Strengthening Trust and Leadership: Reflections on National Institutes of Health (NIH) 2026 Community Days: Securing NIH Controlled-Access Data and Our Data Protection Journey | Data Science at NIH
peter.suber's bookmarks 2026-09-04
Summary:
"On April 13 and 14, I had the privilege of leading the National Institutes of Health (NIH) 2026 Community Days: Securing NIH Controlled-Access Data webinars to engage directly with our stakeholders, researchers, and the broader public about the critical work we’re undertaking to protect controlled-access data. These sessions were designed to foster transparency around our security and operational standards, update the community on new resources and requirements, and reinforce our shared responsibility in safeguarding participant trust. I am deeply grateful for the vibrant participation and thoughtful questions that were raised, which underscores the importance and urgency of our mission.
Protecting participants’ trust requires one standard: secure, consistent protections for NIH controlled-access data—whether it is processed within a NIH Controlled-Access Data Repository (CADR) or a research institution’s IT systems. This principle drove the Extramural Community Days agenda, where we discussed not only what needs to be done, but why rigorous data protection is more essential than ever. Our commitment goes beyond compliance; it’s about honoring the trust participants place in us and ensuring the integrity of scientific research that impacts lives.
The risks facing Americans’ health and genomic data are not theoretical—they are real, documented, and evolving. Adversaries seek to leverage diverse datasets for economic gain, surveillance, and even military advantage. We’ve seen threat actors link wearable data (like smartwatches), health records, and geographical information to identify military movements and compromising information on global leaders. Alarmingly, we’re witnessing a 300% increase in data breaches within the healthcare sector and a 37% rise in ransomware attacks.i Most research institutions haven't been required until recently to follow specific security standards, making them softer targets than hospitals or government agencies. The threat surface expands daily, and adversarial AI accelerates these risks, exponentially increasing the possibility of re-identification of deidentified health information.
In response, NIH has been building a framework to address exactly these threats through robust data protection standards. The Community Days webinars provided a comprehensive overview of security and data access standards for researchers using NIH controlled-access repositories. We highlighted the NIST Special Publication 800-171 series—a foundational resource that institutions can leverage to comply with NIH Security Best Practices. Additionally, we discussed how NIH Is strengthening identity proofing using modern technologies such as NIH Research Auth Service (RAS), Login.gov, and ID.me."