Critical Infrastructure Security, Data Security

Major NIH health database’s cyber protections fall short

Health and Technology Stethoscope on Circuit Board blue

The National Institutes of Health's All of Us research database, which stores over 1 million individuals' health records, was found by the Department of Health and Human Services' Office of Inspector General to have lacked appropriate cybersecurity safeguards, FedScoop reports.

All of Us, which includes 607,000 biosamples and 470,000 electronic health records, was found to have access-control weaknesses and unresolved privacy issues. The audit also showed that the NIH failed to confirm limits on who could reach sensitive data, allowed identified vulnerabilities to persist beyond federal remediation timelines, and did not convey national-security concerns tied to genomic information. Inspectors also discovered that internal users could access systems while abroad and could download detailed participant data despite program rules prohibiting such downloads.

NIH agreed with the watchdog's five recommendations. The awardee operating the Data and Research Center has since developed a more formal access-control process and plans to reassess the system's risk level to reflect the sensitivity of genomic data.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds