence maximal.",
    "proposed_score_notes": "Suggested GER: GER-4. Suggested GPR: GPR-5. Suggested GPI: GPI-4 if ancient-DNA authentication and custody are documented.",
    "clusters": [
      "Community and population governance"
    ],
    "related_case_ids": [
      "GS-CASE-009",
      "GS-CASE-019",
      "GS-CASE-029",
      "GS-CASE-065"
    ],
    "related_comparisons": [
      {
        "case_number": "009",
        "text": "Compare DOJ bulk genomic data for genomic sovereignty / strategic data security. This case focuses on ancestral genomic governance."
      },
      {
        "case_number": "019",
        "text": "Compare Chaco Canyon Ancient DNA for community standing survives temporal distance. This case focuses on ancestral genomic governance."
      },
      {
        "case_number": "029",
        "text": "Compare Kuwait's Universal DNA Law for population-scale collection limits. This case focuses on ancestral genomic governance."
      },
      {
        "case_number": "065",
        "text": "Compare Mass DNA Collection In Xinjiang And Tibet for genetic surveillance of populations. This case focuses on ancestral genomic governance."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Ancient One's remains became the subject of competing scientific and tribal claims. Genomic analysis added evidence to the debate about ancestry and affiliation, but a statistical relationship does not answer every question about cultural identity, legal status, or authority over remains.",
          "Ancient DNA brings living communities into a decision about a person who cannot consent. Destructive sampling, publication, and preservation should be considered together. The governance question begins before a sequence is produced: who participates in deciding whether the analysis should happen, and how will its findings and limits be communicated?"
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "museum-held remains",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns ancient remains and mitochondrial dna. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Community Standing Survives Temporal Distance identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows ancient remains and mitochondrial dna through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-019",
    "case_number": "019",
    "slug": "/cases/019-chaco-canyon-ancient-dna-ethics/",
    "title": "Chaco Canyon: Ancient DNA Without Living-Community Engagement",
    "short_title": "Chaco Canyon Ancient DNA",
    "summary": "The Chaco Canyon ancient-DNA controversy demonstrates that legal possession of archaeological remains and technical ability to sequence them do not settle the ethical question of engagement with living Indigenous communities connected to those remains and places.",
    "direct_answer": "The Chaco Canyon ancient-DNA controversy demonstrates that legal possession of archaeological remains and technical ability to sequence them do not settle the ethical question of engagement with living Indigenous communities connected to those remains and places.",
    "event_label": "2017",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "governance_dispute",
    "genetic_asset_type": "Ancient remains and mitochondrial DNA",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case019source1",
      "case019source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Community Standing Survives Temporal Distance",
    "processing": "museum-held remains → destructive sampling → mtDNA analysis → kinship inference → public historical narrative → community impact",
    "direct_parties": "Individuals whose remains were sampled and connected communities",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Pre-research consultation, community research agreements, limits on destructive sampling, interpretive co-authorship, culturally responsive repositories, and post-publication correction mechanisms.",
    "limitations": "A mitochondrial lineage does not by itself establish political rule or an entire social structure. Connected communities should not be assumed to hold one view.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-019",
    "family_codes": [
      "CO",
      "RI"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Chaco Canyon ancient DNA ethics case study",
    "status": "governance_dispute",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Ancient remains and mitochondrial DNA"
    ],
    "threat_codes": [
      "Community Standing Survives Temporal Distance"
    ],
    "imported": true,
    "threat_chain": [
      "museum-held remains",
      "destructive sampling",
      "mtDNA analysis",
      "kinship inference",
      "public historical narrative",
      "community impact"
    ],
    "controls": [
      "pre-research consultation",
      "community research agreements",
      "limits on destructive sampling",
      "interpretive co-authorship",
      "culturally responsive repositories",
      "post-publication correction mechanisms"
    ],
    "does_not_prove": [
      "A mitochondrial lineage does not by itself establish political rule or an entire social structure. Connected communities should not be assumed to hold one view."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Pueblo Bonito study used genetic evidence to investigate relationships among individuals buried at Chaco Canyon. The scientific interpretation and the criticism of community engagement are distinct parts of the case. Evidence about a shared lineage should not be treated as a complete account of political authority or social organization.",
          "The people studied lived long ago, but the way their remains and history are interpreted can matter to communities today. Legal possession of material does not by itself settle that relationship. Consultation and interpretive accountability belong in the research design, rather than being treated as an optional response after publication."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality low for named individuals but community privacy high; integrity/provenance high; consent/community engagement critical; relational exposure population-scale.",
    "proposed_score_notes": "Suggested GER: GER-4. Suggested GPR: GPR-5. Suggested GPI: GPI-3/4.",
    "clusters": [
      "Community and population governance"
    ],
    "related_case_ids": [
      "GS-CASE-009",
      "GS-CASE-018",
      "GS-CASE-029",
      "GS-CASE-065"
    ],
    "related_comparisons": [
      {
        "case_number": "009",
        "text": "Compare DOJ bulk genomic data for genomic sovereignty / strategic data security. This case focuses on community standing survives temporal distance."
      },
      {
        "case_number": "018",
        "text": "Compare Kennewick Man / The Ancient One for ancestral genomic governance. This case focuses on community standing survives temporal distance."
      },
      {
        "case_number": "029",
        "text": "Compare Kuwait's Universal DNA Law for population-scale collection limits. This case focuses on community standing survives temporal distance."
      },
      {
        "case_number": "065",
        "text": "Compare Mass DNA Collection In Xinjiang And Tibet for genetic surveillance of populations. This case focuses on community standing survives temporal distance."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Pueblo Bonito study used genetic evidence to investigate relationships among individuals buried at Chaco Canyon. The scientific interpretation and the criticism of community engagement are distinct parts of the case. Evidence about a shared lineage should not be treated as a complete account of political authority or social organization.",
          "The people studied lived long ago, but the way their remains and history are interpreted can matter to communities today. Legal possession of material does not by itself settle that relationship. Consultation and interpretive accountability belong in the research design, rather than being treated as an optional response after publication."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Canada",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "specific-purpose collection",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns blood specimens and derived research data. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Specimen Mobility and Community Control identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows blood specimens and derived research data through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-020",
    "case_number": "020",
    "slug": "/cases/020-nuu-chah-nulth-blood-sample-return/",
    "title": "Nuu-chah-nulth: When Blood Collected for One Study Traveled Further",
    "short_title": "Nuu-Chah-Nulth Blood-Sample Return",
    "summary": "The Nuu-chah-nulth case shows how samples collected for a specific health study can move between institutions and support additional research beyond the community's original understanding, making custody maps and community governance essential security controls.",
    "direct_answer": "The Nuu-chah-nulth case shows how samples collected for a specific health study can move between institutions and support additional research beyond the community's original understanding, making custody maps and community governance essential security controls.",
    "event_label": "1980s–2000s",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "historical_case",
    "genetic_asset_type": "Blood specimens and derived research data",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case020source1",
      "case020source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Specimen Mobility and Community Control",
    "processing": "specific-purpose collection → researcher custody → institutional movement → secondary analyses → loss of community visibility → return and destruction",
    "direct_parties": "Nuu-chah-nulth participants and communities",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Community-level agreements, specimen passports, use-specific approvals, no-transfer clauses, benefit sharing, Indigenous data sovereignty principles, withdrawal workflows, and verifiable destruction.",
    "limitations": "The account does not establish the authorization history of every secondary study. Its focus is unclear purpose, movement, and accountability.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-020",
    "family_codes": [
      "CO"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Nuu-chah-nulth blood samples genetic research return",
    "status": "historical_case",
    "jurisdictions": [
      "Canada"
    ],
    "asset_classes": [
      "Blood specimens and derived research data"
    ],
    "threat_codes": [
      "Specimen Mobility and Community Control"
    ],
    "imported": true,
    "threat_chain": [
      "specific-purpose collection",
      "researcher custody",
      "institutional movement",
      "secondary analyses",
      "loss of community visibility",
      "return and destruction"
    ],
    "controls": [
      "community-level agreements",
      "specimen passports",
      "use-specific approvals",
      "no-transfer clauses",
      "benefit sharing",
      "Indigenous data sovereignty principles",
      "withdrawal workflows",
      "verifiable destruction"
    ],
    "does_not_prove": [
      "The account does not establish the authorization history of every secondary study. Its focus is unclear purpose, movement, and accountability."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Nuu-chah-nulth case follows specimens beyond the study for which people understood they were contributing them. Movement between institutions can make it difficult for a community to see which material still exists, who controls it, and what research has been performed.",
          "The security lesson concerns that loss of visibility and control. A complete account should not assume that every subsequent use had the same authorization history. Transfer records, purpose restrictions, and return or destruction agreements need to follow the material so that the collection's original context does not disappear when an investigator moves."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity/provenance critical; consent critical; availability contested; persistence high; group exposure high.",
    "proposed_score_notes": "Suggested GER: GER-4. Suggested GPR: GPR-5. Suggested GPI: GPI-1/2 if a complete custody/use history cannot be reconstructed.",
    "clusters": [
      "Consent and biospecimens"
    ],
    "related_case_ids": [
      "GS-CASE-004",
      "GS-CASE-005",
      "GS-CASE-014",
      "GS-CASE-015"
    ],
    "related_comparisons": [
      {
        "case_number": "004",
        "text": "Compare Havasupai for purpose drift / secondary-use consent failure. This case focuses on specimen mobility and community control."
      },
      {
        "case_number": "005",
        "text": "Compare Henrietta Lacks / HeLa for familial genomic consent. This case focuses on specimen mobility and community control."
      },
      {
        "case_number": "014",
        "text": "Compare Moore v. Regents Of The University Of California for biospecimen control is not one right. This case focuses on specimen mobility and community control."
      },
      {
        "case_number": "015",
        "text": "Compare Washington University v. Catalona for custody, ownership, and withdrawal are distinct. This case focuses on specimen mobility and community control."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Nuu-chah-nulth case follows specimens beyond the study for which people understood they were contributing them. Movement between institutions can make it difficult for a community to see which material still exists, who controls it, and what research has been performed.",
          "The security lesson concerns that loss of visibility and control. A complete account should not assume that every subsequent use had the same authorization history. Transfer records, purpose restrictions, and return or destruction agreements need to follow the material so that the collection's original context does not disappear when an investigator moves."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Iceland",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "participant genomes",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns sequence, genotype, and genealogical information. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Population Imputation Spillover identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows sequence, genotype, and genealogical information through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-021",
    "case_number": "021",
    "slug": "/cases/021-iceland-genome-imputation-nonparticipants/",
    "title": "Iceland: Inferring Genomes of People Who Never Enrolled",
    "short_title": "Icelandic Population Imputation",
    "summary": "Large Icelandic sequencing studies showed that genomes from consenting participants, combined with genotypes and genealogies, could support imputation across much of a closely connected population. Genetic participation can therefore generate information about nonparticipants.",
    "direct_answer": "Large Icelandic sequencing studies showed that genomes from consenting participants, combined with genotypes and genealogies, could support imputation across much of a closely connected population. Genetic participation can therefore generate information about nonparticipants.",
    "event_label": "2015",
    "sector": "Re-identification and inference",
    "event_type": "research_demonstration",
    "genetic_asset_type": "Sequence, genotype, and genealogical information",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case021source1",
      "case021source2"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Population Imputation Spillover",
    "processing": "participant genomes → reference haplotypes + genealogy → population imputation → disease-variant inference → notification/consent dilemma",
    "direct_parties": "Research participants and people included in inference",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "mitigations": "Population-level ethics review, nonparticipant risk analysis, calibrated uncertainty, notification policy, opt-out mechanisms where feasible, access controls, and separation of research inference from clinical action.",
    "limitations": "Imputation is probabilistic and variant-dependent; it is not equivalent to directly sequencing every person.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-021",
    "family_codes": [
      "RI"
    ],
    "family": "Re-identification and inference",
    "primary_query": "Iceland genetic imputation nonparticipants privacy",
    "status": "research_demonstration",
    "jurisdictions": [
      "Iceland"
    ],
    "asset_classes": [
      "Sequence, genotype, and genealogical information"
    ],
    "threat_codes": [
      "Population Imputation Spillover"
    ],
    "imported": true,
    "threat_chain": [
      "participant genomes",
      "reference haplotypes + genealogy",
      "population imputation",
      "disease-variant inference",
      "notification/consent dilemma"
    ],
    "controls": [
      "population-level ethics review",
      "nonparticipant risk analysis",
      "calibrated uncertainty",
      "notification policy",
      "opt-out mechanisms where feasible",
      "access controls",
      "separation of research inference from clinical action"
    ],
    "does_not_prove": [
      "Imputation is probabilistic and variant-dependent; it is not equivalent to directly sequencing every person."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Icelandic research illustrates the difference between sequencing a participant and inferring information across a connected population. Genotypes, reference information, and genealogical relationships can make the analytical reach wider than the group whose genomes were directly sequenced.",
          "That reach creates a consent question without requiring a database intrusion. It also creates an accuracy question: an imputed result is not interchangeable with a direct measurement. Decisions about notification or further use should preserve that distinction, particularly when an inference concerns someone who did not enroll in the original research."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity high; availability beneficial; consent critical; persistence critical; relational exposure population-scale.",
    "proposed_score_notes": "Suggested GER: GER-4. Suggested GPR: GPR-5. Suggested GPI: GPI-4 for documented research pipelines.",
    "clusters": [
      "Re-identification science"
    ],
    "related_case_ids": [
      "GS-CASE-022",
      "GS-CASE-023",
      "GS-CASE-024",
      "GS-CASE-025"
    ],
    "related_comparisons": [
      {
        "case_number": "022",
        "text": "Compare Homer Et Al. And Aggregate GWAS Data for membership inference from summary data. This case focuses on population imputation spillover."
      },
      {
        "case_number": "023",
        "text": "Compare Gymrek Surname Inference for quasi-identifier fusion. This case focuses on population imputation spillover."
      },
      {
        "case_number": "024",
        "text": "Compare James Watson's Redacted APOE Region for correlated-data leakage. This case focuses on population imputation spillover."
      },
      {
        "case_number": "025",
        "text": "Compare Genomic Beacon Re-Identification for query interface leakage. This case focuses on population imputation spillover."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Icelandic research illustrates the difference between sequencing a participant and inferring information across a connected population. Genotypes, reference information, and genealogical relationships can make the analytical reach wider than the group whose genomes were directly sequenced.",
          "That reach creates a consent question without requiring a database intrusion. It also creates an accuracy question: an imputed result is not interchangeable with a direct measurement. Decisions about notification or further use should preserve that distinction, particularly when an inference concerns someone who did not enroll in the original research."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "target genotype + aggregate case/control statistics",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns dense snp data and aggregate statistics. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Membership Inference from Summary Data identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows dense snp data and aggregate statistics through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-022",
    "case_number": "022",
    "slug": "/cases/022-homer-aggregate-gwas-membership-inference/",
    "title": "Homer 2008: When Aggregate Genomic Data Stopped Looking Anonymous",
    "short_title": "Homer Et Al. And Aggregate GWAS Data",
    "summary": "Homer and colleagues showed that, under certain conditions, an individual's contribution to a complex DNA mixture could be detected using dense SNP data. The work triggered restrictions on some public aggregate genomic datasets and changed research-data risk assumptions.",
    "direct_answer": "Homer and colleagues showed that, under certain conditions, an individual's contribution to a complex DNA mixture could be detected using dense SNP data. The work triggered restrictions on some public aggregate genomic datasets and changed research-data risk assumptions.",
    "event_label": "2008",
    "sector": "Re-identification and inference",
    "event_type": "research_demonstration",
    "genetic_asset_type": "Dense SNP data and aggregate statistics",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case022source1",
      "case022source2"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Membership Inference from Summary Data",
    "processing": "target genotype + aggregate case/control statistics → statistical comparison → membership inference → sensitive-study association",
    "direct_parties": "Participants represented in a genomic dataset",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "mitigations": "Formal privacy review, minimum cohort sizes, query budgets, controlled access, differential-privacy research, audit logging, and attack-aware release testing.",
    "limitations": "It does not make every aggregate statistic re-identifying. Risk depends on sample size, marker density, reference knowledge, query design, and defensive controls.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-022",
    "family_codes": [
      "RI"
    ],
    "family": "Re-identification and inference",
    "primary_query": "Homer 2008 aggregate genomic data privacy",
    "status": "research_demonstration",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Dense SNP data and aggregate statistics"
    ],
    "threat_codes": [
      "Membership Inference from Summary Data"
    ],
    "imported": true,
    "threat_chain": [
      "target genotype + aggregate case/control statistics",
      "statistical comparison",
      "membership inference",
      "sensitive-study association"
    ],
    "controls": [
      "formal privacy review",
      "minimum cohort sizes",
      "query budgets",
      "controlled access",
      "differential-privacy research",
      "audit logging",
      "attack-aware release testing"
    ],
    "does_not_prove": [
      "It does not make every aggregate statistic re-identifying. Risk depends on sample size, marker density, reference knowledge, query design, and defensive controls."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Homer study challenged the assumption that summary genomic information was necessarily harmless to release. Under the study's conditions, a target's known genetic information could be compared with aggregate data to assess whether that person contributed to the group.",
          "The sensitive conclusion may be membership itself. Association with a particular cohort can reveal something that an individual-level file was intended to protect. The lesson is not that all statistics identify people, but that a release assessment needs to consider outside knowledge, the structure of the dataset, and what can be inferred from their combination."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity low; availability affected because data access was restricted; consent moderate/high; persistence high.",
    "proposed_score_notes": "Suggested GER: GER-0/1. Suggested GPR: GPR-4. GPI: not central.",
    "clusters": [
      "Re-identification science"
    ],
    "related_case_ids": [
      "GS-CASE-021",
      "GS-CASE-023",
      "GS-CASE-024",
      "GS-CASE-025"
    ],
    "related_comparisons": [
      {
        "case_number": "021",
        "text": "Compare Icelandic Population Imputation for population imputation spillover. This case focuses on membership inference from summary data."
      },
      {
        "case_number": "023",
        "text": "Compare Gymrek Surname Inference for quasi-identifier fusion. This case focuses on membership inference from summary data."
      },
      {
        "case_number": "024",
        "text": "Compare James Watson's Redacted APOE Region for correlated-data leakage. This case focuses on membership inference from summary data."
      },
      {
        "case_number": "025",
        "text": "Compare Genomic Beacon Re-Identification for query interface leakage. This case focuses on membership inference from summary data."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Homer study challenged the assumption that summary genomic information was necessarily harmless to release. Under the study's conditions, a target's known genetic information could be compared with aggregate data to assess whether that person contributed to the group.",
          "The sensitive conclusion may be membership itself. Association with a particular cohort can reveal something that an individual-level file was intended to protect. The lesson is not that all statistics identify people, but that a release assessment needs to consider outside knowledge, the structure of the dataset, and what can be inferred from their combination."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "anonymous male genome",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns y-chromosome markers and public demographic information. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Quasi-Identifier Fusion identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows y-chromosome markers and public demographic information through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-023",
    "case_number": "023",
    "slug": "/cases/023-surname-inference-anonymous-genomes/",
    "title": "Surname Inference: How an Anonymous Genome Found a Family Name",
    "short_title": "Gymrek Surname Inference",
    "summary": "Researchers demonstrated that Y-chromosome markers could sometimes be linked to surnames through genealogy databases, then combined with age, geography, and family information to identify supposedly anonymous genome donors.",
    "direct_answer": "Researchers demonstrated that Y-chromosome markers could sometimes be linked to surnames through genealogy databases, then combined with age, geography, and family information to identify supposedly anonymous genome donors.",
    "event_label": "2013",
    "sector": "Re-identification and inference",
    "event_type": "research_demonstration",
    "genetic_asset_type": "Y-chromosome markers and public demographic information",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case023source1",
      "case023source2"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Quasi-Identifier Fusion",
    "processing": "anonymous male genome → Y-STR profile → genealogy database → surname candidate → demographics/public records → identity hypothesis",
    "direct_parties": "Genome donors involved in the research demonstration",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "mitigations": "Remove unnecessary quasi-identifiers, model auxiliary-data attacks, controlled access, family-risk disclosure, resistant query design, and continuous re-identification testing.",
    "limitations": "Surname inference does not work for everyone, is culturally and demographically uneven, and produces leads rather than guaranteed identities.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-023",
    "family_codes": [
      "RI"
    ],
    "family": "Re-identification and inference",
    "primary_query": "identify anonymous genome surname inference",
    "status": "research_demonstration",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Y-chromosome markers and public demographic information"
    ],
    "threat_codes": [
      "Quasi-Identifier Fusion"
    ],
    "imported": true,
    "threat_chain": [
      "anonymous male genome",
      "Y-STR profile",
      "genealogy database",
      "surname candidate",
      "demographics/public records",
      "identity hypothesis"
    ],
    "controls": [
      "remove unnecessary quasi-identifiers",
      "model auxiliary-data attacks",
      "controlled access",
      "family-risk disclosure",
      "resistant query design",
      "continuous re-identification testing"
    ],
    "does_not_prove": [
      "Surname inference does not work for everyone, is culturally and demographically uneven, and produces leads rather than guaranteed identities."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The surname-inference research connected genetic markers with genealogy records and demographic clues. Its significance was the joining of information across datasets: a name and a genomic record did not have to appear together in the same release to become linkable.",
          "The method's reach depends on the population, the available genealogy information, and the clues accompanying the record. A surname candidate is not a guaranteed identity. The broader security question is which external datasets can supply the missing connection after obvious identifiers have been removed."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality critical; integrity low; consent high; persistence high; relational exposure extended-family scale.",
    "proposed_score_notes": "Suggested GER: GER-2/3. Suggested GPR: GPR-5. GPI: not central.",
    "clusters": [
      "Re-identification science"
    ],
    "related_case_ids": [
      "GS-CASE-021",
      "GS-CASE-022",
      "GS-CASE-024",
      "GS-CASE-025"
    ],
    "related_comparisons": [
      {
        "case_number": "021",
        "text": "Compare Icelandic Population Imputation for population imputation spillover. This case focuses on quasi-identifier fusion."
      },
      {
        "case_number": "022",
        "text": "Compare Homer Et Al. And Aggregate GWAS Data for membership inference from summary data. This case focuses on quasi-identifier fusion."
      },
      {
        "case_number": "024",
        "text": "Compare James Watson's Redacted APOE Region for correlated-data leakage. This case focuses on quasi-identifier fusion."
      },
      {
        "case_number": "025",
        "text": "Compare Genomic Beacon Re-Identification for query interface leakage. This case focuses on quasi-identifier fusion."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The surname-inference research connected genetic markers with genealogy records and demographic clues. Its significance was the joining of information across datasets: a name and a genomic record did not have to appear together in the same release to become linkable.",
          "The method's reach depends on the population, the available genealogy information, and the clues accompanying the record. A surname candidate is not a guaranteed identity. The broader security question is which external datasets can supply the missing connection after obvious identifiers have been removed."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "public genome with narrow redaction",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns a public genome with a redacted apoe region. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Correlated-Data Leakage identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows a public genome with a redacted apoe region through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-024",
    "case_number": "024",
    "slug": "/cases/024-watson-apoe-genome-redaction-failure/",
    "title": "The Gene He Hid: Why Genomic Redaction Is Hard",
    "short_title": "James Watson's Redacted APOE Region",
    "summary": "James Watson withheld the APOE region from his public genome because of its association with Alzheimer disease risk, but researchers showed that nearby correlated variants could still support inference. Deleting the secret field may not delete the secret.",
    "direct_answer": "James Watson withheld the APOE region from his public genome because of its association with Alzheimer disease risk, but researchers showed that nearby correlated variants could still support inference. Deleting the secret field may not delete the secret.",
    "event_label": "2008",
    "sector": "Re-identification and inference",
    "event_type": "research_demonstration",
    "genetic_asset_type": "A public genome with a redacted APOE region",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case024source1",
      "case024source2"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Correlated-Data Leakage",
    "processing": "public genome with narrow redaction → correlated flanking variants → statistical inference → sensitive genotype risk",
    "direct_parties": "The publicly described genome donor",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "mitigations": "Correlation-aware redaction, privacy threat modeling before release, family-impact counseling, controlled rather than public access, and periodic reassessment as reference panels improve.",
    "limitations": "The example does not establish an Alzheimer diagnosis, a predetermined outcome, or perfect genotype inference.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-024",
    "family_codes": [
      "RI"
    ],
    "family": "Re-identification and inference",
    "primary_query": "James Watson APOE genome redaction inference",
    "status": "research_demonstration",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "A public genome with a redacted APOE region"
    ],
    "threat_codes": [
      "Correlated-Data Leakage"
    ],
    "imported": true,
    "threat_chain": [
      "public genome with narrow redaction",
      "correlated flanking variants",
      "statistical inference",
      "sensitive genotype risk"
    ],
    "controls": [
      "correlation-aware redaction",
      "privacy threat modeling before release",
      "family-impact counseling",
      "controlled rather than public access",
      "periodic reassessment as reference panels improve"
    ],
    "does_not_prove": [
      "The example does not establish an Alzheimer diagnosis, a predetermined outcome, or perfect genotype inference."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Watson example concerns selective disclosure. Withholding one region of a genome did not necessarily remove the information needed to infer something about that region, because visible variants could remain correlated with the hidden data. The researchers did not disclose his status.",
          "Redaction therefore needs to consider relationships between fields, not merely whether the sensitive field is absent. This is a privacy lesson rather than a diagnosis: inferred genetic risk does not establish disease or destiny. A release should be assessed for what its remaining information supports, including in combination with outside reference data."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity unaffected; consent complex because publication was voluntary but selective; persistence high.",
    "proposed_score_notes": "Suggested GER: GER-1/2 because APOE information may matter to relatives. Suggested GPR: GPR-5. GPI: not central.",
    "clusters": [
      "Re-identification science"
    ],
    "related_case_ids": [
      "GS-CASE-021",
      "GS-CASE-022",
      "GS-CASE-023",
      "GS-CASE-025"
    ],
    "related_comparisons": [
      {
        "case_number": "021",
        "text": "Compare Icelandic Population Imputation for population imputation spillover. This case focuses on correlated-data leakage."
      },
      {
        "case_number": "022",
        "text": "Compare Homer Et Al. And Aggregate GWAS Data for membership inference from summary data. This case focuses on correlated-data leakage."
      },
      {
        "case_number": "023",
        "text": "Compare Gymrek Surname Inference for quasi-identifier fusion. This case focuses on correlated-data leakage."
      },
      {
        "case_number": "025",
        "text": "Compare Genomic Beacon Re-Identification for query interface leakage. This case focuses on correlated-data leakage."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Watson example concerns selective disclosure. Withholding one region of a genome did not necessarily remove the information needed to infer something about that region, because visible variants could remain correlated with the hidden data. The researchers did not disclose his status.",
          "Redaction therefore needs to consider relationships between fields, not merely whether the sensitive field is absent. This is a privacy lesson rather than a diagnosis: inferred genetic risk does not establish disease or destiny. A release should be assessed for what its remaining information supports, including in combination with outside reference data."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "target genotype",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns genomic beacon responses and target variant information. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Query Interface Leakage identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows genomic beacon responses and target variant information through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-025",
    "case_number": "025",
    "slug": "/cases/025-genomic-beacon-membership-inference/",
    "title": "The Yes-or-No Oracle: Re-identifying People Through a Genomic Beacon",
    "short_title": "Genomic Beacon Re-Identification",
    "summary": "A genomic beacon may answer only whether a variant exists in a dataset, yet a sequence of yes/no responses can support membership inference. Minimal answers can still reveal a sensitive whole when queries accumulate.",
    "direct_answer": "A genomic beacon may answer only whether a variant exists in a dataset, yet a sequence of yes/no responses can support membership inference. Minimal answers can still reveal a sensitive whole when queries accumulate.",
    "event_label": "2015",
    "sector": "Re-identification and inference",
    "event_type": "research_demonstration",
    "genetic_asset_type": "Genomic beacon responses and target variant information",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case025source1",
      "case025source2"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Query Interface Leakage",
    "processing": "target genotype → repeated API queries → response pattern → likelihood test → membership inference → disease-cohort exposure",
    "direct_parties": "Dataset participants represented in the demonstration",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Permission to contribute a record does not settle what may be inferred about a nonparticipant or relative. Public availability and authorization for a particular use should be distinguished.",
    "mitigations": "Authentication, query budgets, rate limits, minimum cohort sizes, response perturbation, aggregation, auditing, access tiers, and privacy testing before deployment.",
    "limitations": "The research does not establish that every beacon is vulnerable under every dataset size, query rule, or defensive configuration.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-025",
    "family_codes": [
      "RI",
      "CY"
    ],
    "family": "Re-identification and inference",
    "primary_query": "genomic beacon re-identification attack",
    "status": "research_demonstration",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Genomic beacon responses and target variant information"
    ],
    "threat_codes": [
      "Query Interface Leakage"
    ],
    "imported": true,
    "threat_chain": [
      "target genotype",
      "repeated API queries",
      "response pattern",
      "likelihood test",
      "membership inference",
      "disease-cohort exposure"
    ],
    "controls": [
      "authentication",
      "query budgets",
      "rate limits",
      "minimum cohort sizes",
      "response perturbation",
      "aggregation",
      "auditing",
      "access tiers",
      "privacy testing before deployment"
    ],
    "does_not_prove": [
      "The research does not establish that every beacon is vulnerable under every dataset size, query rule, or defensive configuration."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "A beacon can provide a very small answer to each query while revealing more through a collection of responses. The research example asks whether someone with knowledge of a target's variants can use that pattern to infer dataset membership.",
          "The individual response and the whole interface need different privacy assessments. Authentication, query limits, and other defenses affect the circumstances under which an inference might work. This case concerns a published demonstration and its assumptions; it is not a claim that every deployed beacon exposes its participants or that a live service was attacked."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality critical; availability tension because defenses may reduce openness; integrity low; consent high; persistence high.",
    "proposed_score_notes": "Suggested GER: GER-0/1. Suggested GPR: GPR-4/5. GPI: not central.",
    "clusters": [
      "Re-identification science"
    ],
    "related_case_ids": [
      "GS-CASE-021",
      "GS-CASE-022",
      "GS-CASE-023",
      "GS-CASE-024"
    ],
    "related_comparisons": [
      {
        "case_number": "021",
        "text": "Compare Icelandic Population Imputation for population imputation spillover. This case focuses on query interface leakage."
      },
      {
        "case_number": "022",
        "text": "Compare Homer Et Al. And Aggregate GWAS Data for membership inference from summary data. This case focuses on query interface leakage."
      },
      {
        "case_number": "023",
        "text": "Compare Gymrek Surname Inference for quasi-identifier fusion. This case focuses on query interface leakage."
      },
      {
        "case_number": "024",
        "text": "Compare James Watson's Redacted APOE Region for correlated-data leakage. This case focuses on query interface leakage."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "A beacon can provide a very small answer to each query while revealing more through a collection of responses. The research example asks whether someone with knowledge of a target's variants can use that pattern to infer dataset membership.",
          "The individual response and the whole interface need different privacy assessments. Authentication, query limits, and other defenses affect the circumstances under which an inference might work. This case concerns a published demonstration and its assumptions; it is not a claim that every deployed beacon exposes its participants or that a live service was attacked."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "voluntary enrollment",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns public genomic and phenotypic records. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Residual-Risk Transparency identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows public genomic and phenotypic records through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-026",
    "case_number": "026",
    "slug": "/cases/026-personal-genome-project-open-consent/",
    "title": "Open Consent: The Personal Genome Project's Honest Privacy Bargain",
    "short_title": "Personal Genome Project Open Consent",
    "summary": "The Personal Genome Project treated re-identification as a foreseeable risk rather than promising anonymity it could not guarantee. Its open-consent model is a governance case about truthful risk disclosure, not a claim that privacy no longer matters.",
    "direct_answer": "The Personal Genome Project treated re-identification as a foreseeable risk rather than promising anonymity it could not guarantee. Its open-consent model is a governance case about truthful risk disclosure, not a claim that privacy no longer matters.",
    "event_label": "Ongoing research program",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "governance_dispute",
    "genetic_asset_type": "Public genomic and phenotypic records",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case026source1",
      "case026source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Residual-Risk Transparency",
    "processing": "voluntary enrollment → public genomic/phenotypic data → linkage to public records → possible identification → family and future-inference effects",
    "direct_parties": "Voluntary research participants",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Comprehension testing, staged consent, family-risk warnings, withdrawal limits stated up front, data-use transparency, ongoing participant communication, and versioned consent text.",
    "limitations": "Open consent does not erase risk, authorize decisions for relatives, or resolve the ethics of every future use.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-026",
    "family_codes": [
      "CO",
      "RI"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Personal Genome Project open consent privacy",
    "status": "governance_dispute",
    "jurisdictions": [
      "United States",
      "International"
    ],
    "asset_classes": [
      "Public genomic and phenotypic records"
    ],
    "threat_codes": [
      "Residual-Risk Transparency"
    ],
    "imported": true,
    "threat_chain": [
      "voluntary enrollment",
      "public genomic/phenotypic data",
      "linkage to public records",
      "possible identification",
      "family and future-inference effects"
    ],
    "controls": [
      "comprehension testing",
      "staged consent",
      "family-risk warnings",
      "withdrawal limits stated up front",
      "data-use transparency",
      "ongoing participant communication",
      "versioned consent text"
    ],
    "does_not_prove": [
      "Open consent does not erase risk, authorize decisions for relatives, or resolve the ethics of every future use."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Personal Genome Project takes a different approach to public-data risk: it does not depend on an absolute promise of anonymity. The governance question becomes whether participants understand what public release means and which consequences cannot be withdrawn later.",
          "An explicit choice can still have limits. One participant cannot make every decision for relatives, and future analytical uses cannot all be predicted at enrollment. The case is useful for comparing transparent acceptance of residual risk with a reassuring but unsupported guarantee that removing a name makes a genome anonymous."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality intentionally low; integrity/provenance high; availability high; consent explicit; persistence critical; relational exposure significant.",
    "proposed_score_notes": "Suggested GER: GER-2. Suggested GPR: GPR-5. Suggested GPI: GPI-4 for curated public records.",
    "clusters": [
      "Re-identification science"
    ],
    "related_case_ids": [
      "GS-CASE-021",
      "GS-CASE-022",
      "GS-CASE-023",
      "GS-CASE-024"
    ],
    "related_comparisons": [
      {
        "case_number": "021",
        "text": "Compare Icelandic Population Imputation for population imputation spillover. This case focuses on residual-risk transparency."
      },
      {
        "case_number": "022",
        "text": "Compare Homer Et Al. And Aggregate GWAS Data for membership inference from summary data. This case focuses on residual-risk transparency."
      },
      {
        "case_number": "023",
        "text": "Compare Gymrek Surname Inference for quasi-identifier fusion. This case focuses on residual-risk transparency."
      },
      {
        "case_number": "024",
        "text": "Compare James Watson's Redacted APOE Region for correlated-data leakage. This case focuses on residual-risk transparency."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Personal Genome Project takes a different approach to public-data risk: it does not depend on an absolute promise of anonymity. The governance question becomes whether participants understand what public release means and which consequences cannot be withdrawn later.",
          "An explicit choice can still have limits. One participant cannot make every decision for relatives, and future analytical uses cannot all be predicted at enrollment. The case is useful for comparing transparent acceptance of residual risk with a reassuring but unsupported guarantee that removing a name makes a genome anonymous."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United Kingdom / European Court of Human Rights",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "arrest/investigation",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns retained cellular samples, dna profiles, and fingerprints. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Retention Proportionality identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows retained cellular samples, dna profiles, and fingerprints through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-027",
    "case_number": "027",
    "slug": "/cases/027-s-marper-dna-retention-privacy/",
    "title": "S. and Marper: Indefinite DNA Retention After Acquittal",
    "short_title": "S. And Marper v. United Kingdom",
    "summary": "The European Court of Human Rights held that the United Kingdom's blanket, indefinite retention of fingerprints, cellular samples, and DNA profiles from people not convicted of offenses violated Article 8 privacy rights.",
    "direct_answer": "The European Court of Human Rights held that the United Kingdom's blanket, indefinite retention of fingerprints, cellular samples, and DNA profiles from people not convicted of offenses violated Article 8 privacy rights.",
    "event_label": "2008",
    "sector": "Law enforcement and forensic genetics",
    "event_type": "court_case",
    "genetic_asset_type": "Retained cellular samples, DNA profiles, and fingerprints",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 1,
    "sources": [
      "case027source1"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Retention Proportionality",
    "processing": "arrest/investigation → sample and profile collection → no conviction → indefinite retention → continuing state searchability and future analytical potential",
    "direct_parties": "The applicants and people covered by the challenged regime",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "mitigations": "Retention schedules tied to case status and seriousness, sample/profile separation, automatic deletion review, independent oversight, purpose limitation, and accessible challenge procedures.",
    "limitations": "It did not ban forensic DNA databases or all post-arrest retention. The judgment concerned the blanket and indiscriminate character of the regime.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-027",
    "family_codes": [
      "LE"
    ],
    "family": "Law enforcement and forensic genetics",
    "primary_query": "S and Marper DNA retention case",
    "status": "court_case",
    "jurisdictions": [
      "United Kingdom",
      "European Court of Human Rights"
    ],
    "asset_classes": [
      "Retained cellular samples, DNA profiles, and fingerprints"
    ],
    "threat_codes": [
      "Retention Proportionality"
    ],
    "imported": true,
    "threat_chain": [
      "arrest/investigation",
      "sample and profile collection",
      "no conviction",
      "indefinite retention",
      "continuing state searchability and future analytical potential"
    ],
    "controls": [
      "retention schedules tied to case status and seriousness",
      "sample/profile separation",
      "automatic deletion review",
      "independent oversight",
      "purpose limitation",
      "accessible challenge procedures"
    ],
    "does_not_prove": [
      "It did not ban forensic DNA databases or all post-arrest retention. The judgment concerned the blanket and indiscriminate character of the regime."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "S. and Marper examined the retention of fingerprints, samples, and profiles from people who had not been convicted. The European Court of Human Rights objected to the blanket and indiscriminate character of the regime. Its judgment did not abolish forensic databases or resolve every possible retention policy.",
          "The assets matter individually. A cellular sample and a limited forensic profile do not support identical future uses. A retention review should connect each asset to the reason for keeping it, the individual's case status, and the process for challenging or ending retention."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; availability favored law enforcement; consent absent; persistence critical; relational exposure possible.",
    "proposed_score_notes": "Suggested GER: GER-1/2. Suggested GPR: GPR-5 for retained cellular material; lower for limited profile alone. Suggested GPI: GPI-4 if state custody is documented.",
    "clusters": [],
    "related_case_ids": [],
    "related_comparisons": [],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "S. and Marper examined the retention of fingerprints, samples, and profiles from people who had not been convicted. The European Court of Human Rights objected to the blanket and indiscriminate character of the regime. Its judgment did not abolish forensic databases or resolve every possible retention policy.",
          "The assets matter individually. A cellular sample and a limited forensic profile do not support identical future uses. A retention review should connect each asset to the reason for keeping it, the individual's case status, and the process for challenging or ending retention."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Maryland",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "serious-offense arrest",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns arrestee cheek swab and forensic profile. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Collection Threshold and Purpose Expansion identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows arrestee cheek swab and forensic profile through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-028",
    "case_number": "028",
    "slug": "/cases/028-maryland-king-arrestee-dna/",
    "title": "Maryland v. King: When a Cheek Swab Became Booking Identification",
    "short_title": "Maryland v. King",
    "summary": "In 2013 the U.S. Supreme Court upheld, under the circumstances before it, Maryland's collection of a DNA cheek swab from an arrestee charged with a serious offense as a reasonable booking procedure.",
    "direct_answer": "In 2013 the U.S. Supreme Court upheld, under the circumstances before it, Maryland's collection of a DNA cheek swab from an arrestee charged with a serious offense as a reasonable booking procedure.",
    "event_label": "2013",
    "sector": "Law enforcement and forensic genetics",
    "event_type": "court_case",
    "genetic_asset_type": "Arrestee cheek swab and forensic profile",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case028source1",
      "case028source2"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Collection Threshold and Purpose Expansion",
    "processing": "serious-offense arrest → cheek swab → forensic profile → database search → cold-case hit → prosecution",
    "direct_parties": "The arrestee in the case and people covered by the collection law",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "mitigations": "Statutory scope limits, profile/sample separation, expungement, analysis restrictions, audit trails, accreditation, and warrants for uses outside the authorized purpose.",
    "limitations": "It does not approve universal sequencing, collection from everyone, every arrest category, or unrestricted analysis of retained samples.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-028",
    "family_codes": [
      "LE"
    ],
    "family": "Law enforcement and forensic genetics",
    "primary_query": "Maryland v King arrestee DNA Supreme Court",
    "status": "court_case",
    "jurisdictions": [
      "United States",
      "Maryland"
    ],
    "asset_classes": [
      "Arrestee cheek swab and forensic profile"
    ],
    "threat_codes": [
      "Collection Threshold and Purpose Expansion"
    ],
    "imported": true,
    "threat_chain": [
      "serious-offense arrest",
      "cheek swab",
      "forensic profile",
      "database search",
      "cold-case hit",
      "prosecution"
    ],
    "controls": [
      "statutory scope limits",
      "profile/sample separation",
      "expungement",
      "analysis restrictions",
      "audit trails",
      "accreditation",
      "warrants for uses outside the authorized purpose"
    ],
    "does_not_prove": [
      "It does not approve universal sequencing, collection from everyone, every arrest category, or unrestricted analysis of retained samples."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Maryland v. King addressed a cheek swab collected after an arrest for a serious offense. The majority's booking-identification rationale and the dissent's concerns about crime-solving purposes reveal the importance of specifying what a collection is intended to accomplish.",
          "The physical act of swabbing, the profile generated from it, and any retained specimen should remain separate in the analysis. The decision does not authorize universal sequencing or unlimited analysis. Its value in this collection is as a bounded legal example of how collection thresholds and stated purposes shape a forensic data system."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity/provenance high; availability supports public safety; consent absent; persistence high.",
    "proposed_score_notes": "Suggested GER: GER-1. Suggested GPR: GPR-3 for a limited profile, GPR-5 if the biological sample remains available. Suggested GPI: GPI-4.",
    "clusters": [],
    "related_case_ids": [],
    "related_comparisons": [],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Maryland v. King addressed a cheek swab collected after an arrest for a serious offense. The majority's booking-identification rationale and the dissent's concerns about crime-solving purposes reveal the importance of specifying what a collection is intended to accomplish.",
          "The physical act of swabbing, the profile generated from it, and any retained specimen should remain separate in the analysis. The decision does not authorize universal sequencing or unlimited analysis. Its value in this collection is as a bounded legal example of how collection thresholds and stated purposes shape a forensic data system."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Kuwait",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "national-security shock",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns proposed population dna collection and database. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Population-Scale Collection Limits identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows proposed population dna collection and database through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-029",
    "case_number": "029",
    "slug": "/cases/029-kuwait-universal-dna-law/",
    "title": "Kuwait's DNA Law: The Universal Database That the Court Rejected",
    "short_title": "Kuwait's Universal DNA Law",
    "summary": "Kuwait adopted a law requiring DNA collection on an extraordinary population-wide scale after a 2015 terrorist attack, but its Constitutional Court struck the law down in 2017, making it a landmark boundary case for universal forensic databases.",
    "direct_answer": "Kuwait adopted a law requiring DNA collection on an extraordinary population-wide scale after a 2015 terrorist attack, but its Constitutional Court struck the law down in 2017, making it a landmark boundary case for universal forensic databases.",
    "event_label": "2015–2017",
    "sector": "Law enforcement and forensic genetics",
    "event_type": "court_case",
    "genetic_asset_type": "Proposed population DNA collection and database",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 1,
    "sources": [
      "case029source1"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Population-Scale Collection Limits",
    "processing": "national-security shock → universal collection mandate → centralized DNA database → constitutional challenge → invalidation",
    "direct_parties": "People within the collection mandate",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "mitigations": "Narrow predicates, judicial authorization, strict purpose limitation, deletion, independent oversight, transparency, limits on familial searching, and constitutional review before collection.",
    "limitations": "It does not establish one global constitutional rule. It illustrates how proportionality and scope can defeat an asserted security objective.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-029",
    "family_codes": [
      "LE",
      "SV"
    ],
    "family": "Law enforcement and forensic genetics",
    "primary_query": "Kuwait mandatory DNA law unconstitutional",
    "status": "court_case",
    "jurisdictions": [
      "Kuwait"
    ],
    "asset_classes": [
      "Proposed population DNA collection and database"
    ],
    "threat_codes": [
      "Population-Scale Collection Limits"
    ],
    "imported": true,
    "threat_chain": [
      "national-security shock",
      "universal collection mandate",
      "centralized DNA database",
      "constitutional challenge",
      "invalidation"
    ],
    "controls": [
      "narrow predicates",
      "judicial authorization",
      "strict purpose limitation",
      "deletion",
      "independent oversight",
      "transparency",
      "limits on familial searching",
      "constitutional review before collection"
    ],
    "does_not_prove": [
      "It does not establish one global constitutional rule. It illustrates how proportionality and scope can defeat an asserted security objective."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Kuwait's law proposed DNA collection on a scale much broader than an ordinary suspect database. The security rationale, the population covered by the mandate, and the constitutional response are separate elements of the case.",
          "A collection plan also needs to be distinguished from its implementation. A broad statutory mandate does not prove that every intended sample was collected or that every proposed use occurred. The case illustrates the importance of examining proportionality and limits before a population-scale system creates durable biological records."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality critical; integrity/provenance critical; availability high for state searches; consent absent; persistence critical; relational exposure population-scale.",
    "proposed_score_notes": "Suggested GER: GER-4/5. Suggested GPR: GPR-5. Suggested GPI: unknown unless implementation records support scoring.",
    "clusters": [
      "Community and population governance"
    ],
    "related_case_ids": [
      "GS-CASE-009",
      "GS-CASE-018",
      "GS-CASE-019",
      "GS-CASE-065"
    ],
    "related_comparisons": [
      {
        "case_number": "009",
        "text": "Compare DOJ bulk genomic data for genomic sovereignty / strategic data security. This case focuses on population-scale collection limits."
      },
      {
        "case_number": "018",
        "text": "Compare Kennewick Man / The Ancient One for ancestral genomic governance. This case focuses on population-scale collection limits."
      },
      {
        "case_number": "019",
        "text": "Compare Chaco Canyon Ancient DNA for community standing survives temporal distance. This case focuses on population-scale collection limits."
      },
      {
        "case_number": "065",
        "text": "Compare Mass DNA Collection In Xinjiang And Tibet for genetic surveillance of populations. This case focuses on population-scale collection limits."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Kuwait's law proposed DNA collection on a scale much broader than an ordinary suspect database. The security rationale, the population covered by the mandate, and the constitutional response are separate elements of the case.",
          "A collection plan also needs to be distinguished from its implementation. A broad statutory mandate does not prove that every intended sample was collected or that every proposed use occurred. The case illustrates the importance of examining proportionality and limits before a population-scale system creates durable biological records."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "consumer uploads",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "law_enforcement": true,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns consumer genealogy profiles and matching access. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Material Policy Change identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows consumer genealogy profiles and matching access through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-030",
    "case_number": "030",
    "slug": "/cases/030-familytreedna-fbi-matching-policy/",
    "title": "FamilyTreeDNA: When a Consumer Database Opened a Law-Enforcement Door",
    "short_title": "FamilyTreeDNA And FBI Matching",
    "summary": "FamilyTreeDNA's 2019 disclosure that it was cooperating with FBI investigations showed how a consumer genealogy service's matching policy can materially change the exposure of existing customers and their relatives.",
    "direct_answer": "FamilyTreeDNA's 2019 disclosure that it was cooperating with FBI investigations showed how a consumer genealogy service's matching policy can materially change the exposure of existing customers and their relatives.",
    "event_label": "2019 onward",
    "sector": "Consumer genetics and commercial data",
    "event_type": "policy_event",
    "genetic_asset_type": "Consumer genealogy profiles and matching access",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "case030source1",
      "case030source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Material Policy Change",
    "processing": "consumer uploads → policy/terms change → law-enforcement kits → relative matches → genealogical narrowing",
    "direct_parties": "FamilyTreeDNA customers and matching participants",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "mitigations": "Prospective opt-in, conspicuous notice, narrow crime criteria, legal-process verification, public transparency reports, user-visible audit history, and deletion/withdrawal mechanisms.",
    "limitations": "Matching access does not establish that investigators received unrestricted raw-genome access or a bulk database export.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-030",
    "family_codes": [
      "CG",
      "LE"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "FamilyTreeDNA FBI law enforcement matching policy",
    "status": "policy_event",
    "jurisdictions": [
      "United States",
      "International"
    ],
    "asset_classes": [
      "Consumer genealogy profiles and matching access"
    ],
    "threat_codes": [
      "Material Policy Change"
    ],
    "imported": true,
    "threat_chain": [
      "consumer uploads",
      "policy/terms change",
      "law-enforcement kits",
      "relative matches",
      "genealogical narrowing"
    ],
    "controls": [
      "prospective opt-in",
      "conspicuous notice",
      "narrow crime criteria",
      "legal-process verification",
      "public transparency reports",
      "user-visible audit history",
      "deletion/withdrawal mechanisms"
    ],
    "does_not_prove": [
      "Matching access does not establish that investigators received unrestricted raw-genome access or a bulk database export."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "FamilyTreeDNA's law-enforcement cooperation raised questions about how an established consumer relationship changes when a new kind of matching becomes possible. The historical disclosure, later policy changes, and current service rules are different time periods and should not be collapsed into one account.",
          "Matching access is also different from receiving raw files or exporting an entire database. The relevant permission needs to be named. The governance lesson is that meaningful notice should explain the new action, who can perform it, and how a user's choices affect future comparisons."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity low; consent critical; persistence high; relational exposure high.",
    "proposed_score_notes": "Suggested GER: GER-3. Suggested GPR: GPR-4/5. Suggested GPI: GPI-3 for documented matching operations.",
    "clusters": [
      "Genealogy governance"
    ],
    "related_case_ids": [
      "GS-CASE-002",
      "GS-CASE-006",
      "GS-CASE-012",
      "GS-CASE-031"
    ],
    "related_comparisons": [
      {
        "case_number": "002",
        "text": "Compare Golden State Killer for kinship leakage. This case focuses on material policy change."
      },
      {
        "case_number": "006",
        "text": "Compare GEDmatch for governance as a security control. This case focuses on material policy change."
      },
      {
        "case_number": "012",
        "text": "Compare GEDmatch 2020 Permissions Breach for consent-state integrity. This case focuses on material policy change."
      },
      {
        "case_number": "031",
        "text": "Compare Buckskin Girl / Marcia King for restorative identification. This case focuses on material policy change."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "FamilyTreeDNA's law-enforcement cooperation raised questions about how an established consumer relationship changes when a new kind of matching becomes possible. The historical disclosure, later policy changes, and current service rules are different time periods and should not be collapsed into one account.",
          "Matching access is also different from receiving raw files or exporting an entire database. The relevant permission needs to be named. The governance lesson is that meaningful notice should explain the new action, who can perform it, and how a user's choices affect future comparisons."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Ohio",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "unidentified remains",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns unidentified remains and genealogy profile. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Restorative Identification identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows unidentified remains and genealogy profile through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-031",
    "case_number": "031",
    "slug": "/cases/031-buckskin-girl-marcia-king-identification/",
    "title": "Buckskin Girl: Genetic Genealogy Gives a Jane Doe Her Name",
    "short_title": "Buckskin Girl / Marcia King",
    "summary": "The 2018 identification of the woman long known as Buckskin Girl as Marcia King became one of the earliest prominent successes of investigative genetic genealogy for unidentified remains.",
    "direct_answer": "The 2018 identification of the woman long known as Buckskin Girl as Marcia King became one of the earliest prominent successes of investigative genetic genealogy for unidentified remains.",
    "event_label": "2018",
    "sector": "Law enforcement and forensic genetics",
    "event_type": "historical_case",
    "genetic_asset_type": "Unidentified remains and genealogy profile",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "case031source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Restorative Identification",
    "processing": "unidentified remains → DNA extraction/profile → genealogy matches → family tree → candidate identity → family confirmation",
    "direct_parties": "Marcia King and relatives contacted during identification",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "mitigations": "Case eligibility criteria, respectful family contact, independent confirmation, database-policy compliance, minimization, genealogist documentation, and post-identification data retention rules.",
    "limitations": "A genealogy lead is not a final identification and does not imply that every database or relative was searched.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-031",
    "family_codes": [
      "LE"
    ],
    "family": "Law enforcement and forensic genetics",
    "primary_query": "Buckskin Girl genetic genealogy identification",
    "status": "historical_case",
    "jurisdictions": [
      "United States",
      "Ohio"
    ],
    "asset_classes": [
      "Unidentified remains and genealogy profile"
    ],
    "threat_codes": [
      "Restorative Identification"
    ],
    "imported": true,
    "threat_chain": [
      "unidentified remains",
      "DNA extraction/profile",
      "genealogy matches",
      "family tree",
      "candidate identity",
      "family confirmation"
    ],
    "controls": [
      "case eligibility criteria",
      "respectful family contact",
      "independent confirmation",
      "database-policy compliance",
      "minimization",
      "genealogist documentation",
      "post-identification data retention rules"
    ],
    "does_not_prove": [
      "A genealogy lead is not a final identification and does not imply that every database or relative was searched."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The identification of Marcia King shows a use of genetic genealogy directed toward restoring a name to unidentified remains. It shares the relative-matching mechanism of suspect investigations while serving a different immediate purpose.",
          "The distinction does not remove the need for careful confirmation or consideration of living relatives. A genealogy lead, documentary research, and the final identification play different roles. Respectful family contact and clear retention decisions help keep a beneficial outcome connected to an accountable process rather than treating success as proof that every method was appropriate."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality complex; integrity/provenance critical; consent unavailable; relational exposure extended-family scale; public-interest benefit high.",
    "proposed_score_notes": "Suggested GER: GER-2/3. Suggested GPR: GPR-4. Suggested GPI: GPI-4 if chain and confirmation are documented.",
    "clusters": [
      "Genealogy governance"
    ],
    "related_case_ids": [
      "GS-CASE-002",
      "GS-CASE-006",
      "GS-CASE-012",
      "GS-CASE-030"
    ],
    "related_comparisons": [
      {
        "case_number": "002",
        "text": "Compare Golden State Killer for kinship leakage. This case focuses on restorative identification."
      },
      {
        "case_number": "006",
        "text": "Compare GEDmatch for governance as a security control. This case focuses on restorative identification."
      },
      {
        "case_number": "012",
        "text": "Compare GEDmatch 2020 Permissions Breach for consent-state integrity. This case focuses on restorative identification."
      },
      {
        "case_number": "030",
        "text": "Compare FamilyTreeDNA And FBI Matching for material policy change. This case focuses on restorative identification."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The identification of Marcia King shows a use of genetic genealogy directed toward restoring a name to unidentified remains. It shares the relative-matching mechanism of suspect investigations while serving a different immediate purpose.",
          "The distinction does not remove the need for careful confirmation or consideration of living relatives. A genealogy lead, documentary research, and the final identification play different roles. Respectful family contact and clear retention decisions help keep a beneficial outcome connected to an accountable process rather than treating success as proof that every method was appropriate."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / New Hampshire",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "multiple remains",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns preserved remains and multi-person kinship evidence. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Multi-Person Kinship Reconstruction identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows preserved remains and multi-person kinship evidence through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-032",
    "case_number": "032",
    "slug": "/cases/032-bear-brook-genetic-genealogy/",
    "title": "Bear Brook: A Family Tree Reassembled from Unidentified Remains",
    "short_title": "Bear Brook Identifications",
    "summary": "The Bear Brook investigation shows how mitochondrial, autosomal, and genealogical evidence can reconstruct identities and family relationships across multiple victims and suspects—but also how one unresolved node can persist for years.",
    "direct_answer": "The Bear Brook investigation shows how mitochondrial, autosomal, and genealogical evidence can reconstruct identities and family relationships across multiple victims and suspects—but also how one unresolved node can persist for years.",
    "event_label": "1985–2025",
    "sector": "Law enforcement and forensic genetics",
    "event_type": "historical_case",
    "genetic_asset_type": "Preserved remains and multi-person kinship evidence",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "case032source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Multi-Person Kinship Reconstruction",
    "processing": "multiple remains → kinship testing → cross-case linkage → genealogy and records → phased identifications → renewed missing-person inquiry",
    "direct_parties": "The identified victims and connected family members",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "mitigations": "Long-term evidence preservation, interoperable case records, versioned kinship hypotheses, multidisciplinary review, confirmatory testing, and living-family support.",
    "limitations": "Genetic genealogy did not solve every factual question or establish every missing person's fate. Separate identity, relationship, and criminal attribution.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-032",
    "family_codes": [
      "LE"
    ],
    "family": "Law enforcement and forensic genetics",
    "primary_query": "Bear Brook genetic genealogy victims identified",
    "status": "historical_case",
    "jurisdictions": [
      "United States",
      "New Hampshire"
    ],
    "asset_classes": [
      "Preserved remains and multi-person kinship evidence"
    ],
    "threat_codes": [
      "Multi-Person Kinship Reconstruction"
    ],
    "imported": true,
    "threat_chain": [
      "multiple remains",
      "kinship testing",
      "cross-case linkage",
      "genealogy and records",
      "phased identifications",
      "renewed missing-person inquiry"
    ],
    "controls": [
      "long-term evidence preservation",
      "interoperable case records",
      "versioned kinship hypotheses",
      "multidisciplinary review",
      "confirmatory testing",
      "living-family support"
    ],
    "does_not_prove": [
      "Genetic genealogy did not solve every factual question or establish every missing person's fate. Separate identity, relationship, and criminal attribution."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Bear Brook involved relationships among multiple people and links across investigative records. Identification occurred in stages, so the meaning of an older account depends on when it was written. The New Hampshire source listed below records the later identification of the final previously unidentified child.",
          "The case separates three questions that are easily confused: who a person was, how people were related, and who was responsible for a crime. Evidence supporting one conclusion does not automatically establish the others. Preserved material and versioned hypotheses make it possible to revisit an unresolved relationship without treating an earlier inference as permanent fact."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity/provenance critical; consent unavailable; confidentiality relational; availability of old evidence decisive.",
    "proposed_score_notes": "Suggested GER: GER-3. Suggested GPR: GPR-4. Suggested GPI: GPI-4.",
    "clusters": [
      "Genealogy governance"
    ],
    "related_case_ids": [
      "GS-CASE-002",
      "GS-CASE-006",
      "GS-CASE-012",
      "GS-CASE-030"
    ],
    "related_comparisons": [
      {
        "case_number": "002",
        "text": "Compare Golden State Killer for kinship leakage. This case focuses on multi-person kinship reconstruction."
      },
      {
        "case_number": "006",
        "text": "Compare GEDmatch for governance as a security control. This case focuses on multi-person kinship reconstruction."
      },
      {
        "case_number": "012",
        "text": "Compare GEDmatch 2020 Permissions Breach for consent-state integrity. This case focuses on multi-person kinship reconstruction."
      },
      {
        "case_number": "030",
        "text": "Compare FamilyTreeDNA And FBI Matching for material policy change. This case focuses on multi-person kinship reconstruction."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Bear Brook involved relationships among multiple people and links across investigative records. Identification occurred in stages, so the meaning of an older account depends on when it was written. The New Hampshire source listed below records the later identification of the final previously unidentified child.",
          "The case separates three questions that are easily confused: who a person was, how people were related, and who was responsible for a crime. Evidence supporting one conclusion does not automatically establish the others. Preserved material and versioned hypotheses make it possible to revisit an unresolved relationship without treating an earlier inference as permanent fact."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Idaho",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "crime-scene DNA",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns crime-scene dna and genealogical leads. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Genetic Evidence as Corrective Control identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows crime-scene dna and genealogical leads through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-033",
    "case_number": "033",
    "slug": "/cases/033-angie-dodge-genetic-genealogy-exoneration/",
    "title": "Angie Dodge: Genetic Genealogy Found a Suspect—and Helped Clear the Wrong Man",
    "short_title": "Angie Dodge / Christopher Tapp",
    "summary": "The Angie Dodge case demonstrates that genetic genealogy can do more than generate arrests: when integrated with exclusionary DNA and case review, it can help expose a wrongful conviction and identify a different perpetrator.",
    "direct_answer": "The Angie Dodge case demonstrates that genetic genealogy can do more than generate arrests: when integrated with exclusionary DNA and case review, it can help expose a wrongful conviction and identify a different perpetrator.",
    "event_label": "1996–2021",
    "sector": "Law enforcement and forensic genetics",
    "event_type": "historical_case",
    "genetic_asset_type": "Crime-scene DNA and genealogical leads",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case033source1",
      "case033source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Genetic Evidence as Corrective Control",
    "processing": "crime-scene DNA → exclusion ignored or rationalized → wrongful conviction → renewed testing/genealogy → family lead → direct confirmation → exoneration and new prosecution",
    "direct_parties": "The victim, wrongly convicted person, and people involved in investigative leads",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.",
    "mitigations": "Mandatory confirmatory testing, documented elimination criteria, independent case review, disclosure of probabilistic leads, avoidance of tunnel vision, and preservation of exculpatory evidence.",
    "limitations": "Genetic genealogy is neither inherently exonerating nor inherently accusatory. It produces leads whose value depends on disciplined confirmation and willingness to revisit prior theories.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-033",
    "family_codes": [
      "LE"
    ],
    "family": "Law enforcement and forensic genetics",
    "primary_query": "Angie Dodge genetic genealogy Christopher Tapp exoneration",
    "status": "historical_case",
    "jurisdictions": [
      "United States",
      "Idaho"
    ],
    "asset_classes": [
      "Crime-scene DNA and genealogical leads"
    ],
    "threat_codes": [
      "Genetic Evidence as Corrective Control"
    ],
    "imported": true,
    "threat_chain": [
      "crime-scene DNA",
      "exclusion ignored or rationalized",
      "wrongful conviction",
      "renewed testing/genealogy",
      "family lead",
      "direct confirmation",
      "exoneration and new prosecution"
    ],
    "controls": [
      "mandatory confirmatory testing",
      "documented elimination criteria",
      "independent case review",
      "disclosure of probabilistic leads",
      "avoidance of tunnel vision",
      "preservation of exculpatory evidence"
    ],
    "does_not_prove": [
      "Genetic genealogy is neither inherently exonerating nor inherently accusatory. It produces leads whose value depends on disciplined confirmation and willingness to revisit prior theories."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Angie Dodge case brings exclusionary evidence into the foreground. A genetic lead can help redirect an investigation, but its corrective value depends on investigators being willing to reconsider an existing account. A mismatch should not be made to disappear simply because it conflicts with a favored theory.",
          "The later genealogy work belongs within a wider process of testing and confirmation. A relative lead can point in the wrong direction if it is treated as identification. This case therefore supports both the usefulness of genetic evidence and the need to preserve elimination criteria, contrary evidence, and independent review."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity critical; provenance high; confidentiality high; consent absent for searched relatives; availability of preserved evidence critical.",
    "proposed_score_notes": "Suggested GER: GER-3. Suggested GPR: GPR-4. Suggested GPI: GPI-4.",
    "clusters": [
      "Genealogy governance"
    ],
    "related_case_ids": [
      "GS-CASE-002",
      "GS-CASE-006",
      "GS-CASE-012",
      "GS-CASE-030"
    ],
    "related_comparisons": [
      {
        "case_number": "002",
        "text": "Compare Golden State Killer for kinship leakage. This case focuses on genetic evidence as corrective control."
      },
      {
        "case_number": "006",
        "text": "Compare GEDmatch for governance as a security control. This case focuses on genetic evidence as corrective control."
      },
      {
        "case_number": "012",
        "text": "Compare GEDmatch 2020 Permissions Breach for consent-state integrity. This case focuses on genetic evidence as corrective control."
      },
      {
        "case_number": "030",
        "text": "Compare FamilyTreeDNA And FBI Matching for material policy change. This case focuses on genetic evidence as corrective control."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Angie Dodge case brings exclusionary evidence into the foreground. A genetic lead can help redirect an investigation, but its corrective value depends on investigators being willing to reconsider an existing account. A mismatch should not be made to disappear simply because it conflicts with a favored theory.",
          "The later genealogy work belongs within a wider process of testing and confirmation. A relative lead can point in the wrong direction if it is treated as identification. This case therefore supports both the usefulness of genetic evidence and the need to preserve elimination criteria, contrary evidence, and independent review."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Europe",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "manufacturing contamination",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Permission to analyze material does not resolve whether the material, identity, or interpretation is correct. This case focuses on those evidentiary boundaries.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns collection swabs and contaminating dna. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Collection-Supply-Chain Contamination identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows collection swabs and contaminating dna through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-034",
    "case_number": "034",
    "slug": "/cases/034-phantom-heilbronn-dna-contamination/",
    "title": "The Phantom of Heilbronn: A Serial Killer Manufactured by Cotton Swabs",
    "short_title": "The Phantom Of Heilbronn",
    "summary": "For years, the same female DNA profile appeared across unrelated European crime scenes. The apparent serial offender was ultimately traced to contamination associated with swabs that were sterile for microbes but not certified DNA-free.",
    "direct_answer": "For years, the same female DNA profile appeared across unrelated European crime scenes. The apparent serial offender was ultimately traced to contamination associated with swabs that were sterile for microbes but not certified DNA-free.",
    "event_label": "1990s–2009",
    "sector": "Integrity, provenance, and laboratory failure",
    "event_type": "historical_case",
    "genetic_asset_type": "Collection swabs and contaminating DNA",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case034source1",
      "case034source2"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Collection-Supply-Chain Contamination",
    "processing": "manufacturing contamination → evidence swab → repeated profile → false cross-case linkage → investigative escalation → provenance failure discovered",
    "direct_parties": "People affected by false cross-case connections",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Permission to analyze material does not resolve whether the material, identity, or interpretation is correct. This case focuses on those evidentiary boundaries.",
    "mitigations": "Forensic-grade consumables, elimination databases with safeguards, batch traceability, blanks/controls, contamination monitoring, anomaly detection, and skepticism toward impossible geographic patterns.",
    "limitations": "It does not show DNA profiling is useless. It shows that high analytical specificity cannot rescue contaminated collection materials.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-034",
    "family_codes": [
      "IN",
      "LE"
    ],
    "family": "Integrity, provenance, and laboratory failure",
    "primary_query": "Phantom of Heilbronn contaminated DNA swabs",
    "status": "historical_case",
    "jurisdictions": [
      "Europe"
    ],
    "asset_classes": [
      "Collection swabs and contaminating DNA"
    ],
    "threat_codes": [
      "Collection-Supply-Chain Contamination"
    ],
    "imported": true,
    "threat_chain": [
      "manufacturing contamination",
      "evidence swab",
      "repeated profile",
      "false cross-case linkage",
      "investigative escalation",
      "provenance failure discovered"
    ],
    "controls": [
      "forensic-grade consumables",
      "elimination databases with safeguards",
      "batch traceability",
      "blanks/controls",
      "contamination monitoring",
      "anomaly detection",
      "skepticism toward impossible geographic patterns"
    ],
    "does_not_prove": [
      "It does not show DNA profiling is useless. It shows that high analytical specificity cannot rescue contaminated collection materials."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Phantom of Heilbronn appeared to connect otherwise unrelated scenes through a recurring profile. The explanation lay upstream of the investigations, in contamination associated with collection materials. The apparent pattern was produced by the evidence supply chain rather than a person traveling between all the scenes.",
          "Sterility for one purpose does not establish suitability for every forensic use. A highly specific analytical result can still describe contamination rather than the event under investigation. Batch records, blanks, and review of implausible patterns help connect a reported match to the circumstances in which the trace was collected."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity critical; provenance catastrophic; confidentiality concerns for the worker; availability wasted; consent irrelevant.",
    "proposed_score_notes": "Suggested GER: GER-0 for the contaminant's biology but operational blast radius multi-case. Suggested GPR: GPR-2/3. Suggested GPI: GPI-0/1.",
    "clusters": [
      "Forensic integrity"
    ],
    "related_case_ids": [
      "GS-CASE-035",
      "GS-CASE-036"
    ],
    "related_comparisons": [
      {
        "case_number": "035",
        "text": "Compare Adam Scott / LGC Forensics Contamination for workflow carryover and contextual review. This case focuses on collection-supply-chain contamination."
      },
      {
        "case_number": "036",
        "text": "Compare Lukis Anderson And Secondary DNA Transfer for presence of dna is not proof of presence. This case focuses on collection-supply-chain contamination."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Phantom of Heilbronn appeared to connect otherwise unrelated scenes through a recurring profile. The explanation lay upstream of the investigations, in contamination associated with collection materials. The apparent pattern was produced by the evidence supply chain rather than a person traveling between all the scenes.",
          "Sterility for one purpose does not establish suitability for every forensic use. A highly specific analytical result can still describe contamination rather than the event under investigation. Batch records, blanks, and review of implausible patterns help connect a reported match to the circumstances in which the trace was collected."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United Kingdom",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "prior sample",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Permission to analyze material does not resolve whether the material, identity, or interpretation is correct. This case focuses on those evidentiary boundaries.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns laboratory samples and a misleading partial profile. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Workflow Carryover and Contextual Review identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows laboratory samples and a misleading partial profile through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-035",
    "case_number": "035",
    "slug": "/cases/035-adam-scott-dna-laboratory-contamination/",
    "title": "Adam Scott: The DNA Match Created Inside the Laboratory",
    "short_title": "Adam Scott / LGC Forensics Contamination",
    "summary": "Adam Scott was wrongly charged with rape after contamination during laboratory processing produced a misleading partial DNA profile. The failure was compounded because evidence inconsistent with the alleged geography was not treated as a stop signal soon enough.",
    "direct_answer": "Adam Scott was wrongly charged with rape after contamination during laboratory processing produced a misleading partial DNA profile. The failure was compounded because evidence inconsistent with the alleged geography was not treated as a stop signal soon enough.",
    "event_label": "2011–2012",
    "sector": "Integrity, provenance, and laboratory failure",
    "event_type": "historical_case",
    "genetic_asset_type": "Laboratory samples and a misleading partial profile",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "case035source1"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Workflow Carryover and Contextual Review",
    "processing": "prior sample → reused contaminated tray/component → partial profile → database match → charge and detention → contradiction review → error discovery",
    "direct_parties": "Adam Scott and the people in the investigation",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Permission to analyze material does not resolve whether the material, identity, or interpretation is correct. This case focuses on those evidentiary boundaries.",
    "mitigations": "Single-use enforcement, physical workflow separation, negative controls, batch reconstruction, geographic/contextual plausibility checks, no-charge-on-DNA-alone policy, and rapid escalation of anomalies.",
    "limitations": "A DNA match alone did not establish presence at the crime scene, and the case does not establish malicious misconduct. Follow the regulator's findings.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-035",
    "family_codes": [
      "IN",
      "LE"
    ],
    "family": "Integrity, provenance, and laboratory failure",
    "primary_query": "Adam Scott DNA contamination LGC Forensics",
    "status": "historical_case",
    "jurisdictions": [
      "United Kingdom"
    ],
    "asset_classes": [
      "Laboratory samples and a misleading partial profile"
    ],
    "threat_codes": [
      "Workflow Carryover and Contextual Review"
    ],
    "imported": true,
    "threat_chain": [
      "prior sample",
      "reused contaminated tray/component",
      "partial profile",
      "database match",
      "charge and detention",
      "contradiction review",
      "error discovery"
    ],
    "controls": [
      "single-use enforcement",
      "physical workflow separation",
      "negative controls",
      "batch reconstruction",
      "geographic/contextual plausibility checks",
      "no-charge-on-DNA-alone policy",
      "rapid escalation of anomalies"
    ],
    "does_not_prove": [
      "A DNA match alone did not establish presence at the crime scene, and the case does not establish malicious misconduct. Follow the regulator's findings."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Adam Scott case locates the failure inside laboratory processing. Carryover produced a misleading partial profile, which acquired weight when it was treated as evidence of a person's presence. The regulator's report is the central source for the process failure and the missed opportunities to investigate it.",
          "A match should not override incompatible contextual evidence without examination. Reconstructing the batch and handling history can be as important as repeating the final analysis. The case connects consumable use, contamination controls, and escalation procedures to a concrete consequence for the person wrongly implicated."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity critical; provenance critical; availability of audit records crucial; confidentiality moderate.",
    "proposed_score_notes": "Suggested GER: GER-0. Suggested GPR: GPR-2. Suggested GPI: GPI-0/1.",
    "clusters": [
      "Forensic integrity"
    ],
    "related_case_ids": [
      "GS-CASE-034",
      "GS-CASE-036"
    ],
    "related_comparisons": [
      {
        "case_number": "034",
        "text": "Compare The Phantom Of Heilbronn for collection-supply-chain contamination. This case focuses on workflow carryover and contextual review."
      },
      {
        "case_number": "036",
        "text": "Compare Lukis Anderson And Secondary DNA Transfer for presence of dna is not proof of presence. This case focuses on workflow carryover and contextual review."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Adam Scott case locates the failure inside laboratory processing. Carryover produced a misleading partial profile, which acquired weight when it was treated as evidence of a person's presence. The regulator's report is the central source for the process failure and the missed opportunities to investigate it.",
          "A match should not override incompatible contextual evidence without examination. Reconstructing the batch and handling history can be as important as repeating the final analysis. The case connects consumable use, contamination controls, and escalation procedures to a concrete consequence for the person wrongly implicated."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / California",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "medical contact",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Permission to analyze material does not resolve whether the material, identity, or interpretation is correct. This case focuses on those evidentiary boundaries.",
    "law_enforcement": true,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns transferred biological traces and a dna profile. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Presence of DNA Is Not Proof of Presence identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows transferred biological traces and a dna profile through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-036",
    "case_number": "036",
    "slug": "/cases/036-lukis-anderson-secondary-dna-transfer/",
    "title": "Lukis Anderson: How Paramedics Carried DNA to a Murder Scene",
    "short_title": "Lukis Anderson And Secondary DNA Transfer",
    "summary": "Lukis Anderson's DNA appeared on a homicide victim even though hospital records placed him elsewhere. Investigators concluded that paramedics likely transferred his DNA after treating him and later responding to the victim, demonstrating the danger of secondary transfer.",
    "direct_answer": "Lukis Anderson's DNA appeared on a homicide victim even though hospital records placed him elsewhere. Investigators concluded that paramedics likely transferred his DNA after treating him and later responding to the victim, demonstrating the danger of secondary transfer.",
    "event_label": "2012–2013",
    "sector": "Integrity, provenance, and laboratory failure",
    "event_type": "historical_case",
    "genetic_asset_type": "Transferred biological traces and a DNA profile",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 0,
    "sources": [
      "case036source1"
    ],
    "parent_hub": "/threats/",
    "security_principle": "Presence of DNA Is Not Proof of Presence",
    "processing": "medical contact → DNA on responder/equipment → later crime-scene contact → trace recovery → database match → false implication",
    "direct_parties": "Lukis Anderson and people in the homicide investigation",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Permission to analyze material does not resolve whether the material, identity, or interpretation is correct. This case focuses on those evidentiary boundaries.",
    "mitigations": "Activity-level propositions, transfer-aware collection protocols, responder/equipment logs, contextual corroboration, elimination testing with safeguards, and mandatory review of hard alibis.",
    "limitations": "Secondary transfer does not explain every disputed trace. It is a hypothesis requiring timing, quantity, substrate, and activity-level evaluation.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-036",
    "family_codes": [
      "IN",
      "LE"
    ],
    "family": "Integrity, provenance, and laboratory failure",
    "primary_query": "Lukis Anderson secondary DNA transfer case",
    "status": "historical_case",
    "jurisdictions": [
      "United States",
      "California"
    ],
    "asset_classes": [
      "Transferred biological traces and a DNA profile"
    ],
    "threat_codes": [
      "Presence of DNA Is Not Proof of Presence"
    ],
    "imported": true,
    "threat_chain": [
      "medical contact",
      "DNA on responder/equipment",
      "later crime-scene contact",
      "trace recovery",
      "database match",
      "false implication"
    ],
    "controls": [
      "activity-level propositions",
      "transfer-aware collection protocols",
      "responder/equipment logs",
      "contextual corroboration",
      "elimination testing with safeguards",
      "mandatory review of hard alibis"
    ],
    "does_not_prove": [
      "Secondary transfer does not explain every disputed trace. It is a hypothesis requiring timing, quantity, substrate, and activity-level evaluation."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Lukis Anderson's case concerns the route by which DNA can arrive at a location. The reported secondary-transfer explanation involved medical responders who had contact with him and later with the victim. Hospital records supplied important evidence against the inference that he had been present at the crime.",
          "The distinction is between identifying a trace and explaining an activity. Those are not the same conclusion. Secondary transfer is one possible account that needs evidence about timing and contact; it should not become a universal explanation for every disputed result."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity of interpretation critical; provenance critical; confidentiality moderate; availability of hospital records exculpatory.",
    "proposed_score_notes": "Suggested GER: GER-0. Suggested GPR: GPR-2. Suggested GPI: GPI-1.",
    "clusters": [
      "Forensic integrity"
    ],
    "related_case_ids": [
      "GS-CASE-034",
      "GS-CASE-035"
    ],
    "related_comparisons": [
      {
        "case_number": "034",
        "text": "Compare The Phantom Of Heilbronn for collection-supply-chain contamination. This case focuses on presence of dna is not proof of presence."
      },
      {
        "case_number": "035",
        "text": "Compare Adam Scott / LGC Forensics Contamination for workflow carryover and contextual review. This case focuses on presence of dna is not proof of presence."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Lukis Anderson's case concerns the route by which DNA can arrive at a location. The reported secondary-transfer explanation involved medical responders who had contact with him and later with the victim. Hospital records supplied important evidence against the inference that he had been present at the crime.",
          "The distinction is between identifying a trace and explaining an activity. Those are not the same conclusion. Secondary transfer is one possible account that needs evidence about timing and contact; it should not become a universal explanation for every disputed result."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "injury claim",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The employment relationship can constrain a person’s choice. A general medical examination does not explain or authorize every genetic-information request.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns employee samples and hereditary-condition testing. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Genetic Testing as Institutional Power identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows employee samples and hereditary-condition testing through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-037",
    "case_number": "037",
    "slug": "/cases/037-bnsf-secret-employee-genetic-testing/",
    "title": "BNSF: Secret Genetic Testing in a Workplace Injury Program",
    "short_title": "Burlington Northern Santa Fe Genetic Testing",
    "summary": "BNSF tested or sought to test employees pursuing carpal-tunnel injury claims for a hereditary condition without adequate knowledge or consent, producing an early landmark enforcement action against workplace genetic testing.",
    "direct_answer": "BNSF tested or sought to test employees pursuing carpal-tunnel injury claims for a hereditary condition without adequate knowledge or consent, producing an early landmark enforcement action against workplace genetic testing.",
    "event_label": "2001–2002",
    "sector": "Discrimination and institutional use",
    "event_type": "enforcement_action",
    "genetic_asset_type": "Employee samples and hereditary-condition testing",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 2,
    "sources": [
      "case037source1",
      "case037source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Genetic Testing as Institutional Power",
    "processing": "injury claim → employer-directed medical exam → undisclosed genetic test → liability narrative → employee resistance → enforcement and settlement",
    "direct_parties": "Employees included in the testing dispute",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "The employment relationship can constrain a person’s choice. A general medical examination does not explain or authorize every genetic-information request.",
    "mitigations": "Purpose-specific consent, separation of occupational health from claims investigation, no genetic testing absent lawful necessity, disclosure of test names, restricted results, deletion, and anti-retaliation safeguards.",
    "limitations": "The settlement did not adjudicate every disputed fact, and the tested variant was not a simple “carpal tunnel gene.”",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-037",
    "family_codes": [
      "DI"
    ],
    "family": "Discrimination and institutional use",
    "primary_query": "Burlington Northern secret genetic testing employees",
    "status": "enforcement_action",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Employee samples and hereditary-condition testing"
    ],
    "threat_codes": [
      "Genetic Testing as Institutional Power"
    ],
    "imported": true,
    "threat_chain": [
      "injury claim",
      "employer-directed medical exam",
      "undisclosed genetic test",
      "liability narrative",
      "employee resistance",
      "enforcement and settlement"
    ],
    "controls": [
      "purpose-specific consent",
      "separation of occupational health from claims investigation",
      "no genetic testing absent lawful necessity",
      "disclosure of test names",
      "restricted results",
      "deletion",
      "anti-retaliation safeguards"
    ],
    "does_not_prove": [
      "The settlement did not adjudicate every disputed fact, and the tested variant was not a simple “carpal tunnel gene.”"
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The BNSF matter placed genetic testing inside an employment-related medical process. The dispute concerned what employees understood about the examination and how test information could serve an institutional interest beyond their immediate care. The EEOC action preceded GINA and arose under the ADA.",
          "An examination's general label does not explain every assay performed within it. Clear test names, purposes, recipients, and retention rules make the actual information flow visible. The settlement is evidence of agreed enforcement relief, not an adjudication of every disputed allegation."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity moderate; consent critical; discrimination high; persistence high.",
    "proposed_score_notes": "Suggested GER: GER-1. Suggested GPR: GPR-4. Suggested GPI: GPI-3 if testing records survive.",
    "clusters": [
      "Employment genetics"
    ],
    "related_case_ids": [
      "GS-CASE-038",
      "GS-CASE-039",
      "GS-CASE-040"
    ],
    "related_comparisons": [
      {
        "case_number": "038",
        "text": "Compare Lowe v. Atlas Logistics for genetic protection is not limited to disease risk. This case focuses on genetic testing as institutional power."
      },
      {
        "case_number": "039",
        "text": "Compare Fabricut And The First EEOC GINA Settlement for family history is genetic information. This case focuses on genetic testing as institutional power."
      },
      {
        "case_number": "040",
        "text": "Compare Norman-Bloodsaw v. Lawrence Berkeley Laboratory for general consent is not specific consent. This case focuses on genetic testing as institutional power."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The BNSF matter placed genetic testing inside an employment-related medical process. The dispute concerned what employees understood about the examination and how test information could serve an institutional interest beyond their immediate care. The EEOC action preceded GINA and arose under the ADA.",
          "An examination's general label does not explain every assay performed within it. Clear test names, purposes, recipients, and retention rules make the actual information flow visible. The settlement is evidence of agreed enforcement relief, not an adjudication of every disputed allegation."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Georgia",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "workplace misconduct",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The employment relationship can constrain a person’s choice. A general medical examination does not explain or authorize every genetic-information request.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns employee cheek swabs and identity comparisons. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Genetic Protection Is Not Limited to Disease Risk identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows employee cheek swabs and identity comparisons through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-038",
    "case_number": "038",
    "slug": "/cases/038-atlas-logistics-employee-dna-testing/",
    "title": "The Devious Defecator Case: GINA Covers Identification DNA Too",
    "short_title": "Lowe v. Atlas Logistics",
    "summary": "Atlas Logistics asked employees for cheek swabs to identify who was repeatedly defecating in a warehouse. A court held that GINA's genetic-testing protections were not limited to medical-predisposition tests, and a jury awarded substantial damages.",
    "direct_answer": "Atlas Logistics asked employees for cheek swabs to identify who was repeatedly defecating in a warehouse. A court held that GINA's genetic-testing protections were not limited to medical-predisposition tests, and a jury awarded substantial damages.",
    "event_label": "2015",
    "sector": "Discrimination and institutional use",
    "event_type": "court_case",
    "genetic_asset_type": "Employee cheek swabs and identity comparisons",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 1,
    "sources": [
      "case038source1"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Genetic Protection Is Not Limited to Disease Risk",
    "processing": "workplace misconduct → compelled/requested cheek swabs → identity comparison → genetic-information acquisition → civil litigation",
    "direct_parties": "Employees asked to provide DNA during the workplace investigation",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "The employment relationship can constrain a person’s choice. A general medical examination does not explain or authorize every genetic-information request.",
    "mitigations": "Legal review, non-genetic investigative methods, voluntariness analysis, data minimization, prompt destruction, and prohibition on acquiring genetic information merely because it seems evidentially convenient.",
    "limitations": "The decision should not be treated as a universal rule for every employer interaction with DNA; the statutory context and exceptions matter.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-038",
    "family_codes": [
      "DI"
    ],
    "family": "Discrimination and institutional use",
    "primary_query": "devious defecator DNA testing GINA case",
    "status": "court_case",
    "jurisdictions": [
      "United States",
      "Georgia"
    ],
    "asset_classes": [
      "Employee cheek swabs and identity comparisons"
    ],
    "threat_codes": [
      "Genetic Protection Is Not Limited to Disease Risk"
    ],
    "imported": true,
    "threat_chain": [
      "workplace misconduct",
      "compelled/requested cheek swabs",
      "identity comparison",
      "genetic-information acquisition",
      "civil litigation"
    ],
    "controls": [
      "legal review",
      "non-genetic investigative methods",
      "voluntariness analysis",
      "data minimization",
      "prompt destruction",
      "prohibition on acquiring genetic information merely because it seems evidentially convenient"
    ],
    "does_not_prove": [
      "The decision should not be treated as a universal rule for every employer interaction with DNA; the statutory context and exceptions matter."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Atlas Logistics sought DNA comparisons during a workplace investigation. The case challenged the assumption that a test used for identity, rather than disease prediction, necessarily falls outside genetic-information protections.",
          "The employment context matters because a request can carry pressure even when it is presented as cooperation. The legal analysis should remain tied to the statute and the court's decision. For institutional design, the question is whether obtaining genetic information is justified at all, not merely whether the organization can keep the resulting file secure."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; consent compromised by employment power; discrimination/statutory impact critical; persistence moderate/high.",
    "proposed_score_notes": "Suggested GER: GER-0/1. Suggested GPR: GPR-3. Suggested GPI: GPI-3.",
    "clusters": [
      "Employment genetics"
    ],
    "related_case_ids": [
      "GS-CASE-037",
      "GS-CASE-039",
      "GS-CASE-040"
    ],
    "related_comparisons": [
      {
        "case_number": "037",
        "text": "Compare Burlington Northern Santa Fe Genetic Testing for genetic testing as institutional power. This case focuses on genetic protection is not limited to disease risk."
      },
      {
        "case_number": "039",
        "text": "Compare Fabricut And The First EEOC GINA Settlement for family history is genetic information. This case focuses on genetic protection is not limited to disease risk."
      },
      {
        "case_number": "040",
        "text": "Compare Norman-Bloodsaw v. Lawrence Berkeley Laboratory for general consent is not specific consent. This case focuses on genetic protection is not limited to disease risk."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Atlas Logistics sought DNA comparisons during a workplace investigation. The case challenged the assumption that a test used for identity, rather than disease prediction, necessarily falls outside genetic-information protections.",
          "The employment context matters because a request can carry pressure even when it is presented as cooperation. The legal analysis should remain tied to the statute and the court's decision. For institutional design, the question is whether obtaining genetic information is justified at all, not merely whether the organization can keep the resulting file secure."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Oklahoma",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "conditional job offer",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The employment relationship can constrain a person’s choice. A general medical examination does not explain or authorize every genetic-information request.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns family medical history in a medical examination. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Family History Is Genetic Information identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows family medical history in a medical examination through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-039",
    "case_number": "039",
    "slug": "/cases/039-fabricut-first-eeoc-gina-settlement/",
    "title": "Fabricut: Family Medical History Entered the Hiring Room",
    "short_title": "Fabricut And The First EEOC GINA Settlement",
    "summary": "The EEOC's 2013 Fabricut settlement—widely described as its first GINA lawsuit—showed that employers can violate genetic-information rules by requesting family medical history during pre-employment medical evaluation, even without sequencing DNA.",
    "direct_answer": "The EEOC's 2013 Fabricut settlement—widely described as its first GINA lawsuit—showed that employers can violate genetic-information rules by requesting family medical history during pre-employment medical evaluation, even without sequencing DNA.",
    "event_label": "2013",
    "sector": "Discrimination and institutional use",
    "event_type": "enforcement_action",
    "genetic_asset_type": "Family medical history in a medical examination",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 1,
    "sources": [
      "case039source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Family History Is Genetic Information",
    "processing": "conditional job offer → medical questionnaire → family history acquisition → hiring decision context → EEOC action",
    "direct_parties": "The applicant and relatives described in the history",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "The employment relationship can constrain a person’s choice. A general medical examination does not explain or authorize every genetic-information request.",
    "mitigations": "Remove family-history questions, segregate occupational health records, train vendors, audit forms, restrict post-offer exams to job-related needs, and enforce no-use rules.",
    "limitations": "A settlement is not a trial finding. The allegations and agreed relief remain distinct.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-039",
    "family_codes": [
      "DI"
    ],
    "family": "Discrimination and institutional use",
    "primary_query": "first EEOC GINA lawsuit Fabricut",
    "status": "enforcement_action",
    "jurisdictions": [
      "United States",
      "Oklahoma"
    ],
    "asset_classes": [
      "Family medical history in a medical examination"
    ],
    "threat_codes": [
      "Family History Is Genetic Information"
    ],
    "imported": true,
    "threat_chain": [
      "conditional job offer",
      "medical questionnaire",
      "family history acquisition",
      "hiring decision context",
      "EEOC action"
    ],
    "controls": [
      "remove family-history questions",
      "segregate occupational health records",
      "train vendors",
      "audit forms",
      "restrict post-offer exams to job-related needs",
      "enforce no-use rules"
    ],
    "does_not_prove": [
      "A settlement is not a trial finding. The allegations and agreed relief remain distinct."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Fabricut demonstrates how genetic information can enter a hiring process through ordinary questions about relatives. No genome sequencing is required for a family medical history to disclose sensitive familial information. The EEOC matter also involved disability-discrimination allegations, which should be distinguished from the genetic-information issue.",
          "Forms and outside medical providers are part of an employer's information system. A policy against unnecessary genetic collection needs to reach the questionnaire used in practice. The settlement illustrates that governance boundary without turning the agreed resolution into a trial finding."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; consent constrained; discrimination critical; persistence moderate.",
    "proposed_score_notes": "Suggested GER: GER-1/2. Suggested GPR: GPR-2/3. GPI: not central.",
    "clusters": [
      "Employment genetics"
    ],
    "related_case_ids": [
      "GS-CASE-037",
      "GS-CASE-038",
      "GS-CASE-040"
    ],
    "related_comparisons": [
      {
        "case_number": "037",
        "text": "Compare Burlington Northern Santa Fe Genetic Testing for genetic testing as institutional power. This case focuses on family history is genetic information."
      },
      {
        "case_number": "038",
        "text": "Compare Lowe v. Atlas Logistics for genetic protection is not limited to disease risk. This case focuses on family history is genetic information."
      },
      {
        "case_number": "040",
        "text": "Compare Norman-Bloodsaw v. Lawrence Berkeley Laboratory for general consent is not specific consent. This case focuses on family history is genetic information."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Fabricut demonstrates how genetic information can enter a hiring process through ordinary questions about relatives. No genome sequencing is required for a family medical history to disclose sensitive familial information. The EEOC matter also involved disability-discrimination allegations, which should be distinguished from the genetic-information issue.",
          "Forms and outside medical providers are part of an employer's information system. A policy against unnecessary genetic collection needs to reach the questionnaire used in practice. The settlement illustrates that governance boundary without turning the agreed resolution into a trial finding."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / California",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "employment exam",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The employment relationship can constrain a person’s choice. A general medical examination does not explain or authorize every genetic-information request.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns employment-examination samples and undisclosed test results. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. General Consent Is Not Specific Consent identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows employment-examination samples and undisclosed test results through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-040",
    "case_number": "040",
    "slug": "/cases/040-norman-bloodsaw-secret-medical-genetic-tests/",
    "title": "Norman-Bloodsaw: The Tests Hidden Inside a Medical Exam",
    "short_title": "Norman-Bloodsaw v. Lawrence Berkeley Laboratory",
    "summary": "Employees and applicants alleged that Lawrence Berkeley Laboratory tested samples for conditions including sickle-cell trait, syphilis, and pregnancy without their knowledge. The Ninth Circuit recognized serious privacy interests in undisclosed testing.",
    "direct_answer": "Employees and applicants alleged that Lawrence Berkeley Laboratory tested samples for conditions including sickle-cell trait, syphilis, and pregnancy without their knowledge. The Ninth Circuit recognized serious privacy interests in undisclosed testing.",
    "event_label": "1998",
    "sector": "Discrimination and institutional use",
    "event_type": "court_case",
    "genetic_asset_type": "Employment-examination samples and undisclosed test results",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case040source1",
      "case040source2"
    ],
    "parent_hub": "/policy/",
    "security_principle": "General Consent Is Not Specific Consent",
    "processing": "employment exam → sample collection → undisclosed additional tests → sensitive inference → institutional records → litigation",
    "direct_parties": "Employees and applicants in the litigation",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "The employment relationship can constrain a person’s choice. A general medical examination does not explain or authorize every genetic-information request.",
    "mitigations": "Itemized test consent, purpose limitation, equal testing criteria, results segregation, retention limits, auditability, and a prohibition on silent secondary assays.",
    "limitations": "It is not a ruling that every occupational medical test is unlawful. Scope, notice, necessity, and constitutional/statutory context matter.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-040",
    "family_codes": [
      "DI",
      "CO"
    ],
    "family": "Discrimination and institutional use",
    "primary_query": "Norman Bloodsaw Lawrence Berkeley genetic testing",
    "status": "court_case",
    "jurisdictions": [
      "United States",
      "California"
    ],
    "asset_classes": [
      "Employment-examination samples and undisclosed test results"
    ],
    "threat_codes": [
      "General Consent Is Not Specific Consent"
    ],
    "imported": true,
    "threat_chain": [
      "employment exam",
      "sample collection",
      "undisclosed additional tests",
      "sensitive inference",
      "institutional records",
      "litigation"
    ],
    "controls": [
      "itemized test consent",
      "purpose limitation",
      "equal testing criteria",
      "results segregation",
      "retention limits",
      "auditability",
      "a prohibition on silent secondary assays"
    ],
    "does_not_prove": [
      "It is not a ruling that every occupational medical test is unlawful. Scope, notice, necessity, and constitutional/statutory context matter."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Norman-Bloodsaw concerned allegations that specimens supplied for an employment examination were used for undisclosed tests. The appellate decision recognized privacy interests that were not extinguished merely because a person had agreed to provide a sample.",
          "The tests at issue were not all genetic tests, and that distinction matters. Their connection in this case is the alleged hidden purpose. Itemized notice and a record of authorized assays make it possible to distinguish permission to collect material from permission to draw a particular conclusion from it."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality critical; integrity moderate; consent critical; discrimination high; persistence moderate/high.",
    "proposed_score_notes": "Suggested GER: GER-1. Suggested GPR: GPR-3. Suggested GPI: GPI-3.",
    "clusters": [
      "Employment genetics"
    ],
    "related_case_ids": [
      "GS-CASE-037",
      "GS-CASE-038",
      "GS-CASE-039"
    ],
    "related_comparisons": [
      {
        "case_number": "037",
        "text": "Compare Burlington Northern Santa Fe Genetic Testing for genetic testing as institutional power. This case focuses on general consent is not specific consent."
      },
      {
        "case_number": "038",
        "text": "Compare Lowe v. Atlas Logistics for genetic protection is not limited to disease risk. This case focuses on general consent is not specific consent."
      },
      {
        "case_number": "039",
        "text": "Compare Fabricut And The First EEOC GINA Settlement for family history is genetic information. This case focuses on general consent is not specific consent."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Norman-Bloodsaw concerned allegations that specimens supplied for an employment examination were used for undisclosed tests. The appellate decision recognized privacy interests that were not extinguished merely because a person had agreed to provide a sample.",
          "The tests at issue were not all genetic tests, and that distinction matters. Their connection in this case is the alleged hidden purpose. Itemized notice and a record of authorized assays make it possible to distinguish permission to collect material from permission to draw a particular conclusion from it."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "China",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "recruitment",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Consent depends on the intervention and the identity of the reproductive material. A substitution or undisclosed intervention changes what was authorized.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns edited embryos and associated research/oversight records. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Heritable-Edit Governance Failure identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows edited embryos and associated research/oversight records through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-041",
    "case_number": "041",
    "slug": "/cases/041-he-jiankui-crispr-babies-governance/",
    "title": "The CRISPR Babies: A Heritable Change Without a Trustworthy Control Plane",
    "short_title": "The He Jiankui CRISPR-Baby Experiment",
    "summary": "He Jiankui's embryo-editing experiment turned governance defects—questionable consent, forged or misleading oversight materials, premature clinical use, uncertain off-target effects, and heritable consequences—into permanent biological risk.",
    "direct_answer": "He Jiankui's embryo-editing experiment turned governance defects—questionable consent, forged or misleading oversight materials, premature clinical use, uncertain off-target effects, and heritable consequences—into permanent biological risk.",
    "event_label": "2018–2019",
    "sector": "Reproductive and heritable genetics",
    "event_type": "historical_case",
    "genetic_asset_type": "Edited embryos and associated research/oversight records",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case041source1",
      "case041source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Heritable-Edit Governance Failure",
    "processing": "recruitment → embryo editing → inadequate/invalid oversight → implantation → live births → permanent and potentially heritable uncertainty",
    "direct_parties": "Children born following the intervention and their families",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Consent depends on the intervention and the identity of the reproductive material. A substitution or undisclosed intervention changes what was authorized.",
    "mitigations": "Credible independent review, trial registration, validated preclinical evidence, consent comprehension, long-term welfare plans, identity protection, transparent assay provenance, and enforceable international norms.",
    "limitations": "It does not prove all human gene editing is unethical or that every claimed outcome is known. Separate somatic therapy from heritable embryo editing.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-041",
    "family_codes": [
      "RE"
    ],
    "family": "Reproductive and heritable genetics",
    "primary_query": "He Jiankui CRISPR babies ethics consent case",
    "status": "historical_case",
    "jurisdictions": [
      "China"
    ],
    "asset_classes": [
      "Edited embryos and associated research/oversight records"
    ],
    "threat_codes": [
      "Heritable-Edit Governance Failure"
    ],
    "imported": true,
    "threat_chain": [
      "recruitment",
      "embryo editing",
      "inadequate/invalid oversight",
      "implantation",
      "live births",
      "permanent and potentially heritable uncertainty"
    ],
    "controls": [
      "credible independent review",
      "trial registration",
      "validated preclinical evidence",
      "consent comprehension",
      "long-term welfare plans",
      "identity protection",
      "transparent assay provenance",
      "enforceable international norms"
    ],
    "does_not_prove": [
      "It does not prove all human gene editing is unethical or that every claimed outcome is known. Separate somatic therapy from heritable embryo editing."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The embryo-editing experiment joined scientific uncertainty with failures of oversight and consent. A heritable intervention creates a different governance problem from a software change: its consequences cannot be handled through a routine rollback, and the people most directly affected could not authorize the decision.",
          "The analysis should protect the children's privacy and avoid claiming that every long-term outcome is known. The case concerns a specific experiment and its governance, not a judgment that all gene editing is equivalent. Somatic treatment and heritable embryo editing require distinct descriptions of purpose, evidence, and affected parties."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity critical; provenance critical; consent critical; persistence maximal; availability not central; relational exposure intergenerational.",
    "proposed_score_notes": "Suggested GER: GER-1 initially, potentially generational. Suggested GPR: GPR-5. Suggested GPI: GPI-1/2 due to contested records and incomplete independent verification.",
    "clusters": [
      "Reproductive provenance"
    ],
    "related_case_ids": [
      "GS-CASE-042",
      "GS-CASE-043",
      "GS-CASE-044"
    ],
    "related_comparisons": [
      {
        "case_number": "042",
        "text": "Compare Donald Cline Fertility Fraud for reproductive provenance fraud. This case focuses on heritable-edit governance failure."
      },
      {
        "case_number": "043",
        "text": "Compare Jan Karbaat And The Dutch Donor Registry Failure for genetic auditability of reproductive systems. This case focuses on heritable-edit governance failure."
      },
      {
        "case_number": "044",
        "text": "Compare CHA Fertility Center Embryo Mix-Up for reproductive sample identity integrity. This case focuses on heritable-edit governance failure."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The embryo-editing experiment joined scientific uncertainty with failures of oversight and consent. A heritable intervention creates a different governance problem from a software change: its consequences cannot be handled through a routine rollback, and the people most directly affected could not authorize the decision.",
          "The analysis should protect the children's privacy and avoid claiming that every long-term outcome is known. The case concerns a specific experiment and its governance, not a judgment that all gene editing is equivalent. Somatic treatment and heritable embryo editing require distinct descriptions of purpose, evidence, and affected parties."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States / Indiana",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "promised donor insemination",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Consent depends on the intervention and the identity of the reproductive material. A substitution or undisclosed intervention changes what was authorized.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns reproductive material, clinic records, and genetic-relative matches. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Reproductive Provenance Fraud identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows reproductive material, clinic records, and genetic-relative matches through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-042",
    "case_number": "042",
    "slug": "/cases/042-donald-cline-fertility-fraud-genetic-genealogy/",
    "title": "Donald Cline: Genetic Genealogy Exposed a Hidden Biological Father",
    "short_title": "Donald Cline Fertility Fraud",
    "summary": "Consumer DNA matching helped donor-conceived people discover that fertility doctor Donald Cline had used his own sperm without patients' informed agreement, turning kinship databases into an audit mechanism for decades-old reproductive records.",
    "direct_answer": "Consumer DNA matching helped donor-conceived people discover that fertility doctor Donald Cline had used his own sperm without patients' informed agreement, turning kinship databases into an audit mechanism for decades-old reproductive records.",
    "event_label": "Historical treatment / later discoveries",
    "sector": "Reproductive and heritable genetics",
    "event_type": "historical_case",
    "genetic_asset_type": "Reproductive material, clinic records, and genetic-relative matches",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "case042source1",
      "case042source2"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Reproductive Provenance Fraud",
    "processing": "promised donor insemination → undisclosed substitution → births → decades of hidden kinship → consumer DNA matches → cluster detection → legal/policy response",
    "direct_parties": "Patients and donor-conceived people",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Consent depends on the intervention and the identity of the reproductive material. A substitution or undisclosed intervention changes what was authorized.",
    "mitigations": "Donor identity ledgers, dual witnessing, chain-of-custody, centralized donor limits, patient-accessible records, independent audits, and criminal/civil statutes tailored to reproductive fraud.",
    "limitations": "Genetic genealogy alone does not establish every act or date; documentary evidence and direct comparisons matter.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-042",
    "family_codes": [
      "RE",
      "RI"
    ],
    "family": "Reproductive and heritable genetics",
    "primary_query": "Donald Cline fertility fraud DNA genealogy",
    "status": "historical_case",
    "jurisdictions": [
      "United States",
      "Indiana"
    ],
    "asset_classes": [
      "Reproductive material, clinic records, and genetic-relative matches"
    ],
    "threat_codes": [
      "Reproductive Provenance Fraud"
    ],
    "imported": true,
    "threat_chain": [
      "promised donor insemination",
      "undisclosed substitution",
      "births",
      "decades of hidden kinship",
      "consumer DNA matches",
      "cluster detection",
      "legal/policy response"
    ],
    "controls": [
      "donor identity ledgers",
      "dual witnessing",
      "chain-of-custody",
      "centralized donor limits",
      "patient-accessible records",
      "independent audits",
      "criminal/civil statutes tailored to reproductive fraud"
    ],
    "does_not_prove": [
      "Genetic genealogy alone does not establish every act or date; documentary evidence and direct comparisons matter."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Unexpected genetic-relative matches helped expose relationships that clinical representations had concealed. The Cline case makes reproductive provenance tangible: records about the source of reproductive material can shape a person's understanding of family for decades.",
          "Genetic comparisons are an important audit mechanism, but they do not independently establish every date, act, or clinical conversation. Documentary evidence remains relevant. The security lesson connects donor identity, custody, and truthful records with the lasting consequences of substitution, without relying on changing or speculative counts of relatives."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity/provenance critical; consent critical; confidentiality complex; persistence maximal; relational exposure high.",
    "proposed_score_notes": "Suggested GER: GER-3. Suggested GPR: GPR-5. Suggested GPI: GPI-0 for clinic provenance, later raised by direct testing.",
    "clusters": [
      "Reproductive provenance"
    ],
    "related_case_ids": [
      "GS-CASE-041",
      "GS-CASE-043",
      "GS-CASE-044"
    ],
    "related_comparisons": [
      {
        "case_number": "041",
        "text": "Compare The He Jiankui CRISPR-Baby Experiment for heritable-edit governance failure. This case focuses on reproductive provenance fraud."
      },
      {
        "case_number": "043",
        "text": "Compare Jan Karbaat And The Dutch Donor Registry Failure for genetic auditability of reproductive systems. This case focuses on reproductive provenance fraud."
      },
      {
        "case_number": "044",
        "text": "Compare CHA Fertility Center Embryo Mix-Up for reproductive sample identity integrity. This case focuses on reproductive provenance fraud."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Unexpected genetic-relative matches helped expose relationships that clinical representations had concealed. The Cline case makes reproductive provenance tangible: records about the source of reproductive material can shape a person's understanding of family for decades.",
          "Genetic comparisons are an important audit mechanism, but they do not independently establish every date, act, or clinical conversation. Documentary evidence remains relevant. The security lesson connects donor identity, custody, and truthful records with the lasting consequences of substitution, without relying on changing or speculative counts of relatives."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Netherlands",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "clinic donor process",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Consent depends on the intervention and the identity of the reproductive material. A substitution or undisclosed intervention changes what was authorized.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns donor records and genetic kinship evidence. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Genetic Auditability of Reproductive Systems identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows donor records and genetic kinship evidence through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-043",
    "case_number": "043",
    "slug": "/cases/043-jan-karbaat-fertility-dna-case/",
    "title": "Jan Karbaat: The Clinic Records Said Donor; DNA Said Doctor",
    "short_title": "Jan Karbaat And The Dutch Donor Registry Failure",
    "summary": "DNA comparisons indicated that Dutch fertility doctor Jan Karbaat fathered numerous children conceived at his clinic, illustrating how genetic matching can expose hidden substitution and systemic donor-record failures decades later.",
    "direct_answer": "DNA comparisons indicated that Dutch fertility doctor Jan Karbaat fathered numerous children conceived at his clinic, illustrating how genetic matching can expose hidden substitution and systemic donor-record failures decades later.",
    "event_label": "Historical treatment / later comparisons",
    "sector": "Reproductive and heritable genetics",
    "event_type": "historical_case",
    "genetic_asset_type": "Donor records and genetic kinship evidence",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 0,
    "sources": [
      "case043source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Genetic Auditability of Reproductive Systems",
    "processing": "clinic donor process → undisclosed provider substitution → fragmented records → consumer testing → sibling network → court-ordered comparison → system reform",
    "direct_parties": "Patients and donor-conceived people",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Consent depends on the intervention and the identity of the reproductive material. A substitution or undisclosed intervention changes what was authorized.",
    "mitigations": "National donor registries, hard offspring limits, cross-clinic deduplication, immutable provenance, audit sampling, recipient access rights, and long retention of reproductive records.",
    "limitations": "This case should not be merged with unrelated donor cases or treated as support for an undated speculative offspring count.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-043",
    "family_codes": [
      "RE",
      "RI"
    ],
    "family": "Reproductive and heritable genetics",
    "primary_query": "Jan Karbaat DNA fertility doctor children",
    "status": "historical_case",
    "jurisdictions": [
      "Netherlands"
    ],
    "asset_classes": [
      "Donor records and genetic kinship evidence"
    ],
    "threat_codes": [
      "Genetic Auditability of Reproductive Systems"
    ],
    "imported": true,
    "threat_chain": [
      "clinic donor process",
      "undisclosed provider substitution",
      "fragmented records",
      "consumer testing",
      "sibling network",
      "court-ordered comparison",
      "system reform"
    ],
    "controls": [
      "national donor registries",
      "hard offspring limits",
      "cross-clinic deduplication",
      "immutable provenance",
      "audit sampling",
      "recipient access rights",
      "long retention of reproductive records"
    ],
    "does_not_prove": [
      "This case should not be merged with unrelated donor cases or treated as support for an undated speculative offspring count."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Karbaat case involved efforts to establish biological relationships despite incomplete or unreliable clinic records. Court-authorized comparisons and later testing brought genetic evidence to questions that the original documentation had not resolved.",
          "The number of identified relatives can change as more people test, so a stable case should not depend on an undated headline count. The distinctive institutional question is how donor records, limits, and oversight work across a system. Genetic auditability may expose a failure long after the original clinical process has ended."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity/provenance critical; consent critical; persistence maximal; relational exposure high.",
    "proposed_score_notes": "Suggested GER: GER-3. Suggested GPR: GPR-5. Suggested GPI: GPI-0/1 for original clinical records.",
    "clusters": [
      "Reproductive provenance"
    ],
    "related_case_ids": [
      "GS-CASE-041",
      "GS-CASE-042",
      "GS-CASE-044"
    ],
    "related_comparisons": [
      {
        "case_number": "041",
        "text": "Compare The He Jiankui CRISPR-Baby Experiment for heritable-edit governance failure. This case focuses on genetic auditability of reproductive systems."
      },
      {
        "case_number": "042",
        "text": "Compare Donald Cline Fertility Fraud for reproductive provenance fraud. This case focuses on genetic auditability of reproductive systems."
      },
      {
        "case_number": "044",
        "text": "Compare CHA Fertility Center Embryo Mix-Up for reproductive sample identity integrity. This case focuses on genetic auditability of reproductive systems."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Karbaat case involved efforts to establish biological relationships despite incomplete or unreliable clinic records. Court-authorized comparisons and later testing brought genetic evidence to questions that the original documentation had not resolved.",
          "The number of identified relatives can change as more people test, so a stable case should not depend on an undated headline count. The distinctive institutional question is how donor records, limits, and oversight work across a system. Genetic auditability may expose a failure long after the original clinical process has ended."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "gamete/embryo creation",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Consent depends on the intervention and the identity of the reproductive material. A substitution or undisclosed intervention changes what was authorized.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns embryos, transfer records, and parentage comparisons. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Reproductive Sample Identity Integrity identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows embryos, transfer records, and parentage comparisons through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-044",
    "case_number": "044",
    "slug": "/cases/044-cha-fertility-embryo-mix-up/",
    "title": "The Embryo Mix-Up: When Chain of Custody Became Parenthood",
    "short_title": "CHA Fertility Center Embryo Mix-Up",
    "summary": "The CHA Fertility Center litigation alleged a catastrophic embryo mix-up in which a woman gave birth to children genetically unrelated to her and later had to relinquish them to their genetic parents. It is a provenance failure with irreversible human consequences.",
    "direct_answer": "The CHA Fertility Center litigation alleged a catastrophic embryo mix-up in which a woman gave birth to children genetically unrelated to her and later had to relinquish them to their genetic parents. It is a provenance failure with irreversible human consequences.",
    "event_label": "2019 litigation",
    "sector": "Reproductive and heritable genetics",
    "event_type": "governance_dispute",
    "genetic_asset_type": "Embryos, transfer records, and parentage comparisons",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "alleged",
    "primary_source_count": 1,
    "sources": [
      "case044source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Reproductive Sample Identity Integrity",
    "processing": "gamete/embryo creation → labeling or selection failure → wrong transfer → pregnancy and birth → phenotype concern/DNA testing → kinship discovery → custody litigation",
    "direct_parties": "Families involved in the alleged embryo mix-up",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Consent depends on the intervention and the identity of the reproductive material. A substitution or undisclosed intervention changes what was authorized.",
    "mitigations": "Electronic witnessing, barcode/RFID identity checks, two-person verification, separation of simultaneous cases, immutable event logs, pre-transfer confirmation, incident disclosure, and long-term support.",
    "limitations": "The alleged outcome does not establish the precise technical root cause or the stage where the workflow failed.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-044",
    "family_codes": [
      "RE",
      "IN"
    ],
    "family": "Reproductive and heritable genetics",
    "primary_query": "CHA Fertility embryo mix up DNA lawsuit",
    "status": "governance_dispute",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Embryos, transfer records, and parentage comparisons"
    ],
    "threat_codes": [
      "Reproductive Sample Identity Integrity"
    ],
    "imported": true,
    "threat_chain": [
      "gamete/embryo creation",
      "labeling or selection failure",
      "wrong transfer",
      "pregnancy and birth",
      "phenotype concern/DNA testing",
      "kinship discovery",
      "custody litigation"
    ],
    "controls": [
      "electronic witnessing",
      "barcode/RFID identity checks",
      "two-person verification",
      "separation of simultaneous cases",
      "immutable event logs",
      "pre-transfer confirmation",
      "incident disclosure",
      "long-term support"
    ],
    "does_not_prove": [
      "The alleged outcome does not establish the precise technical root cause or the stage where the workflow failed."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The CHA litigation alleged a mismatch between the intended embryo transfer and the genetic parentage of children born afterward. The alleged outcome brings the stakes of specimen identity into sharp focus, but it does not on its own establish the precise point where the workflow failed.",
          "Labeling, selection, witnessing, and transfer are distinct stages. An investigation needs to reconstruct their records rather than infer a technical cause from the eventual discovery. This case concerns allegations and their provenance implications; sensitive family details are unnecessary to explain the security principle."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity critical; provenance catastrophic; consent invalidated by substitution; persistence maximal; relational exposure immediate-family scale.",
    "proposed_score_notes": "Suggested GER: GER-1/2. Suggested GPR: GPR-5. Suggested GPI: GPI-0.",
    "clusters": [
      "Reproductive provenance"
    ],
    "related_case_ids": [
      "GS-CASE-041",
      "GS-CASE-042",
      "GS-CASE-043"
    ],
    "related_comparisons": [
      {
        "case_number": "041",
        "text": "Compare The He Jiankui CRISPR-Baby Experiment for heritable-edit governance failure. This case focuses on reproductive sample identity integrity."
      },
      {
        "case_number": "042",
        "text": "Compare Donald Cline Fertility Fraud for reproductive provenance fraud. This case focuses on reproductive sample identity integrity."
      },
      {
        "case_number": "043",
        "text": "Compare Jan Karbaat And The Dutch Donor Registry Failure for genetic auditability of reproductive systems. This case focuses on reproductive sample identity integrity."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The CHA litigation alleged a mismatch between the intended embryo transfer and the genetic parentage of children born afterward. The alleged outcome brings the stakes of specimen identity into sharp focus, but it does not on its own establish the precise point where the workflow failed.",
          "Labeling, selection, witnessing, and transfer are distinct stages. An investigation needs to reconstruct their records rather than infer a technical cause from the eventual discovery. This case concerns allegations and their provenance implications; sensitive family details are unnecessary to explain the security principle."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "reachable instrument software",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Legitimate instrument access does not authorize compromise. Vulnerability notices and research demonstrations are not evidence of consent violations against a known victim group.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns sequencing instrument software and workflow files. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Instrument Software Is Part of the Genome identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows sequencing instrument software and workflow files through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-045",
    "case_number": "045",
    "slug": "/cases/045-illumina-local-run-manager-vulnerabilities/",
    "title": "Local Run Manager: The Sequencer Was Also a Networked Computer",
    "short_title": "Illumina Local Run Manager Vulnerabilities",
    "summary": "Critical vulnerabilities disclosed in Illumina Local Run Manager showed that sequencing instruments can inherit ordinary web, authentication, and file-handling weaknesses with extraordinary consequences for genomic confidentiality and result integrity.",
    "direct_answer": "Critical vulnerabilities disclosed in Illumina Local Run Manager showed that sequencing instruments can inherit ordinary web, authentication, and file-handling weaknesses with extraordinary consequences for genomic confidentiality and result integrity.",
    "event_label": "2022 disclosure",
    "sector": "Genomic cybersecurity and infrastructure",
    "event_type": "policy_event",
    "genetic_asset_type": "Sequencing instrument software and workflow files",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 2,
    "sources": [
      "case045source1",
      "case045source2"
    ],
    "parent_hub": "/infrastructure/",
    "security_principle": "Instrument Software Is Part of the Genome",
    "processing": "reachable instrument software → authentication/path-handling flaw → unauthorized access or modification → sequencing data/result risk → clinical/research consequence",
    "direct_parties": "Operators of potentially affected instrument software",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Legitimate instrument access does not authorize compromise. Vulnerability notices and research demonstrations are not evidence of consent violations against a known victim group.",
    "mitigations": "Network segmentation, no direct internet exposure, vendor patching, MFA where supported, allowlisting, signed updates, backup/restore testing, and post-compromise result revalidation.",
    "limitations": "A vulnerability is not proof of exploitation, altered patient results, or data theft.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-045",
    "family_codes": [
      "CY"
    ],
    "family": "Genomic cybersecurity and infrastructure",
    "primary_query": "Illumina Local Run Manager cybersecurity vulnerability",
    "status": "policy_event",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Sequencing instrument software and workflow files"
    ],
    "threat_codes": [
      "Instrument Software Is Part of the Genome"
    ],
    "imported": true,
    "threat_chain": [
      "reachable instrument software",
      "authentication/path-handling flaw",
      "unauthorized access or modification",
      "sequencing data/result risk",
      "clinical/research consequence"
    ],
    "controls": [
      "network segmentation",
      "no direct internet exposure",
      "vendor patching",
      "MFA where supported",
      "allowlisting",
      "signed updates",
      "backup/restore testing",
      "post-compromise result revalidation"
    ],
    "does_not_prove": [
      "A vulnerability is not proof of exploitation, altered patient results, or data theft."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Local Run Manager advisory brought instrument software into the same security discussion as the genomic data it processes. A sequencing instrument is also a networked computing system, with software, identities, and file-handling behavior that can create access paths.",
          "An advisory establishes a vulnerability, not evidence that someone exploited it or changed a patient's result. The practical response is to identify affected versions and follow the vendor's remediation for the actual environment. If a compromise is suspected, the trustworthiness of affected outputs becomes a separate question from whether the instrument is running again."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality, integrity, availability, and provenance all high/critical.",
    "proposed_score_notes": "Suggested GER: depends on instrument workload, potentially GER-3/4. Suggested GPR: GPR-5 if whole genomes exposed. Suggested GPI: GPI-0/1 after unbounded compromise until revalidated.",
    "clusters": [
      "Instrument security"
    ],
    "related_case_ids": [
      "GS-CASE-008",
      "GS-CASE-046",
      "GS-CASE-047"
    ],
    "related_comparisons": [
      {
        "case_number": "008",
        "text": "Compare Genomic laboratory ransomware for genomic infrastructure compromise. This case focuses on instrument software is part of the genome."
      },
      {
        "case_number": "046",
        "text": "Compare Illumina Universal Copy Service Vulnerability for shared-component blast radius. This case focuses on instrument software is part of the genome."
      },
      {
        "case_number": "047",
        "text": "Compare DNA-Encoded Malware Proof Of Concept for cross-domain input validation. This case focuses on instrument software is part of the genome."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Local Run Manager advisory brought instrument software into the same security discussion as the genomic data it processes. A sequencing instrument is also a networked computing system, with software, identities, and file-handling behavior that can create access paths.",
          "An advisory establishes a vulnerability, not evidence that someone exploited it or changed a patient's result. The practical response is to identify affected versions and follow the vendor's remediation for the actual environment. If a compromise is suspected, the trustworthiness of affected outputs becomes a separate question from whether the instrument is running again."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "common privileged service",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Legitimate instrument access does not authorize compromise. Vulnerability notices and research demonstrations are not evidence of consent violations against a known victim group.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns shared instrument software and configuration. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Shared-Component Blast Radius identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows shared instrument software and configuration through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-046",
    "case_number": "046",
    "slug": "/cases/046-illumina-universal-copy-service-vulnerability/",
    "title": "Universal Copy Service: One Shared Component, Many Sequencers",
    "short_title": "Illumina Universal Copy Service Vulnerability",
    "summary": "The 2023 Illumina Universal Copy Service disclosure showed how one privileged software component embedded across multiple sequencing instruments can create a fleet-wide attack surface capable of affecting settings, software, or genomic results.",
    "direct_answer": "The 2023 Illumina Universal Copy Service disclosure showed how one privileged software component embedded across multiple sequencing instruments can create a fleet-wide attack surface capable of affecting settings, software, or genomic results.",
    "event_label": "2023 disclosure",
    "sector": "Genomic cybersecurity and infrastructure",
    "event_type": "policy_event",
    "genetic_asset_type": "Shared instrument software and configuration",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 2,
    "sources": [
      "case046source1",
      "case046source2"
    ],
    "parent_hub": "/infrastructure/",
    "security_principle": "Shared-Component Blast Radius",
    "processing": "common privileged service → remotely reachable vulnerability → code execution or configuration change → multi-instrument impact → potential result manipulation",
    "direct_parties": "Operators of potentially affected sequencing instruments",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Legitimate instrument access does not authorize compromise. Vulnerability notices and research demonstrations are not evidence of consent violations against a known victim group.",
    "mitigations": "Software bill of materials, shared-component inventory, coordinated disclosure, rapid fleet patching, signed software, instrument isolation, integrity monitoring, and run-level provenance attestation.",
    "limitations": "The vulnerability disclosure does not establish exploitation, patient harm, or altered results.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-046",
    "family_codes": [
      "CY"
    ],
    "family": "Genomic cybersecurity and infrastructure",
    "primary_query": "Illumina Universal Copy Service cybersecurity",
    "status": "policy_event",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Shared instrument software and configuration"
    ],
    "threat_codes": [
      "Shared-Component Blast Radius"
    ],
    "imported": true,
    "threat_chain": [
      "common privileged service",
      "remotely reachable vulnerability",
      "code execution or configuration change",
      "multi-instrument impact",
      "potential result manipulation"
    ],
    "controls": [
      "software bill of materials",
      "shared-component inventory",
      "coordinated disclosure",
      "rapid fleet patching",
      "signed software",
      "instrument isolation",
      "integrity monitoring",
      "run-level provenance attestation"
    ],
    "does_not_prove": [
      "The vulnerability disclosure does not establish exploitation, patient harm, or altered results."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Universal Copy Service illustrates risk inherited through a component used across several products. A device-by-device inventory can miss that relationship if it records only instrument model names and not the shared software beneath them.",
          "The reported potential effects should not be rewritten as confirmed patient harm or data theft. The case instead shows why coordinated component inventories and remediation matter. Teams need a way to connect a shared-component notice to the instruments they operate and the runs whose processing history may need attention."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity/provenance critical; confidentiality and availability high; supply-chain scope high.",
    "proposed_score_notes": "Suggested GER: GER-3/4. Suggested GPR: GPR-5 for exfiltrated sequence data. Suggested GPI: GPI-0/1 for affected runs until validated.",
    "clusters": [
      "Instrument security"
    ],
    "related_case_ids": [
      "GS-CASE-008",
      "GS-CASE-045",
      "GS-CASE-047"
    ],
    "related_comparisons": [
      {
        "case_number": "008",
        "text": "Compare Genomic laboratory ransomware for genomic infrastructure compromise. This case focuses on shared-component blast radius."
      },
      {
        "case_number": "045",
        "text": "Compare Illumina Local Run Manager Vulnerabilities for instrument software is part of the genome. This case focuses on shared-component blast radius."
      },
      {
        "case_number": "047",
        "text": "Compare DNA-Encoded Malware Proof Of Concept for cross-domain input validation. This case focuses on shared-component blast radius."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Universal Copy Service illustrates risk inherited through a component used across several products. A device-by-device inventory can miss that relationship if it records only instrument model names and not the shared software beneath them.",
          "The reported potential effects should not be rewritten as confirmed patient harm or data theft. The case instead shows why coordinated component inventories and remediation matter. Teams need a way to connect a shared-component notice to the instruments they operate and the runs whose processing history may need attention."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "crafted synthetic DNA",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Legitimate instrument access does not authorize compromise. Vulnerability notices and research demonstrations are not evidence of consent violations against a known victim group.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns engineered dna input and modified analysis software. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Cross-Domain Input Validation identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows engineered dna input and modified analysis software through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-047",
    "case_number": "047",
    "slug": "/cases/047-dna-encoded-malware-sequencing-pipeline/",
    "title": "DNA-Encoded Malware: When a Biological Sample Became an Input Attack",
    "short_title": "DNA-Encoded Malware Proof Of Concept",
    "summary": "University of Washington researchers demonstrated a deliberately engineered proof of concept in which synthetic DNA, after sequencing, produced data that exploited intentionally modified analysis software. The case is a warning about untrusted biological inputs—not evidence of a common real-world attack.",
    "direct_answer": "University of Washington researchers demonstrated a deliberately engineered proof of concept in which synthetic DNA, after sequencing, produced data that exploited intentionally modified analysis software. The case is a warning about untrusted biological inputs—not evidence of a common real-world attack.",
    "event_label": "2017",
    "sector": "Genomic cybersecurity and infrastructure",
    "event_type": "research_demonstration",
    "genetic_asset_type": "Engineered DNA input and modified analysis software",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case047source1",
      "case047source2"
    ],
    "parent_hub": "/infrastructure/",
    "security_principle": "Cross-Domain Input Validation",
    "processing": "crafted synthetic DNA → sequencer → base-call file → vulnerable parser → code execution in demonstration environment",
    "direct_parties": "Researchers' demonstration environment; no victims asserted",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Legitimate instrument access does not authorize compromise. Vulnerability notices and research demonstrations are not evidence of consent violations against a known victim group.",
    "mitigations": "Memory-safe parsers, sandboxing, least privilege, fuzzing, signed pipelines, file-size/input validation, isolation of sequencing networks, and treating submitted samples as untrusted.",
    "limitations": "It did not show that ordinary DNA naturally carries executable malware or that production sequencers were broadly compromised.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-047",
    "family_codes": [
      "CY"
    ],
    "family": "Genomic cybersecurity and infrastructure",
    "primary_query": "malware encoded in DNA sequencing software",
    "status": "research_demonstration",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Engineered DNA input and modified analysis software"
    ],
    "threat_codes": [
      "Cross-Domain Input Validation"
    ],
    "imported": true,
    "threat_chain": [
      "crafted synthetic DNA",
      "sequencer",
      "base-call file",
      "vulnerable parser",
      "code execution in demonstration environment"
    ],
    "controls": [
      "memory-safe parsers",
      "sandboxing",
      "least privilege",
      "fuzzing",
      "signed pipelines",
      "file-size/input validation",
      "isolation of sequencing networks",
      "treating submitted samples as untrusted"
    ],
    "does_not_prove": [
      "It did not show that ordinary DNA naturally carries executable malware or that production sequencers were broadly compromised."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The DNA-encoded malware demonstration deliberately connected a biological input to vulnerable analysis software under engineered conditions. The proof of concept is informative precisely because those conditions are explicit. It does not establish that ordinary specimens naturally contain executable malware or that production laboratories were compromised.",
          "The general software lesson is about trust at an input boundary. Data produced from a specimen should still be handled as input by downstream tools. Sandboxing, validation, and least privilege reduce the consequences of processing an unexpected file without requiring an operational account of how to reproduce the demonstration."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "integrity and availability critical; confidentiality possible; provenance high; real-world likelihood in the demonstration low.",
    "proposed_score_notes": "Suggested GER: workload-dependent. Suggested GPR: not central unless data is exfiltrated. Suggested GPI: GPI-0 after pipeline compromise.",
    "clusters": [
      "Instrument security"
    ],
    "related_case_ids": [
      "GS-CASE-008",
      "GS-CASE-045",
      "GS-CASE-046"
    ],
    "related_comparisons": [
      {
        "case_number": "008",
        "text": "Compare Genomic laboratory ransomware for genomic infrastructure compromise. This case focuses on cross-domain input validation."
      },
      {
        "case_number": "045",
        "text": "Compare Illumina Local Run Manager Vulnerabilities for instrument software is part of the genome. This case focuses on cross-domain input validation."
      },
      {
        "case_number": "046",
        "text": "Compare Illumina Universal Copy Service Vulnerability for shared-component blast radius. This case focuses on cross-domain input validation."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The DNA-encoded malware demonstration deliberately connected a biological input to vulnerable analysis software under engineered conditions. The proof of concept is informative precisely because those conditions are explicit. It does not establish that ordinary specimens naturally contain executable malware or that production laboratories were compromised.",
          "The general software lesson is about trust at an input boundary. Data produced from a specimen should still be handled as input by downstream tools. Sandboxing, validation, and least privilege reduce the consequences of processing an unexpected file without requiring an operational account of how to reproduce the demonstration."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "phished/compromised mailbox",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "law_enforcement": false,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns employee email messages and attachments. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Unstructured Communications Are Genetic Data Stores identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows employee email messages and attachments through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-048",
    "case_number": "048",
    "slug": "/cases/048-ambry-genetics-email-breach/",
    "title": "Ambry Genetics: A Mailbox Became a Clinical-Genetics Exposure",
    "short_title": "Ambry Genetics Email-Account Breach",
    "summary": "Ambry Genetics disclosed unauthorized access to an employee email account in 2020, illustrating how sensitive patient and genetic-testing information may escape purpose-built databases and accumulate in ordinary communications systems.",
    "direct_answer": "Ambry Genetics disclosed unauthorized access to an employee email account in 2020, illustrating how sensitive patient and genetic-testing information may escape purpose-built databases and accumulate in ordinary communications systems.",
    "event_label": "2020",
    "sector": "Consumer genetics and commercial data",
    "event_type": "confirmed_incident",
    "genetic_asset_type": "Employee email messages and attachments",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 1,
    "sources": [
      "case048source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Unstructured Communications Are Genetic Data Stores",
    "processing": "phished/compromised mailbox → messages and attachments → patient/account/insurance or testing information → unauthorized access → notification/litigation",
    "direct_parties": "People whose information appeared in the affected mailbox",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "mitigations": "Phishing-resistant MFA, mailbox retention limits, attachment controls, secure portals, DLP, least privilege, token/session monitoring, and field-level incident scoping.",
    "limitations": "The notice does not establish that raw genomes, every test result, or every customer’s data was accessed.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-048",
    "family_codes": [
      "CG",
      "CY"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "Ambry Genetics 2020 data breach",
    "status": "confirmed_incident",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Employee email messages and attachments"
    ],
    "threat_codes": [
      "Unstructured Communications Are Genetic Data Stores"
    ],
    "imported": true,
    "threat_chain": [
      "phished/compromised mailbox",
      "messages and attachments",
      "patient/account/insurance or testing information",
      "unauthorized access",
      "notification/litigation"
    ],
    "controls": [
      "phishing-resistant MFA",
      "mailbox retention limits",
      "attachment controls",
      "secure portals",
      "DLP",
      "least privilege",
      "token/session monitoring",
      "field-level incident scoping"
    ],
    "does_not_prove": [
      "The notice does not establish that raw genomes, every test result, or every customer’s data was accessed."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Ambry incident concerns an employee mailbox rather than an assumed breach of every laboratory system. Messages and attachments can become a second store of sensitive information even when the organization maintains a dedicated clinical platform.",
          "The affected fields must be established from the notice for the relevant people. A mailbox associated with a genetics organization does not imply that every record contains a genetic result. The useful architectural lesson is to include communications, retention, and attachment handling in the data inventory instead of drawing the boundary around the main database alone."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality high; integrity moderate; availability low; provenance moderate; consent high.",
    "proposed_score_notes": "Suggested GER: GER-1/2 if genetic reports were involved; otherwise classify by confirmed fields. Suggested GPR: GPR-2 to 5. Suggested GPI: GPI-2.",
    "clusters": [
      "Breach classification"
    ],
    "related_case_ids": [
      "GS-CASE-003",
      "GS-CASE-013",
      "GS-CASE-049",
      "GS-CASE-050"
    ],
    "related_comparisons": [
      {
        "case_number": "003",
        "text": "Compare 23andMe 2023 for genetic graph amplification. This case focuses on unstructured communications are genetic data stores."
      },
      {
        "case_number": "013",
        "text": "Compare MyHeritage 2018 Breach: A Negative Control for exposure classification accuracy. This case focuses on unstructured communications are genetic data stores."
      },
      {
        "case_number": "049",
        "text": "Compare DNA Diagnostics Center 2021 Breach for legacy-system discovery failure. This case focuses on unstructured communications are genetic data stores."
      },
      {
        "case_number": "050",
        "text": "Compare Veritas Genetics Portal Incident for interface exposure must be scoped by data class. This case focuses on unstructured communications are genetic data stores."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Ambry incident concerns an employee mailbox rather than an assumed breach of every laboratory system. Messages and attachments can become a second store of sensitive information even when the organization maintains a dedicated clinical platform.",
          "The affected fields must be established from the notice for the relevant people. A mailbox associated with a genetics organization does not imply that every record contains a genetic result. The useful architectural lesson is to include communications, retention, and attachment handling in the data inventory instead of drawing the boundary around the main database alone."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "acquired legacy database",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "law_enforcement": false,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns personal information in an acquired legacy database. The documented scope does not establish disclosure of raw genomic data.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Legacy-System Discovery Failure identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows personal information in an acquired legacy database through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-049",
    "case_number": "049",
    "slug": "/cases/049-dna-diagnostics-center-breach/",
    "title": "DNA Diagnostics Center: The Forgotten Database Behind the Live Network",
    "short_title": "DNA Diagnostics Center 2021 Breach",
    "summary": "State attorneys general alleged that DNA Diagnostics Center failed to detect unauthorized access to a legacy database containing information on about 2.1 million people, turning forgotten infrastructure into the breach's central asset.",
    "direct_answer": "State attorneys general alleged that DNA Diagnostics Center failed to detect unauthorized access to a legacy database containing information on about 2.1 million people, turning forgotten infrastructure into the breach's central asset.",
    "event_label": "2021 / 2023 enforcement",
    "sector": "Consumer genetics and commercial data",
    "event_type": "enforcement_action",
    "genetic_asset_type": "Personal information in an acquired legacy database",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 1,
    "sources": [
      "case049source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Legacy-System Discovery Failure",
    "processing": "acquired legacy database → incomplete inventory/monitoring → unauthorized access and exfiltration → delayed detection → multistate enforcement",
    "direct_parties": "People whose records were held in the legacy database",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "mitigations": "Merger/acquisition data discovery, legacy retirement, EDR and log coverage, segmentation, encryption, data minimization, incident-response testing, and executive accountability.",
    "limitations": "A DNA-testing company breach is not automatically a DNA-data breach.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-049",
    "family_codes": [
      "CG",
      "CY"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "DNA Diagnostics Center 2021 breach settlement",
    "status": "enforcement_action",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Personal information in an acquired legacy database"
    ],
    "threat_codes": [
      "Legacy-System Discovery Failure"
    ],
    "imported": true,
    "threat_chain": [
      "acquired legacy database",
      "incomplete inventory/monitoring",
      "unauthorized access and exfiltration",
      "delayed detection",
      "multistate enforcement"
    ],
    "controls": [
      "merger/acquisition data discovery",
      "legacy retirement",
      "EDR and log coverage",
      "segmentation",
      "encryption",
      "data minimization",
      "incident-response testing",
      "executive accountability"
    ],
    "does_not_prove": [
      "A DNA-testing company breach is not automatically a DNA-data breach."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "DNA Diagnostics Center's legacy-system case links an acquisition history to an inventory problem. Regulators alleged that information remained in a database that was not adequately accounted for in the organization's security processes.",
          "Forgotten data remains an asset an intruder may reach. A merger or migration should therefore examine inherited records, logging coverage, and retirement decisions. The company's name is not evidence about which fields were exposed; the enforcement record and notice must supply that scope."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality critical for confirmed fields; integrity unknown; availability low; provenance and asset inventory critical.",
    "proposed_score_notes": "Suggested GER: GER-0 unless genetic/kinship data is confirmed. Suggested GPR: score confirmed fields, not branding. Suggested GPI: GPI-1 for system provenance/inventory.",
    "clusters": [
      "Breach classification"
    ],
    "related_case_ids": [
      "GS-CASE-003",
      "GS-CASE-013",
      "GS-CASE-048",
      "GS-CASE-050"
    ],
    "related_comparisons": [
      {
        "case_number": "003",
        "text": "Compare 23andMe 2023 for genetic graph amplification. This case focuses on legacy-system discovery failure."
      },
      {
        "case_number": "013",
        "text": "Compare MyHeritage 2018 Breach: A Negative Control for exposure classification accuracy. This case focuses on legacy-system discovery failure."
      },
      {
        "case_number": "048",
        "text": "Compare Ambry Genetics Email-Account Breach for unstructured communications are genetic data stores. This case focuses on legacy-system discovery failure."
      },
      {
        "case_number": "050",
        "text": "Compare Veritas Genetics Portal Incident for interface exposure must be scoped by data class. This case focuses on legacy-system discovery failure."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "DNA Diagnostics Center's legacy-system case links an acquisition history to an inventory problem. Regulators alleged that information remained in a database that was not adequately accounted for in the organization's security processes.",
          "Forgotten data remains an asset an intruder may reach. A merger or migration should therefore examine inherited records, logging coverage, and retirement decisions. The company's name is not evidence about which fields were exposed; the enforcement record and notice must supply that scope."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "customer portal compromise",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "law_enforcement": false,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns customer-facing portal information. The documented scope does not establish disclosure of raw genomic data.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Interface Exposure Must Be Scoped by Data Class identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows customer-facing portal information through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-050",
    "case_number": "050",
    "slug": "/cases/050-veritas-genetics-portal-incident/",
    "title": "Veritas Genetics: Breached Portal, Reportedly No Genetic Results",
    "short_title": "Veritas Genetics Portal Incident",
    "summary": "Veritas Genetics confirmed unauthorized access to a customer-facing portal in 2019 while stating that the portal did not contain genetic data, DNA-test results, or health records. Like MyHeritage, it is a precision test for breach reporting.",
    "direct_answer": "Veritas Genetics confirmed unauthorized access to a customer-facing portal in 2019 while stating that the portal did not contain genetic data, DNA-test results, or health records. Like MyHeritage, it is a precision test for breach reporting.",
    "event_label": "2019",
    "sector": "Consumer genetics and commercial data",
    "event_type": "confirmed_incident",
    "genetic_asset_type": "Customer-facing portal information",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "officially_disclosed",
    "primary_source_count": 0,
    "sources": [
      "case050source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Interface Exposure Must Be Scoped by Data Class",
    "processing": "customer portal compromise → limited account/customer information → investigation and notification; no confirmed genomic store access in the company's statement",
    "direct_parties": "Users affected by the portal incident",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "mitigations": "System/data mapping, separate trust zones, MFA, precise breach notices, evidence preservation, portal minimization, and testing lateral movement paths.",
    "limitations": "It does not prove genetic records were exposed, nor that excluding them from one portal resolves every architectural risk.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-050",
    "family_codes": [
      "CG"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "Veritas Genetics 2019 data breach DNA results",
    "status": "confirmed_incident",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Customer-facing portal information"
    ],
    "threat_codes": [
      "Interface Exposure Must Be Scoped by Data Class"
    ],
    "imported": true,
    "threat_chain": [
      "customer portal compromise",
      "limited account/customer information",
      "investigation and notification; no confirmed genomic store access in the company's statement"
    ],
    "controls": [
      "system/data mapping",
      "separate trust zones",
      "MFA",
      "precise breach notices",
      "evidence preservation",
      "portal minimization",
      "testing lateral movement paths"
    ],
    "does_not_prove": [
      "It does not prove genetic records were exposed, nor that excluding them from one portal resolves every architectural risk."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Veritas stated that the compromised customer-facing portal did not contain genetic data, test results, or health records. The distinction is central to the case, rather than a minor qualification at the end of a breach headline.",
          "Customer support, billing, laboratory, and sequence-storage systems should be mapped separately. Their connections can create additional risk, but that does not prove movement between them occurred in a particular event. The case complements MyHeritage by showing why the interface reached and the information it held deserve their own description."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality depends on confirmed fields; genetic integrity/availability not established; credential persistence remediable.",
    "proposed_score_notes": "Suggested GER: GER-0. Suggested GPR: GPR-0/1 absent genetic data. GPI: not central.",
    "clusters": [
      "Breach classification"
    ],
    "related_case_ids": [
      "GS-CASE-003",
      "GS-CASE-013",
      "GS-CASE-048",
      "GS-CASE-049"
    ],
    "related_comparisons": [
      {
        "case_number": "003",
        "text": "Compare 23andMe 2023 for genetic graph amplification. This case focuses on interface exposure must be scoped by data class."
      },
      {
        "case_number": "013",
        "text": "Compare MyHeritage 2018 Breach: A Negative Control for exposure classification accuracy. This case focuses on interface exposure must be scoped by data class."
      },
      {
        "case_number": "048",
        "text": "Compare Ambry Genetics Email-Account Breach for unstructured communications are genetic data stores. This case focuses on interface exposure must be scoped by data class."
      },
      {
        "case_number": "049",
        "text": "Compare DNA Diagnostics Center 2021 Breach for legacy-system discovery failure. This case focuses on interface exposure must be scoped by data class."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Veritas stated that the compromised customer-facing portal did not contain genetic data, test results, or health records. The distinction is central to the case, rather than a minor qualification at the end of a breach headline.",
          "Customer support, billing, laboratory, and sequence-storage systems should be mapped separately. Their connections can create additional risk, but that does not prove movement between them occurred in a particular event. The case complements MyHeritage by showing why the interface reached and the information it held deserve their own description."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "consumer sample/data",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "law_enforcement": false,
    "commercial": true,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns genetic database, stored samples, and privacy commitments. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Corporate-Continuity Risk identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows genetic database, stored samples, and privacy commitments through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-051",
    "case_number": "051",
    "slug": "/cases/051-23andme-bankruptcy-genetic-data-sale/",
    "title": "23andMe Bankruptcy: Can Genetic Consent Survive a Corporate Sale?",
    "short_title": "23andMe Bankruptcy And Data Stewardship",
    "summary": "23andMe's 2025 Chapter 11 sale process turned genetic privacy into a bankruptcy-governance question: data and stored samples can outlive the company relationship in which users originally provided them.",
    "direct_answer": "23andMe's 2025 Chapter 11 sale process turned genetic privacy into a bankruptcy-governance question: data and stored samples can outlive the company relationship in which users originally provided them.",
    "event_label": "2025 sale process",
    "sector": "Consumer genetics and commercial data",
    "event_type": "policy_event",
    "genetic_asset_type": "Genetic database, stored samples, and privacy commitments",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 3,
    "sources": [
      "case051source1",
      "case051source2",
      "case051source3"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Corporate-Continuity Risk",
    "processing": "consumer sample/data → long-lived database → financial distress → bankruptcy sale → successor control → continuity or reinterpretation of privacy commitments",
    "direct_parties": "Customers and research participants whose assets were subject to successor stewardship",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.",
    "mitigations": "Privacy-by-design sale covenants, independent ombudsman, affirmative consent for material purpose change, deletion and sample-destruction pathways, successor audits, escrowed records, and insolvency planning before crisis.",
    "limitations": "A bankruptcy filing does not automatically make data public or erase privacy law. Likewise, a promise to honor existing policies does not answer every future-use question.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-051",
    "family_codes": [
      "CG",
      "CO"
    ],
    "family": "Consumer genetics and commercial data",
    "primary_query": "what happened to 23andMe DNA data in bankruptcy",
    "status": "policy_event",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Genetic database, stored samples, and privacy commitments"
    ],
    "threat_codes": [
      "Corporate-Continuity Risk"
    ],
    "imported": true,
    "threat_chain": [
      "consumer sample/data",
      "long-lived database",
      "financial distress",
      "bankruptcy sale",
      "successor control",
      "continuity or reinterpretation of privacy commitments"
    ],
    "controls": [
      "privacy-by-design sale covenants",
      "independent ombudsman",
      "affirmative consent for material purpose change",
      "deletion and sample-destruction pathways",
      "successor audits",
      "escrowed records",
      "insolvency planning before crisis"
    ],
    "does_not_prove": [
      "A bankruptcy filing does not automatically make data public or erase privacy law. Likewise, a promise to honor existing policies does not answer every future-use question."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The 2025 bankruptcy process raised a continuity question: which commitments travel with genetic data and stored samples when control changes? The supplied record distinguishes the earlier bidding stage from the later TTAM transaction, rather than treating an initial bidder as the final owner.",
          "The relevant assets are not limited to account records. Sample custody, research permissions, deletion processes, and obligations of a successor can each require separate treatment. Bankruptcy does not automatically make private data public, while a general promise to honor policies does not explain every future-use decision."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality and consent critical; availability uncertain; integrity/provenance high; persistence maximal; relational exposure high.",
    "proposed_score_notes": "Suggested GER: GER-3/4. Suggested GPR: GPR-5. Suggested GPI: GPI-3/4 if custody and transfer are documented.",
    "clusters": [
      "Breach classification"
    ],
    "related_case_ids": [
      "GS-CASE-003",
      "GS-CASE-013",
      "GS-CASE-048",
      "GS-CASE-049"
    ],
    "related_comparisons": [
      {
        "case_number": "003",
        "text": "Compare 23andMe 2023 for genetic graph amplification. This case focuses on corporate-continuity risk."
      },
      {
        "case_number": "013",
        "text": "Compare MyHeritage 2018 Breach: A Negative Control for exposure classification accuracy. This case focuses on corporate-continuity risk."
      },
      {
        "case_number": "048",
        "text": "Compare Ambry Genetics Email-Account Breach for unstructured communications are genetic data stores. This case focuses on corporate-continuity risk."
      },
      {
        "case_number": "049",
        "text": "Compare DNA Diagnostics Center 2021 Breach for legacy-system discovery failure. This case focuses on corporate-continuity risk."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The 2025 bankruptcy process raised a continuity question: which commitments travel with genetic data and stored samples when control changes? The supplied record distinguishes the earlier bidding stage from the later TTAM transaction, rather than treating an initial bidder as the final owner.",
          "The relevant assets are not limited to account records. Sample custody, research permissions, deletion processes, and obligations of a successor can each require separate treatment. Bankruptcy does not automatically make private data public, while a general promise to honor policies does not explain every future-use decision."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "pathogen sequences",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Contributor terms, access, attribution, and public-interest research needs are central. Human subject consent may be relevant where data is linked to people, but should not be assumed for every pathogen record.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns pathogen sequence submissions and repository access. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Repository Governance Is Availability Security identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows pathogen sequence submissions and repository access through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-052",
    "case_number": "052",
    "slug": "/cases/052-gisaid-pathogen-genome-access-governance/",
    "title": "GISAID: The Database That Made Sharing Possible—and Access Disputes Explosive",
    "short_title": "GISAID Access And Pandemic-Data Governance",
    "summary": "GISAID became critical infrastructure for viral genomic sharing, but disputes over access, attribution, terms, and account suspension show that a repository's private governance can affect who participates in global outbreak science.",
    "direct_answer": "GISAID became critical infrastructure for viral genomic sharing, but disputes over access, attribution, terms, and account suspension show that a repository's private governance can affect who participates in global outbreak science.",
    "event_label": "2023 disputes / ongoing repository",
    "sector": "Pathogen and research-data governance",
    "event_type": "governance_dispute",
    "genetic_asset_type": "Pathogen sequence submissions and repository access",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "disputed",
    "primary_source_count": 1,
    "sources": [
      "case052source1",
      "case052source2"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Repository Governance Is Availability Security",
    "processing": "pathogen sequences → governed repository → access/attribution rules → contested enforcement → researcher exclusion or delay → public-health consequence",
    "direct_parties": "Data contributors and researchers whose access was at issue",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Contributor terms, access, attribution, and public-interest research needs are central. Human subject consent may be relevant where data is linked to people, but should not be assumed for every pathogen record.",
    "mitigations": "Published enforcement criteria, independent appeals, transparent suspension notices, mirrored emergency access, durable attribution, contributor consent, and machine-readable provenance.",
    "limitations": "It does not prove that open access has no governance costs or that every access restriction was arbitrary.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-052",
    "family_codes": [
      "PD"
    ],
    "family": "Pathogen and research-data governance",
    "primary_query": "GISAID data access controversy governance",
    "status": "governance_dispute",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Pathogen sequence submissions and repository access"
    ],
    "threat_codes": [
      "Repository Governance Is Availability Security"
    ],
    "imported": true,
    "threat_chain": [
      "pathogen sequences",
      "governed repository",
      "access/attribution rules",
      "contested enforcement",
      "researcher exclusion or delay",
      "public-health consequence"
    ],
    "controls": [
      "published enforcement criteria",
      "independent appeals",
      "transparent suspension notices",
      "mirrored emergency access",
      "durable attribution",
      "contributor consent",
      "machine-readable provenance"
    ],
    "does_not_prove": [
      "It does not prove that open access has no governance costs or that every access restriction was arbitrary."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "GISAID's governance combines access with contributor attribution and conditions of use. Its stated mission and accounts of access disputes describe different sides of the arrangement. The existence of a restriction does not by itself establish an improper motive, just as a mission statement does not resolve every complaint about implementation.",
          "The security question concerns dependable participation in a shared research resource. Clear enforcement criteria, documented reasons, and an appeal path can matter to availability alongside technical uptime. The case leaves disputed motives unresolved and separates repository governance from claims about the scientific conclusions drawn from its data."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "availability critical; integrity/provenance high; confidentiality/sovereignty moderate; consent here concerns data contributors rather than patients alone.",
    "proposed_score_notes": "Suggested GER: GER-5 because global surveillance networks are affected. GPR: not a human-identity score unless linked samples include personal data. Suggested GPI: GPI-4 when submission provenance is intact.",
    "clusters": [
      "Pathogen data"
    ],
    "related_case_ids": [
      "GS-CASE-053",
      "GS-CASE-054"
    ],
    "related_comparisons": [
      {
        "case_number": "053",
        "text": "Compare Deleted Early SARS-CoV-2 Sequences for scientific deletion is not always erasure. This case focuses on repository governance is availability security."
      },
      {
        "case_number": "054",
        "text": "Compare H5N1 Transmissibility Research And Publication for information hazard governance. This case focuses on repository governance is availability security."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "GISAID's governance combines access with contributor attribution and conditions of use. Its stated mission and accounts of access disputes describe different sides of the arrangement. The existence of a restriction does not by itself establish an improper motive, just as a mission statement does not resolve every complaint about implementation.",
          "The security question concerns dependable participation in a shared research resource. Clear enforcement criteria, documented reasons, and an appeal path can matter to availability alongside technical uptime. The case leaves disputed motives unresolved and separates repository governance from claims about the scientific conclusions drawn from its data."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "sequence submission",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Contributor terms, access, attribution, and public-interest research needs are central. Human subject consent may be relevant where data is linked to people, but should not be assumed for every pathogen record.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns archived and recovered partial pathogen sequence data. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Scientific Deletion Is Not Always Erasure identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows archived and recovered partial pathogen sequence data through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-053",
    "case_number": "053",
    "slug": "/cases/053-deleted-sars-cov-2-sequences-recovered/",
    "title": "The Deleted Sequences: Recovery from a Cloud Archive",
    "short_title": "Deleted Early SARS-CoV-2 Sequences",
    "summary": "A 2021 study recovered partial data from early Wuhan SARS-CoV-2 sequencing runs that had been removed from the NIH Sequence Read Archive but remained accessible through cloud infrastructure, highlighting deletion ambiguity and outbreak-data provenance.",
    "direct_answer": "A 2021 study recovered partial data from early Wuhan SARS-CoV-2 sequencing runs that had been removed from the NIH Sequence Read Archive but remained accessible through cloud infrastructure, highlighting deletion ambiguity and outbreak-data provenance.",
    "event_label": "2021 publication",
    "sector": "Pathogen and research-data governance",
    "event_type": "research_demonstration",
    "genetic_asset_type": "Archived and recovered partial pathogen sequence data",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case053source1",
      "case053source2"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Scientific Deletion Is Not Always Erasure",
    "processing": "sequence submission → public archive → withdrawal/removal → residual cloud copy → independent recovery → renewed scientific interpretation",
    "direct_parties": "Sequence contributors and researchers relying on the archive",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Contributor terms, access, attribution, and public-interest research needs are central. Human subject consent may be relevant where data is linked to people, but should not be assumed for every pathogen record.",
    "mitigations": "Transparent withdrawal reasons, tombstone metadata, versioned archives, independent preservation, contributor agreements, reproducible pipelines, and clear distinctions between deletion, de-indexing, and inaccessible copies.",
    "limitations": "Recovered partial sequences do not alone determine the origin of SARS-CoV-2 or prove misconduct.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-053",
    "family_codes": [
      "PD",
      "IN"
    ],
    "family": "Pathogen and research-data governance",
    "primary_query": "deleted early SARS-CoV-2 sequences recovered NIH SRA",
    "status": "research_demonstration",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Archived and recovered partial pathogen sequence data"
    ],
    "threat_codes": [
      "Scientific Deletion Is Not Always Erasure"
    ],
    "imported": true,
    "threat_chain": [
      "sequence submission",
      "public archive",
      "withdrawal/removal",
      "residual cloud copy",
      "independent recovery",
      "renewed scientific interpretation"
    ],
    "controls": [
      "transparent withdrawal reasons",
      "tombstone metadata",
      "versioned archives",
      "independent preservation",
      "contributor agreements",
      "reproducible pipelines",
      "clear distinctions between deletion",
      "de-indexing",
      "inaccessible copies"
    ],
    "does_not_prove": [
      "Recovered partial sequences do not alone determine the origin of SARS-CoV-2 or prove misconduct."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The recovery of sequence information after removal from an archive exposes the difference between deletion from a public interface and erasure of every underlying copy. Metadata, replicas, and withdrawal records can change what researchers are able to reconstruct later.",
          "The case concerns data provenance and availability. Recovered partial sequences cannot, by themselves, decide the origin of a pathogen or prove why a contributor requested removal. Transparent withdrawal records can help preserve scientific context without assuming that every removal has the same explanation."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "availability and provenance critical; integrity high; confidentiality context-dependent; persistence paradoxical.",
    "proposed_score_notes": "Suggested GER: GER-5 for global research consequences. Suggested GPI: GPI-2/3 because custody and version history became disputed.",
    "clusters": [
      "Pathogen data"
    ],
    "related_case_ids": [
      "GS-CASE-052",
      "GS-CASE-054"
    ],
    "related_comparisons": [
      {
        "case_number": "052",
        "text": "Compare GISAID Access And Pandemic-Data Governance for repository governance is availability security. This case focuses on scientific deletion is not always erasure."
      },
      {
        "case_number": "054",
        "text": "Compare H5N1 Transmissibility Research And Publication for information hazard governance. This case focuses on scientific deletion is not always erasure."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The recovery of sequence information after removal from an archive exposes the difference between deletion from a public interface and erasure of every underlying copy. Metadata, replicas, and withdrawal records can change what researchers are able to reconstruct later.",
          "The case concerns data provenance and availability. Recovered partial sequences cannot, by themselves, decide the origin of a pathogen or prove why a contributor requested removal. Transparent withdrawal records can help preserve scientific context without assuming that every removal has the same explanation."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "pathogen manipulation",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Contributor terms, access, attribution, and public-interest research needs are central. Human subject consent may be relevant where data is linked to people, but should not be assumed for every pathogen record.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns dual-use pathogen research information. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Information Hazard Governance identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows dual-use pathogen research information through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-054",
    "case_number": "054",
    "slug": "/cases/054-h5n1-dual-use-genome-publication/",
    "title": "The H5N1 Publication Fight: When Genomic Detail Became Dual-Use Information",
    "short_title": "H5N1 Transmissibility Research And Publication",
    "summary": "The 2011–2012 H5N1 transmissibility controversy forced researchers, journals, and governments to decide whether experimental methods and mutations should be fully published when the same information might support preparedness or misuse.",
    "direct_answer": "The 2011–2012 H5N1 transmissibility controversy forced researchers, journals, and governments to decide whether experimental methods and mutations should be fully published when the same information might support preparedness or misuse.",
    "event_label": "2011–2012",
    "sector": "Pathogen and research-data governance",
    "event_type": "policy_event",
    "genetic_asset_type": "Dual-use pathogen research information",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case054source1",
      "case054source2"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Information Hazard Governance",
    "processing": "pathogen manipulation → genomic/experimental findings → dual-use review → proposed redaction → global debate → publication and policy change",
    "direct_parties": "Researchers, publishers, oversight bodies, and the wider public",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Contributor terms, access, attribution, and public-interest research needs are central. Human subject consent may be relevant where data is linked to people, but should not be assumed for every pathogen record.",
    "mitigations": "Durable dual-use review, staged disclosure, biosafety verification, need-to-know technical annexes where justified, international coordination, and periodic policy review.",
    "limitations": "It does not establish that publication caused misuse or that secrecy would have eliminated biosafety risk.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-054",
    "family_codes": [
      "PD"
    ],
    "family": "Pathogen and research-data governance",
    "primary_query": "H5N1 gain of function publication controversy 2012",
    "status": "policy_event",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Dual-use pathogen research information"
    ],
    "threat_codes": [
      "Information Hazard Governance"
    ],
    "imported": true,
    "threat_chain": [
      "pathogen manipulation",
      "genomic/experimental findings",
      "dual-use review",
      "proposed redaction",
      "global debate",
      "publication and policy change"
    ],
    "controls": [
      "durable dual-use review",
      "staged disclosure",
      "biosafety verification",
      "need-to-know technical annexes where justified",
      "international coordination",
      "periodic policy review"
    ],
    "does_not_prove": [
      "It does not establish that publication caused misuse or that secrecy would have eliminated biosafety risk."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The H5N1 debate placed scientific access and misuse concerns in direct tension. The policy question was how to assess disclosure of research information that could support legitimate preparedness while also presenting risks.",
          "This account stays at the governance level. It does not reproduce experimental procedures, mutations, or instructions. The lesson concerns review responsibilities, the scope of disclosure, and coordination between researchers, publishers, and authorities. Neither publication nor redaction can be treated as proof that all biosafety and security questions have been resolved."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality ambiguous; integrity/provenance critical; availability double-edged; consent not central; population consequence potentially GER-5.",
    "proposed_score_notes": "Suggested GER: GER-5. GPR: use a pathogen-information persistence note, not the human scale. Suggested GPI: GPI-4 for peer-reviewed methods with documented custody.",
    "clusters": [
      "Pathogen data"
    ],
    "related_case_ids": [
      "GS-CASE-052",
      "GS-CASE-053"
    ],
    "related_comparisons": [
      {
        "case_number": "052",
        "text": "Compare GISAID Access And Pandemic-Data Governance for repository governance is availability security. This case focuses on information hazard governance."
      },
      {
        "case_number": "053",
        "text": "Compare Deleted Early SARS-CoV-2 Sequences for scientific deletion is not always erasure. This case focuses on information hazard governance."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The H5N1 debate placed scientific access and misuse concerns in direct tension. The policy question was how to assess disclosure of research information that could support legitimate preparedness while also presenting risks.",
          "This account stays at the governance level. It does not reproduce experimental procedures, mutations, or instructions. The lesson concerns review responsibilities, the scope of disclosure, and coordination between researchers, publishers, and authorities. Neither publication nor redaction can be treated as proof that all biosafety and security questions have been resolved."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Norway / Svalbard",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "warming/precipitation",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns seed-vault access infrastructure and deposited accessions. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Environmental Assumptions Expire identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows seed-vault access infrastructure and deposited accessions through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-055",
    "case_number": "055",
    "slug": "/cases/055-svalbard-seed-vault-water-intrusion/",
    "title": "Svalbard's Wet Tunnel: A Near Miss in the World's Seed Backup",
    "short_title": "Svalbard Seed Vault Water Intrusion",
    "summary": "Water entered the Svalbard Global Seed Vault's access tunnel after unusual warmth and precipitation, but did not reach stored seeds. The event is a near miss showing that resilience plans must revisit climate and infrastructure assumptions.",
    "direct_answer": "Water entered the Svalbard Global Seed Vault's access tunnel after unusual warmth and precipitation, but did not reach stored seeds. The event is a near miss showing that resilience plans must revisit climate and infrastructure assumptions.",
    "event_label": "2016 event / 2017 reporting",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "historical_case",
    "genetic_asset_type": "Seed-vault access infrastructure and deposited accessions",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case055source1",
      "case055source2"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Environmental Assumptions Expire",
    "processing": "warming/precipitation → tunnel water intrusion → ice and access risk → no seed damage → remediation and redesign",
    "direct_parties": "Vault operators and depositors; no seed loss asserted",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Climate-adjusted design basis, drainage, waterproofing, redundant monitoring, no permanent heat sources in tunnels, emergency access plans, and geographically distributed primary genebanks.",
    "limitations": "The seed chambers did not flood, and the event did not demonstrate loss of the collection.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-055",
    "family_codes": [
      "GR",
      "IN"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "Svalbard Seed Vault water intrusion 2017",
    "status": "historical_case",
    "jurisdictions": [
      "Norway",
      "Svalbard"
    ],
    "asset_classes": [
      "Seed-vault access infrastructure and deposited accessions"
    ],
    "threat_codes": [
      "Environmental Assumptions Expire"
    ],
    "imported": true,
    "threat_chain": [
      "warming/precipitation",
      "tunnel water intrusion",
      "ice and access risk",
      "no seed damage",
      "remediation and redesign"
    ],
    "controls": [
      "climate-adjusted design basis",
      "drainage",
      "waterproofing",
      "redundant monitoring",
      "no permanent heat sources in tunnels",
      "emergency access plans",
      "geographically distributed primary genebanks"
    ],
    "does_not_prove": [
      "The seed chambers did not flood, and the event did not demonstrate loss of the collection."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Svalbard event was a near miss, not a loss of the seed collection. Water entered the access tunnel, while the stored seeds remained beyond the affected boundary. Keeping those locations distinct is essential to an accurate account.",
          "The event provides a reason to revisit environmental assumptions and engineering protections. A successful boundary can coexist with a need to improve the approach to that boundary. Resilience reviews should therefore learn from contained incidents rather than treating the absence of damage as proof that nothing needs to change."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "availability moderate; integrity/provenance preserved; environmental resilience high; genetic-resource consequence potentially global.",
    "proposed_score_notes": "Suggested GER: GER-5. GPR: not directly applicable; note irreplaceability of unique accessions. Suggested GPI: GPI-5 for intact deposited inventory, subject to depositor records.",
    "clusters": [
      "Genetic-resource resilience"
    ],
    "related_case_ids": [
      "GS-CASE-010",
      "GS-CASE-056",
      "GS-CASE-057",
      "GS-CASE-058"
    ],
    "related_comparisons": [
      {
        "case_number": "010",
        "text": "Compare Agricultural genetic resources for genetic resource resilience. This case focuses on environmental assumptions expire."
      },
      {
        "case_number": "056",
        "text": "Compare ICARDA Aleppo And The First Svalbard Withdrawal for genetic-resource disaster recovery. This case focuses on environmental assumptions expire."
      },
      {
        "case_number": "057",
        "text": "Compare The Vavilov Collection During The Siege Of Leningrad for human custodianship as a security control. This case focuses on environmental assumptions expire."
      },
      {
        "case_number": "058",
        "text": "Compare Pavlovsk Experiment Station Development Threat for land-use governance can destroy genetic assets. This case focuses on environmental assumptions expire."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Svalbard event was a near miss, not a loss of the seed collection. Water entered the access tunnel, while the stored seeds remained beyond the affected boundary. Keeping those locations distinct is essential to an accurate account.",
          "The event provides a reason to revisit environmental assumptions and engineering protections. A successful boundary can coexist with a need to improve the approach to that boundary. Resilience reviews should therefore learn from contained incidents rather than treating the absence of damage as proof that nothing needs to change."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Syria / Norway / Lebanon / Morocco",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "regional genebank",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns duplicated crop accessions and regeneration records. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Genetic-Resource Disaster Recovery identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows duplicated crop accessions and regeneration records through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-056",
    "case_number": "056",
    "slug": "/cases/056-icarda-aleppo-svalbard-withdrawal/",
    "title": "The Backup Was Used: Syria's War Activated the Seed Vault",
    "short_title": "ICARDA Aleppo And The First Svalbard Withdrawal",
    "summary": "Conflict disrupted access to ICARDA's Aleppo genebank, leading to the first withdrawal from Svalbard in 2015 so collections could be regenerated in Morocco and Lebanon and later re-deposited.",
    "direct_answer": "Conflict disrupted access to ICARDA's Aleppo genebank, leading to the first withdrawal from Svalbard in 2015 so collections could be regenerated in Morocco and Lebanon and later re-deposited.",
    "event_label": "2015 onward",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "historical_case",
    "genetic_asset_type": "Duplicated crop accessions and regeneration records",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case056source1",
      "case056source2"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Genetic-Resource Disaster Recovery",
    "processing": "regional genebank → pre-crisis duplication → armed conflict → operational loss → vault withdrawal → regeneration at new sites → re-deposit",
    "direct_parties": "ICARDA collections, staff, and resource users",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Geographic duplication, tested withdrawal procedures, viability monitoring, regeneration funding, conflict contingency plans, accession-level provenance, and reciprocal backup agreements.",
    "limitations": "Avoid saying every Aleppo sample was destroyed. The key problem was loss of access and operational continuity.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-056",
    "family_codes": [
      "GR"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "ICARDA Aleppo first Svalbard seed withdrawal",
    "status": "historical_case",
    "jurisdictions": [
      "Syria",
      "Norway",
      "Lebanon",
      "Morocco"
    ],
    "asset_classes": [
      "Duplicated crop accessions and regeneration records"
    ],
    "threat_codes": [
      "Genetic-Resource Disaster Recovery"
    ],
    "imported": true,
    "threat_chain": [
      "regional genebank",
      "pre-crisis duplication",
      "armed conflict",
      "operational loss",
      "vault withdrawal",
      "regeneration at new sites",
      "re-deposit"
    ],
    "controls": [
      "geographic duplication",
      "tested withdrawal procedures",
      "viability monitoring",
      "regeneration funding",
      "conflict contingency plans",
      "accession-level provenance",
      "reciprocal backup agreements"
    ],
    "does_not_prove": [
      "Avoid saying every Aleppo sample was destroyed. The key problem was loss of access and operational continuity."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "ICARDA's use of its Svalbard duplicates made backup arrangements operational. Preserved accessions supported regeneration and continuity when conflict disrupted work associated with the Aleppo collection. The important distinction is loss of access and operating capacity, not an assumption that every original sample was destroyed.",
          "A backup needs a path back into use. Withdrawal procedures, suitable sites, staff, funding, and records that connect regenerated material to its accession all matter. The case shows why disaster recovery for genetic resources includes biological work and institutional continuity as well as storage."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "availability critical; integrity/provenance critical; confidentiality low; resilience and custody high.",
    "proposed_score_notes": "Suggested GER: GER-5. Genetic-resource persistence: extreme because some accessions may be unique. Suggested GPI: GPI-5 if accession identities and regeneration histories remain linked.",
    "clusters": [
      "Genetic-resource resilience"
    ],
    "related_case_ids": [
      "GS-CASE-010",
      "GS-CASE-055",
      "GS-CASE-057",
      "GS-CASE-058"
    ],
    "related_comparisons": [
      {
        "case_number": "010",
        "text": "Compare Agricultural genetic resources for genetic resource resilience. This case focuses on genetic-resource disaster recovery."
      },
      {
        "case_number": "055",
        "text": "Compare Svalbard Seed Vault Water Intrusion for environmental assumptions expire. This case focuses on genetic-resource disaster recovery."
      },
      {
        "case_number": "057",
        "text": "Compare The Vavilov Collection During The Siege Of Leningrad for human custodianship as a security control. This case focuses on genetic-resource disaster recovery."
      },
      {
        "case_number": "058",
        "text": "Compare Pavlovsk Experiment Station Development Threat for land-use governance can destroy genetic assets. This case focuses on genetic-resource disaster recovery."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "ICARDA's use of its Svalbard duplicates made backup arrangements operational. Preserved accessions supported regeneration and continuity when conflict disrupted work associated with the Aleppo collection. The important distinction is loss of access and operating capacity, not an assumption that every original sample was destroyed.",
          "A backup needs a path back into use. Withdrawal procedures, suitable sites, staff, funding, and records that connect regenerated material to its accession all matter. The case shows why disaster recovery for genetic resources includes biological work and institutional continuity as well as storage."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Soviet Union / Leningrad",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "global collection",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns seed, crop, and living collections. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Human Custodianship as a Security Control identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows seed, crop, and living collections through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-057",
    "case_number": "057",
    "slug": "/cases/057-vavilov-seed-bank-siege-leningrad/",
    "title": "The Seeds They Would Not Eat: Protecting Genetic Resources During Siege",
    "short_title": "The Vavilov Collection During The Siege Of Leningrad",
    "summary": "During the Siege of Leningrad, staff guarded the Vavilov Institute's seed and crop collections despite starvation, preserving genetic resources whose scientific and food-security value exceeded their immediate caloric value.",
    "direct_answer": "During the Siege of Leningrad, staff guarded the Vavilov Institute's seed and crop collections despite starvation, preserving genetic resources whose scientific and food-security value exceeded their immediate caloric value.",
    "event_label": "1941–1944",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "historical_case",
    "genetic_asset_type": "Seed, crop, and living collections",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 0,
    "sources": [
      "case057source1"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Human Custodianship as a Security Control",
    "processing": "global collection → wartime siege → starvation and institutional isolation → human protection of accessions → postwar continuity",
    "direct_parties": "Collection staff and the resources under their care",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Staff continuity plans, distributed duplicates, emergency rations and power, protected-site status, crisis governance, and digitized accession records stored elsewhere.",
    "limitations": "The historical account does not establish every popular anecdote or prove that no material was lost.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-057",
    "family_codes": [
      "GR"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "Vavilov seed bank Siege of Leningrad",
    "status": "historical_case",
    "jurisdictions": [
      "Soviet Union",
      "Leningrad"
    ],
    "asset_classes": [
      "Seed, crop, and living collections"
    ],
    "threat_codes": [
      "Human Custodianship as a Security Control"
    ],
    "imported": true,
    "threat_chain": [
      "global collection",
      "wartime siege",
      "starvation and institutional isolation",
      "human protection of accessions",
      "postwar continuity"
    ],
    "controls": [
      "staff continuity plans",
      "distributed duplicates",
      "emergency rations and power",
      "protected-site status",
      "crisis governance",
      "digitized accession records stored elsewhere"
    ],
    "does_not_prove": [
      "The historical account does not establish every popular anecdote or prove that no material was lost."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Vavilov collection's wartime history highlights the role of people in preserving scientific resources under extreme conditions. Institutional and historical accounts describe stewardship during the siege, while individual anecdotes and loss totals require care because retellings vary.",
          "The security lesson should not depend on celebrating avoidable sacrifice. A credible continuity plan protects the staff who maintain the collection and supplies the resources they need. Distributed copies, accessible records, and emergency support help turn personal commitment into a sustainable preservation system."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "availability and physical integrity critical; provenance high; environmental and human risk extreme.",
    "proposed_score_notes": "Suggested GER: GER-5. Genetic-resource persistence: potentially irreversible. Suggested GPI: GPI-3/4 where wartime records survived.",
    "clusters": [
      "Genetic-resource resilience"
    ],
    "related_case_ids": [
      "GS-CASE-010",
      "GS-CASE-055",
      "GS-CASE-056",
      "GS-CASE-058"
    ],
    "related_comparisons": [
      {
        "case_number": "010",
        "text": "Compare Agricultural genetic resources for genetic resource resilience. This case focuses on human custodianship as a security control."
      },
      {
        "case_number": "055",
        "text": "Compare Svalbard Seed Vault Water Intrusion for environmental assumptions expire. This case focuses on human custodianship as a security control."
      },
      {
        "case_number": "056",
        "text": "Compare ICARDA Aleppo And The First Svalbard Withdrawal for genetic-resource disaster recovery. This case focuses on human custodianship as a security control."
      },
      {
        "case_number": "058",
        "text": "Compare Pavlovsk Experiment Station Development Threat for land-use governance can destroy genetic assets. This case focuses on human custodianship as a security control."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Vavilov collection's wartime history highlights the role of people in preserving scientific resources under extreme conditions. Institutional and historical accounts describe stewardship during the siege, while individual anecdotes and loss totals require care because retellings vary.",
          "The security lesson should not depend on celebrating avoidable sacrifice. A credible continuity plan protects the staff who maintain the collection and supplies the resources they need. Distributed copies, accessible records, and emergency support help turn personal commitment into a sustainable preservation system."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Russia",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "living collection on land",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns living fruit and berry accessions and station land. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Land-Use Governance Can Destroy Genetic Assets identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows living fruit and berry accessions and station land through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-058",
    "case_number": "058",
    "slug": "/cases/058-pavlovsk-experiment-station-land-threat/",
    "title": "Pavlovsk: When a Living Gene Bank Was Mistaken for Vacant Land",
    "short_title": "Pavlovsk Experiment Station Development Threat",
    "summary": "Plans to transfer or develop land at Russia's Pavlovsk Experiment Station threatened living fruit and berry collections that could not simply be copied as packets of seed, prompting an international preservation campaign.",
    "direct_answer": "Plans to transfer or develop land at Russia's Pavlovsk Experiment Station threatened living fruit and berry collections that could not simply be copied as packets of seed, prompting an international preservation campaign.",
    "event_label": "2010 development dispute",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "governance_dispute",
    "genetic_asset_type": "Living fruit and berry accessions and station land",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 1,
    "sources": [
      "case058source1"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Land-Use Governance Can Destroy Genetic Assets",
    "processing": "living collection on land → administrative classification/development plan → potential habitat removal → irreversible accession loss → advocacy and reprieve",
    "direct_parties": "Collection custodians and users of the germplasm",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Legal protected status, geospatial accession registry, off-site clonal backups, cryopreservation where feasible, land-title review, and executive escalation triggers.",
    "limitations": "This was a threatened-loss case; it does not establish that the collection was destroyed.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-058",
    "family_codes": [
      "GR"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "Pavlovsk seed bank development threat 2010",
    "status": "governance_dispute",
    "jurisdictions": [
      "Russia"
    ],
    "asset_classes": [
      "Living fruit and berry accessions and station land"
    ],
    "threat_codes": [
      "Land-Use Governance Can Destroy Genetic Assets"
    ],
    "imported": true,
    "threat_chain": [
      "living collection on land",
      "administrative classification/development plan",
      "potential habitat removal",
      "irreversible accession loss",
      "advocacy and reprieve"
    ],
    "controls": [
      "legal protected status",
      "geospatial accession registry",
      "off-site clonal backups",
      "cryopreservation where feasible",
      "land-title review",
      "executive escalation triggers"
    ],
    "does_not_prove": [
      "This was a threatened-loss case; it does not establish that the collection was destroyed."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Pavlovsk's living collections made a land-use decision a genetic-resource issue. A cultivated accession cannot always be moved or duplicated as if it were a packet in a storage cabinet. The site and ongoing care are part of the asset.",
          "This is a threatened-loss case, not a report that the collection was destroyed. It illustrates how administrative systems can overlook scientific value when they classify land without recognizing the material growing on it. Accession maps and legal protection help make that value visible before a development decision becomes irreversible."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "availability and integrity critical; provenance high; persistence/irreplaceability extreme.",
    "proposed_score_notes": "Suggested GER: GER-5. Suggested GPI: GPI-4 if accessions are well mapped.",
    "clusters": [
      "Genetic-resource resilience"
    ],
    "related_case_ids": [
      "GS-CASE-010",
      "GS-CASE-055",
      "GS-CASE-056",
      "GS-CASE-057"
    ],
    "related_comparisons": [
      {
        "case_number": "010",
        "text": "Compare Agricultural genetic resources for genetic resource resilience. This case focuses on land-use governance can destroy genetic assets."
      },
      {
        "case_number": "055",
        "text": "Compare Svalbard Seed Vault Water Intrusion for environmental assumptions expire. This case focuses on land-use governance can destroy genetic assets."
      },
      {
        "case_number": "056",
        "text": "Compare ICARDA Aleppo And The First Svalbard Withdrawal for genetic-resource disaster recovery. This case focuses on land-use governance can destroy genetic assets."
      },
      {
        "case_number": "057",
        "text": "Compare The Vavilov Collection During The Siege Of Leningrad for human custodianship as a security control. This case focuses on land-use governance can destroy genetic assets."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Pavlovsk's living collections made a land-use decision a genetic-resource issue. A cultivated accession cannot always be moved or duplicated as if it were a packet in a storage cabinet. The site and ongoing care are part of the asset.",
          "This is a threatened-loss case, not a report that the collection was destroyed. It illustrates how administrative systems can overlook scientific value when they classify land without recognizing the material growing on it. Accession maps and legal protection help make that value visible before a development decision becomes irreversible."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Mexico / United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "landrace acquisition",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns yellow bean germplasm, patent claims, and prior-art records. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Genetic Resource Misappropriation identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows yellow bean germplasm, patent claims, and prior-art records through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-059",
    "case_number": "059",
    "slug": "/cases/059-enola-bean-patent-genetic-resource/",
    "title": "The Enola Bean: When a Mexican Landrace Became a U.S. Patent",
    "short_title": "The Enola Bean Patent",
    "summary": "The Enola bean patent controversy arose after a U.S. breeder obtained protection for a yellow bean developed from Mexican beans, then asserted rights that affected imports. The patent was ultimately invalidated after a long challenge.",
    "direct_answer": "The Enola bean patent controversy arose after a U.S. breeder obtained protection for a yellow bean developed from Mexican beans, then asserted rights that affected imports. The patent was ultimately invalidated after a long challenge.",
    "event_label": "1999–2009",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "court_case",
    "genetic_asset_type": "Yellow bean germplasm, patent claims, and prior-art records",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case059source1",
      "case059source2"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Genetic Resource Misappropriation",
    "processing": "landrace acquisition → selection/patent filing → enforcement at border/market → prior-art and genetic comparison → challenge → revocation",
    "direct_parties": "Growers, importers, and custodians of relevant germplasm",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Defensive publication, accession timestamps, sequence/phenotype records, origin documentation, benefit-sharing agreements, and patent-examiner access to germplasm databases.",
    "limitations": "It does not mean all plant breeding patents are illegitimate or that selection can never be inventive.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-059",
    "family_codes": [
      "GR"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "Enola bean patent revoked biopiracy",
    "status": "court_case",
    "jurisdictions": [
      "Mexico",
      "United States"
    ],
    "asset_classes": [
      "Yellow bean germplasm, patent claims, and prior-art records"
    ],
    "threat_codes": [
      "Genetic Resource Misappropriation"
    ],
    "imported": true,
    "threat_chain": [
      "landrace acquisition",
      "selection/patent filing",
      "enforcement at border/market",
      "prior-art and genetic comparison",
      "challenge",
      "revocation"
    ],
    "controls": [
      "defensive publication",
      "accession timestamps",
      "sequence/phenotype records",
      "origin documentation",
      "benefit-sharing agreements",
      "patent-examiner access to germplasm databases"
    ],
    "does_not_prove": [
      "It does not mean all plant breeding patents are illegitimate or that selection can never be inventive."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Enola bean dispute connected genetic-resource provenance with an exclusivity claim. Records of existing material and prior art became important to challenging the patent. Critics' descriptions of misappropriation should remain distinguishable from the legal grounds and outcome of the proceedings.",
          "The broader lesson is that a genebank record can protect access as well as support research. Dates, origin information, and defensible accession histories help establish what existed before a claim. The case does not establish that all plant patents are improper or that selection can never produce a patentable invention."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "provenance critical; availability/access high; integrity of patent examination high; community consent and benefit sharing high.",
    "proposed_score_notes": "Suggested GER: GER-4/5. Suggested GPI: GPI-5 where accession history proves prior existence.",
    "clusters": [
      "Genetic-resource control"
    ],
    "related_case_ids": [
      "GS-CASE-060",
      "GS-CASE-061",
      "GS-CASE-064"
    ],
    "related_comparisons": [
      {
        "case_number": "060",
        "text": "Compare Bowman v. Monsanto for control of replicating genetic technology. This case focuses on genetic resource misappropriation."
      },
      {
        "case_number": "061",
        "text": "Compare Association For Molecular Pathology v. Myriad for ownership boundaries around genetic information. This case focuses on genetic resource misappropriation."
      },
      {
        "case_number": "064",
        "text": "Compare Digital Sequence Information And The Cali Fund for benefit sharing after digitization. This case focuses on genetic resource misappropriation."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Enola bean dispute connected genetic-resource provenance with an exclusivity claim. Records of existing material and prior art became important to challenging the patent. Critics' descriptions of misappropriation should remain distinguishable from the legal grounds and outcome of the proceedings.",
          "The broader lesson is that a genebank record can protect access as well as support research. Dates, origin information, and defensible accession histories help establish what existed before a claim. The case does not establish that all plant patents are improper or that selection can never produce a patentable invention."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "patented trait enters commodity stream",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns patented soybean seed and subsequent generations. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Control of Replicating Genetic Technology identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows patented soybean seed and subsequent generations through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-060",
    "case_number": "060",
    "slug": "/cases/060-bowman-monsanto-self-replicating-seed/",
    "title": "Bowman v. Monsanto: Patent Exhaustion Meets a Self-Replicating Seed",
    "short_title": "Bowman v. Monsanto",
    "summary": "The U.S. Supreme Court held that patent exhaustion did not permit Vernon Bowman to reproduce patented Roundup Ready soybeans by planting commodity seed and harvesting new generations without Monsanto's authorization.",
    "direct_answer": "The U.S. Supreme Court held that patent exhaustion did not permit Vernon Bowman to reproduce patented Roundup Ready soybeans by planting commodity seed and harvesting new generations without Monsanto's authorization.",
    "event_label": "2013",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "court_case",
    "genetic_asset_type": "Patented soybean seed and subsequent generations",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 2,
    "sources": [
      "case060source1",
      "case060source2"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Control of Replicating Genetic Technology",
    "processing": "patented trait enters commodity stream → farmer plants and selects → new seed generation → infringement claim → Supreme Court rule",
    "direct_parties": "The farmer and patent holder in the litigation",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Clear licenses, seed-lot provenance, coexistence protocols, contamination dispute procedures, trait testing, and preservation of public-domain germplasm.",
    "limitations": "It did not decide every question involving accidental contamination, all self-replicating technologies, or ordinary unpatented seed saving.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-060",
    "family_codes": [
      "GR"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "Bowman v Monsanto seed patent Supreme Court",
    "status": "court_case",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Patented soybean seed and subsequent generations"
    ],
    "threat_codes": [
      "Control of Replicating Genetic Technology"
    ],
    "imported": true,
    "threat_chain": [
      "patented trait enters commodity stream",
      "farmer plants and selects",
      "new seed generation",
      "infringement claim",
      "Supreme Court rule"
    ],
    "controls": [
      "clear licenses",
      "seed-lot provenance",
      "coexistence protocols",
      "contamination dispute procedures",
      "trait testing",
      "preservation of public-domain germplasm"
    ],
    "does_not_prove": [
      "It did not decide every question involving accidental contamination, all self-replicating technologies, or ordinary unpatented seed saving."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Bowman v. Monsanto addressed reproduction of patented seed after commodity soybeans were planted and selected. The Court's analysis concerned making new patented articles; it should not be extended automatically to accidental contamination or every technology capable of replication.",
          "The genetic-security connection is control of an asset that can reproduce. A physical transfer and permission to produce further generations are distinct questions. Clear terms and traceable seed histories help explain that boundary without treating every dispute over agricultural genetics as a confidentiality failure."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality low; integrity/provenance high; availability/access and control high; consent/license central.",
    "proposed_score_notes": "Suggested GER: GER-4 for agricultural market networks. Suggested GPI: GPI-4 when trait and seed history are traceable.",
    "clusters": [
      "Genetic-resource control"
    ],
    "related_case_ids": [
      "GS-CASE-059",
      "GS-CASE-061",
      "GS-CASE-064"
    ],
    "related_comparisons": [
      {
        "case_number": "059",
        "text": "Compare The Enola Bean Patent for genetic resource misappropriation. This case focuses on control of replicating genetic technology."
      },
      {
        "case_number": "061",
        "text": "Compare Association For Molecular Pathology v. Myriad for ownership boundaries around genetic information. This case focuses on control of replicating genetic technology."
      },
      {
        "case_number": "064",
        "text": "Compare Digital Sequence Information And The Cali Fund for benefit sharing after digitization. This case focuses on control of replicating genetic technology."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Bowman v. Monsanto addressed reproduction of patented seed after commodity soybeans were planted and selected. The Court's analysis concerned making new patented articles; it should not be extended automatically to accidental contamination or every technology capable of replication.",
          "The genetic-security connection is control of an asset that can reproduce. A physical transfer and permission to produce further generations are distinct questions. Clear terms and traceable seed histories help explain that boundary without treating every dispute over agricultural genetics as a confidentiality failure."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "United States",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "gene discovery",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "law_enforcement": false,
    "commercial": false,
    "research": true,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns human dna patent claims and genetic-testing access. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Ownership Boundaries Around Genetic Information identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows human dna patent claims and genetic-testing access through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-061",
    "case_number": "061",
    "slug": "/cases/061-myriad-human-gene-patents/",
    "title": "Myriad: Can a Naturally Occurring Human Gene Be Patented?",
    "short_title": "Association For Molecular Pathology v. Myriad",
    "summary": "The U.S. Supreme Court unanimously held that a naturally occurring DNA segment is not patent eligible merely because it was isolated, while distinguishing laboratory-created cDNA.",
    "direct_answer": "The U.S. Supreme Court unanimously held that a naturally occurring DNA segment is not patent eligible merely because it was isolated, while distinguishing laboratory-created cDNA.",
    "event_label": "2013",
    "sector": "Consent, ownership, and biospecimens",
    "event_type": "court_case",
    "genetic_asset_type": "Human DNA patent claims and genetic-testing access",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "historical_governance_case",
    "primary_source_count": 1,
    "sources": [
      "case061source1"
    ],
    "parent_hub": "/privacy/",
    "security_principle": "Ownership Boundaries Around Genetic Information",
    "processing": "gene discovery → patent claims → exclusive testing/control → legal challenge → narrowed patent boundary",
    "direct_parties": "Parties challenging and defending the patent claims",
    "indirect_parties": "Relatives and connected participants may be relevant where the asset contains relationship information.",
    "consent_status": "Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.",
    "mitigations": "Public variant databases, transparent evidence sharing, licensing review, interoperability, and clear separation of natural sequence from engineered application.",
    "limitations": "It did not make every genetic invention unpatentable, decide methods, or prohibit patents on altered sequences and applications.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-061",
    "family_codes": [
      "CO"
    ],
    "family": "Consent, ownership, and biospecimens",
    "primary_query": "Myriad Genetics Supreme Court human gene patent",
    "status": "court_case",
    "jurisdictions": [
      "United States"
    ],
    "asset_classes": [
      "Human DNA patent claims and genetic-testing access"
    ],
    "threat_codes": [
      "Ownership Boundaries Around Genetic Information"
    ],
    "imported": true,
    "threat_chain": [
      "gene discovery",
      "patent claims",
      "exclusive testing/control",
      "legal challenge",
      "narrowed patent boundary"
    ],
    "controls": [
      "public variant databases",
      "transparent evidence sharing",
      "licensing review",
      "interoperability",
      "clear separation of natural sequence from engineered application"
    ],
    "does_not_prove": [
      "It did not make every genetic invention unpatentable, decide methods, or prohibit patents on altered sequences and applications."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Myriad decision distinguished naturally occurring DNA from the claimed laboratory-created cDNA at issue. It concerned patent eligibility, not a finding that every genetic invention, method, or application is outside patent protection.",
          "The case belongs in this collection because control over genetic information can affect access to testing and the use of knowledge. It is not a cybersecurity incident. Describing the challenged claims and the Court's limits makes that access question clearer than a universal slogan about whether anyone can own genes."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality secondary; availability/access critical; provenance and intellectual control high; consent indirect.",
    "proposed_score_notes": "Suggested GER: GER-4 because affected testing populations are broad. GPR: not the main analytical axis. GPI: relevant to variant evidence databases, not the holding itself.",
    "clusters": [
      "Genetic-resource control"
    ],
    "related_case_ids": [
      "GS-CASE-059",
      "GS-CASE-060",
      "GS-CASE-064"
    ],
    "related_comparisons": [
      {
        "case_number": "059",
        "text": "Compare The Enola Bean Patent for genetic resource misappropriation. This case focuses on ownership boundaries around genetic information."
      },
      {
        "case_number": "060",
        "text": "Compare Bowman v. Monsanto for control of replicating genetic technology. This case focuses on ownership boundaries around genetic information."
      },
      {
        "case_number": "064",
        "text": "Compare Digital Sequence Information And The Cali Fund for benefit sharing after digitization. This case focuses on ownership boundaries around genetic information."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "The Myriad decision distinguished naturally occurring DNA from the claimed laboratory-created cDNA at issue. It concerned patent eligibility, not a finding that every genetic invention, method, or application is outside patent protection.",
          "The case belongs in this collection because control over genetic information can affect access to testing and the use of knowledge. It is not a cybersecurity incident. Describing the challenged claims and the Court's limits makes that access question clearer than a universal slogan about whether anyone can own genes."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "commercial preference",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns cavendish cultivars and planting material. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Genetic Monoculture Risk identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows cavendish cultivars and planting material through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-062",
    "case_number": "062",
    "slug": "/cases/062-cavendish-banana-tr4-genetic-uniformity/",
    "title": "Cavendish vs. TR4: The Security Cost of a Clone Army",
    "short_title": "Cavendish Bananas And Tropical Race 4",
    "summary": "The globally important Cavendish banana trade depends heavily on clonally propagated, genetically similar plants, allowing Fusarium wilt Tropical Race 4 to exploit a broadly shared susceptibility.",
    "direct_answer": "The globally important Cavendish banana trade depends heavily on clonally propagated, genetically similar plants, allowing Fusarium wilt Tropical Race 4 to exploit a broadly shared susceptibility.",
    "event_label": "Ongoing crop-disease threat",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "historical_case",
    "genetic_asset_type": "Cavendish cultivars and planting material",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case062source1",
      "case062source2"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Genetic Monoculture Risk",
    "processing": "commercial preference → clonal uniformity → shared susceptibility → soil-borne pathogen spread → regional quarantine/loss → breeding and diversification response",
    "direct_parties": "Growers and food-system participants affected by disease risk",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Portfolio diversity, resistant cultivars, wild-relative conservation, clean planting material, surveillance, quarantine, soil hygiene, and distributed breeding programs.",
    "limitations": "Cavendish bananas are not the only bananas, and TR4 does not imply immediate global disappearance.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-062",
    "family_codes": [
      "GR"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "Cavendish banana genetic diversity TR4 risk",
    "status": "historical_case",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Cavendish cultivars and planting material"
    ],
    "threat_codes": [
      "Genetic Monoculture Risk"
    ],
    "imported": true,
    "threat_chain": [
      "commercial preference",
      "clonal uniformity",
      "shared susceptibility",
      "soil-borne pathogen spread",
      "regional quarantine/loss",
      "breeding and diversification response"
    ],
    "controls": [
      "portfolio diversity",
      "resistant cultivars",
      "wild-relative conservation",
      "clean planting material",
      "surveillance",
      "quarantine",
      "soil hygiene",
      "distributed breeding programs"
    ],
    "does_not_prove": [
      "Cavendish bananas are not the only bananas, and TR4 does not imply immediate global disappearance."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Cavendish production illustrates the tradeoff between a standardized crop and shared susceptibility. Clonal similarity can support consistent production while making a disease threat relevant across a broad network of growers.",
          "The case does not predict the disappearance of every banana. Other varieties, locations, and production systems need separate consideration. The resilience question is how breeding, conservation, clean material, and surveillance can reduce dependence on a narrow set of options when biological change cannot be handled through a quick operational patch."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "availability critical; genetic-resource diversity and resilience critical; provenance high; confidentiality low.",
    "proposed_score_notes": "Suggested GER: GER-5. Genetic-resource persistence: high because susceptible production systems cannot be “patched” quickly. Suggested GPI: GPI-4 for breeding materials.",
    "clusters": [
      "Genetic-resource resilience"
    ],
    "related_case_ids": [
      "GS-CASE-010",
      "GS-CASE-055",
      "GS-CASE-056",
      "GS-CASE-057"
    ],
    "related_comparisons": [
      {
        "case_number": "010",
        "text": "Compare Agricultural genetic resources for genetic resource resilience. This case focuses on genetic monoculture risk."
      },
      {
        "case_number": "055",
        "text": "Compare Svalbard Seed Vault Water Intrusion for environmental assumptions expire. This case focuses on genetic monoculture risk."
      },
      {
        "case_number": "056",
        "text": "Compare ICARDA Aleppo And The First Svalbard Withdrawal for genetic-resource disaster recovery. This case focuses on genetic monoculture risk."
      },
      {
        "case_number": "057",
        "text": "Compare The Vavilov Collection During The Siege Of Leningrad for human custodianship as a security control. This case focuses on genetic monoculture risk."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Cavendish production illustrates the tradeoff between a standardized crop and shared susceptibility. Clonal similarity can support consistent production while making a disease threat relevant across a broad network of growers.",
          "The case does not predict the disappearance of every banana. Other varieties, locations, and production systems need separate consideration. The resilience question is how breeding, conservation, clean material, and surveillance can reduce dependence on a narrow set of options when biological change cannot be handled through a quick operational patch."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "Ireland",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "narrow crop base + dependency",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns potato crops and a dependent food system. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Diversity Is a Security Control identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows potato crops and a dependent food system through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-063",
    "case_number": "063",
    "slug": "/cases/063-irish-potato-famine-genetic-diversity/",
    "title": "The Irish Potato Famine: When Uniformity Turned Blight into Catastrophe",
    "short_title": "The Irish Potato Famine And Crop Uniformity",
    "summary": "Low crop diversity contributed to the vulnerability of Ireland's potato-dependent food system when late blight arrived, but the resulting famine was also shaped by political, economic, land-tenure, and relief failures.",
    "direct_answer": "Low crop diversity contributed to the vulnerability of Ireland's potato-dependent food system when late blight arrived, but the resulting famine was also shaped by political, economic, land-tenure, and relief failures.",
    "event_label": "1840s–1850s",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "historical_case",
    "genetic_asset_type": "Potato crops and a dependent food system",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case063source1",
      "case063source2"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Diversity Is a Security Control",
    "processing": "narrow crop base + dependency → pathogen arrival → repeated harvest loss → policy/economic failure → humanitarian catastrophe",
    "direct_parties": "People affected by crop failure and famine",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Crop and varietal diversity, resistant breeding, decentralized seed systems, disease surveillance, social safety nets, and protection against single-crop dependency.",
    "limitations": "The famine cannot be explained by genetics alone, and Irish agriculture was not literally one genotype everywhere.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-063",
    "family_codes": [
      "GR"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "Irish potato famine genetic diversity monoculture",
    "status": "historical_case",
    "jurisdictions": [
      "Ireland"
    ],
    "asset_classes": [
      "Potato crops and a dependent food system"
    ],
    "threat_codes": [
      "Diversity Is a Security Control"
    ],
    "imported": true,
    "threat_chain": [
      "narrow crop base + dependency",
      "pathogen arrival",
      "repeated harvest loss",
      "policy/economic failure",
      "humanitarian catastrophe"
    ],
    "controls": [
      "crop and varietal diversity",
      "resistant breeding",
      "decentralized seed systems",
      "disease surveillance",
      "social safety nets",
      "protection against single-crop dependency"
    ],
    "does_not_prove": [
      "The famine cannot be explained by genetics alone, and Irish agriculture was not literally one genotype everywhere."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Late blight struck a food system whose vulnerability extended beyond the crop itself. Diversity and crop dependence belong in the account, but political, economic, land-tenure, and relief failures shaped the human catastrophe. A biological explanation alone is inadequate.",
          "The security lesson therefore joins agricultural resilience with the conditions that turn harvest loss into hunger. Varietal diversity can reduce one dependency; it does not replace access to food, effective relief, or social protection. The case is a warning against explaining a humanitarian disaster through a single genetic variable."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "availability critical; resilience critical; provenance of varieties important; population consequence GER-5.",
    "proposed_score_notes": "Suggested GER: GER-5. Genetic-resource persistence: high. Suggested GPI: historical/uncertain; do not force a numeric score without adequate records.",
    "clusters": [
      "Genetic-resource resilience"
    ],
    "related_case_ids": [
      "GS-CASE-010",
      "GS-CASE-055",
      "GS-CASE-056",
      "GS-CASE-057"
    ],
    "related_comparisons": [
      {
        "case_number": "010",
        "text": "Compare Agricultural genetic resources for genetic resource resilience. This case focuses on diversity is a security control."
      },
      {
        "case_number": "055",
        "text": "Compare Svalbard Seed Vault Water Intrusion for environmental assumptions expire. This case focuses on diversity is a security control."
      },
      {
        "case_number": "056",
        "text": "Compare ICARDA Aleppo And The First Svalbard Withdrawal for genetic-resource disaster recovery. This case focuses on diversity is a security control."
      },
      {
        "case_number": "057",
        "text": "Compare The Vavilov Collection During The Siege Of Leningrad for human custodianship as a security control. This case focuses on diversity is a security control."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Late blight struck a food system whose vulnerability extended beyond the crop itself. Diversity and crop dependence belong in the account, but political, economic, land-tenure, and relief failures shaped the human catastrophe. A biological explanation alone is inadequate.",
          "The security lesson therefore joins agricultural resilience with the conditions that turn harvest loss into hunger. Varietal diversity can reduce one dependency; it does not replace access to food, effective relief, or social protection. The case is a warning against explaining a humanitarian disaster through a single genetic variable."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "International",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "physical genetic resource",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": true,
    "confidentiality_impact": "The confidentiality question concerns digital sequence information and origin metadata. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Benefit Sharing After Digitization identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows digital sequence information and origin metadata through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-064",
    "case_number": "064",
    "slug": "/cases/064-digital-sequence-information-cali-fund/",
    "title": "The Cali Fund: Who Benefits When Genetic Resources Become Data?",
    "short_title": "Digital Sequence Information And The Cali Fund",
    "summary": "The Convention on Biological Diversity's multilateral mechanism for digital sequence information, including the Cali Fund, addresses a central genetic-governance problem: sequence data can circulate globally even when physical genetic resources are governed by access-and-benefit-sharing rules.",
    "direct_answer": "The Convention on Biological Diversity's multilateral mechanism for digital sequence information, including the Cali Fund, addresses a central genetic-governance problem: sequence data can circulate globally even when physical genetic resources are governed by access-and-benefit-sharing rules.",
    "event_label": "2024–2025 policy development",
    "sector": "Genetic resources, agriculture, and biodiversity",
    "event_type": "policy_event",
    "genetic_asset_type": "Digital sequence information and origin metadata",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "well_sourced",
    "primary_source_count": 2,
    "sources": [
      "case064source1",
      "case064source2"
    ],
    "parent_hub": "/genetic-resources/",
    "security_principle": "Benefit Sharing After Digitization",
    "processing": "physical genetic resource → sequencing → global digital reuse → commercial/research value → weak traceability to origin → multilateral benefit-sharing mechanism",
    "direct_parties": "Genetic-resource contributors, communities, and data users",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "Access, stewardship, breeding, and benefit-sharing arrangements depend on the collection and setting. These are not necessarily individual privacy questions.",
    "mitigations": "Persistent origin identifiers, machine-readable provenance, community terms, benefit-sharing reporting, database metadata standards, and auditable commercial-use pathways.",
    "limitations": "The mechanism does not settle every definition, payment obligation, database practice, or national implementation question.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-064",
    "family_codes": [
      "GR",
      "PD"
    ],
    "family": "Genetic resources, agriculture, and biodiversity",
    "primary_query": "digital sequence information genetic resources Cali Fund",
    "status": "policy_event",
    "jurisdictions": [
      "International"
    ],
    "asset_classes": [
      "Digital sequence information and origin metadata"
    ],
    "threat_codes": [
      "Benefit Sharing After Digitization"
    ],
    "imported": true,
    "threat_chain": [
      "physical genetic resource",
      "sequencing",
      "global digital reuse",
      "commercial/research value",
      "weak traceability to origin",
      "multilateral benefit-sharing mechanism"
    ],
    "controls": [
      "persistent origin identifiers",
      "machine-readable provenance",
      "community terms",
      "benefit-sharing reporting",
      "database metadata standards",
      "auditable commercial-use pathways"
    ],
    "does_not_prove": [
      "The mechanism does not settle every definition, payment obligation, database practice, or national implementation question."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Digital sequence information can travel and be reused separately from the physical material from which it was produced. The CBD mechanism addresses benefit sharing in that setting, where a record's digital availability does not erase questions about origin and contribution.",
          "The framework's implementation evolves, so this case does not specify a universal payment obligation or settle every national arrangement. The security connection is provenance: keeping origin, terms, and use legible as information moves. Availability and fair participation must be considered together rather than assuming that either open access or restricted access resolves the whole problem."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "provenance critical; availability/open science high; consent and sovereignty high; confidentiality context-dependent.",
    "proposed_score_notes": "Suggested GER: GER-5. Suggested GPI: GPI-2/3 where sequences lose origin and permit metadata.",
    "clusters": [
      "Genetic-resource control"
    ],
    "related_case_ids": [
      "GS-CASE-059",
      "GS-CASE-060",
      "GS-CASE-061"
    ],
    "related_comparisons": [
      {
        "case_number": "059",
        "text": "Compare The Enola Bean Patent for genetic resource misappropriation. This case focuses on benefit sharing after digitization."
      },
      {
        "case_number": "060",
        "text": "Compare Bowman v. Monsanto for control of replicating genetic technology. This case focuses on benefit sharing after digitization."
      },
      {
        "case_number": "061",
        "text": "Compare Association For Molecular Pathology v. Myriad for ownership boundaries around genetic information. This case focuses on benefit sharing after digitization."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Digital sequence information can travel and be reused separately from the physical material from which it was produced. The CBD mechanism addresses benefit sharing in that setting, where a record's digital availability does not erase questions about origin and contribution.",
          "The framework's implementation evolves, so this case does not specify a universal payment obligation or settle every national arrangement. The security connection is provenance: keeping origin, terms, and use legible as information moves. Availability and fair participation must be considered together rather than assuming that either open access or restricted access resolves the whole problem."
        ]
      }
    ]
  },
  {
    "event_date_start": null,
    "event_date_end": null,
    "published_date": null,
    "updated_date": "2026-09-19",
    "organization": null,
    "jurisdiction": "China / Xinjiang / Tibet",
    "country": null,
    "sample_type": null,
    "data_type": null,
    "attack_or_access_vector": "state-directed collection",
    "directly_affected": null,
    "indirectly_affected": null,
    "familial_exposure": null,
    "population_exposure": null,
    "consent_issue": "The account raises questions about authority, voluntariness, and population-level power. Allegations of coercion remain attributed to their source.",
    "law_enforcement": false,
    "commercial": false,
    "research": false,
    "healthcare": null,
    "agricultural": false,
    "confidentiality_impact": "The confidentiality question concerns dna samples and population identification records. Exposure and further inference must be distinguished from the fact of collection or availability.",
    "integrity_impact": "The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Genetic Surveillance of Populations identifies the particular boundary examined here.",
    "availability_impact": "Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.",
    "provenance_impact": "The relevant chain follows dna samples and population identification records through the stages shown below. Missing public detail is not proof that internal records did not exist.",
    "ger_label": null,
    "ger_direct_entities": null,
    "ger_indirect_entities": null,
    "ger_confidence": null,
    "ger_notes": null,
    "gpr_label": null,
    "revocable": null,
    "future_inference_risk": "Later reuse depends on the actual asset and links to other records; no future misuse is asserted.",
    "expected_persistence": "Asset-dependent; not assigned a fixed duration.",
    "gpr_confidence": null,
    "gpi_label": null,
    "sample_provenance_known": null,
    "digital_hashes_present": null,
    "pipeline_version_known": null,
    "reference_version_known": null,
    "custody_documented": null,
    "gpi_confidence": null,
    "source_notes": "Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.",
    "correction_status": "none_recorded",
    "id": "GS-065",
    "case_number": "065",
    "slug": "/cases/065-mass-dna-collection-xinjiang-tibet/",
    "title": "Population DNA Collection: When Genetics Joins the Surveillance Stack",
    "short_title": "Mass DNA Collection In Xinjiang And Tibet",
    "summary": "Human-rights investigations and scientific reporting have documented or alleged large-scale DNA collection programs involving ethnic populations in Xinjiang and Tibet, showing how genetic identifiers can be integrated with broader state surveillance.",
    "direct_answer": "Human-rights investigations and scientific reporting have documented or alleged large-scale DNA collection programs involving ethnic populations in Xinjiang and Tibet, showing how genetic identifiers can be integrated with broader state surveillance.",
    "event_label": "2017–2024 reporting",
    "sector": "State surveillance and population security",
    "event_type": "governance_dispute",
    "genetic_asset_type": "DNA samples and population identification records",
    "ger_level": null,
    "gpr_level": null,
    "gpi_level": null,
    "evidence_status": "alleged",
    "primary_source_count": 3,
    "sources": [
      "case065source1",
      "case065source2",
      "case065source3"
    ],
    "parent_hub": "/policy/",
    "security_principle": "Genetic Surveillance of Populations",
    "processing": "state-directed collection → population database → linkage with identity/biometric systems → familial and group inference → persistent surveillance capability",
    "direct_parties": "Populations described in the cited human-rights reports",
    "indirect_parties": "Connected institutions, communities, or resource users; no affected-person total is assigned.",
    "consent_status": "The account raises questions about authority, voluntariness, and population-level power. Allegations of coercion remain attributed to their source.",
    "mitigations": "Human-rights due diligence, export and end-use controls, procurement transparency, prohibition of coercive collection, independent oversight, deletion rights, familial-search limits, and supplier disengagement triggers.",
    "limitations": "The cited reports do not establish that every resident was sampled, every collected sample was whole-genome sequenced, or every possible downstream abuse occurred.",
    "ger_basis": "No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.",
    "gpr_basis": "Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.",
    "gpi_basis": "A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.",
    "case_id": "GS-CASE-065",
    "family_codes": [
      "SV"
    ],
    "family": "State surveillance and population security",
    "primary_query": "mass DNA collection Xinjiang Tibet surveillance",
    "status": "governance_dispute",
    "jurisdictions": [
      "China",
      "Xinjiang",
      "Tibet"
    ],
    "asset_classes": [
      "DNA samples and population identification records"
    ],
    "threat_codes": [
      "Genetic Surveillance of Populations"
    ],
    "imported": true,
    "threat_chain": [
      "state-directed collection",
      "population database",
      "linkage with identity/biometric systems",
      "familial and group inference",
      "persistent surveillance capability"
    ],
    "controls": [
      "human-rights due diligence",
      "export and end-use controls",
      "procurement transparency",
      "prohibition of coercive collection",
      "independent oversight",
      "deletion rights",
      "familial-search limits",
      "supplier disengagement triggers"
    ],
    "does_not_prove": [
      "The cited reports do not establish that every resident was sampled, every collected sample was whole-genome sequenced, or every possible downstream abuse occurred."
    ],
    "narrative_sections": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Human Rights Watch's reports are the attributed basis for the collection and coercion concerns summarized here. They should not be treated as direct visibility into every operational detail of a state database. Collection practices, equipment procurement, genetic analysis, and later uses require distinct evidence.",
          "The case examines the persistent power that can arise when genetic identifiers are linked with wider identity systems. It does not claim that every resident was sampled, every sample was whole-genome sequenced, or every possible abuse occurred. Specific allegations remain attributed to their sources rather than presented as an independently established account of all program operations."
        ]
      }
    ],
    "last_reviewed": null,
    "source_edition": "2026-09-19",
    "correction_history": [],
    "analysis_notes": "confidentiality critical; integrity/provenance critical; availability favors state operators; consent absent or coercive; persistence maximal; relational exposure population-scale.",
    "proposed_score_notes": "Suggested GER: GER-4/5. Suggested GPR: GPR-5. Suggested GPI: unknown externally; do not fabricate operational details.",
    "clusters": [
      "Community and population governance"
    ],
    "related_case_ids": [
      "GS-CASE-009",
      "GS-CASE-018",
      "GS-CASE-019",
      "GS-CASE-029"
    ],
    "related_comparisons": [
      {
        "case_number": "009",
        "text": "Compare DOJ bulk genomic data for genomic sovereignty / strategic data security. This case focuses on genetic surveillance of populations."
      },
      {
        "case_number": "018",
        "text": "Compare Kennewick Man / The Ancient One for ancestral genomic governance. This case focuses on genetic surveillance of populations."
      },
      {
        "case_number": "019",
        "text": "Compare Chaco Canyon Ancient DNA for community standing survives temporal distance. This case focuses on genetic surveillance of populations."
      },
      {
        "case_number": "029",
        "text": "Compare Kuwait's Universal DNA Law for population-scale collection limits. This case focuses on genetic surveillance of populations."
      }
    ],
    "editorial_analysis": [
      {
        "heading": "The case in context",
        "paragraphs": [
          "Human Rights Watch's reports are the attributed basis for the collection and coercion concerns summarized here. They should not be treated as direct visibility into every operational detail of a state database. Collection practices, equipment procurement, genetic analysis, and later uses require distinct evidence.",
          "The case examines the persistent power that can arise when genetic identifiers are linked with wider identity systems. It does not claim that every resident was sampled, every sample was whole-genome sequenced, or every possible abuse occurred. Specific allegations remain attributed to their sources rather than presented as an independently established account of all program operations."
        ]
      }
    ]
  }
]