Bloomberg reported on April 23, 2026, that records from 500,000 participants in the UK Biobank, the world’s largest repository of health, lifestyle, and biological data, had been listed for sale on the Chinese e-commerce platform Alibaba. But there was no hack. Instead, UK Biobank said that three approved research institutions had breached contractual obligations by leaking the data. Authorized access, weak downstream controls, and misplaced confidence that “de-identified” data, stripped of markers that identify an individual, is actually anonymous created the pathway. The United States has the same structural problem. Records protected by the Health Insurance Portability and Accountability Act (HIPAA), which limits how authorized parties can disclose patients’ protected health information without authorization, sit alongside a growing body of sensitive data that behaves the same way but escapes the statute entirely based on who collects it. The risk chain has three core parts: Protected health information (PHI), the individually identifiable health information held by a HIPAA-covered entity, is too widely accessible. When PHI becomes de-identified data, it is no longer subject to strict HIPAA rules and can be broadly reused, shared, or sold unless another law, contract, or consent obligation applies. De-identified data is not actually anonymous. It can be reidentified using unprotected and easily accessible consumer health data in an era of wearables, data brokers, and AI-enabled inference. Fundamentally, HIPAA does not adequately address the modern health data economy, and there are consequences for individuals, public health, and national security. Policymakers must protect sensitive data based on what it is, not on who holds it, and must not rely on a false sense of security about the protection offered by de-identification. Primary Health Data Is Too Easy To Access Again, the UK Biobank exposure would not have been prevented by stronger cybersecurity measures. Three approved research institutions downloaded the data and listed it commercially, and until late 2024, the platform had no file-size limits or monitoring of bulk downloads. Authorized access without technical enforcement is a structural vulnerability. Luc Rocher, a privacy researcher and associate professor at the Oxford Internet Institute, has identified 198 known exposures of UK Biobank data, instances in which participant data appeared outside the controlled research environment through authorized access channels, accidental uploads, reposting, or other downstream handling outside the original governance model. Research access to large health datasets is essential for scientific progress. However, once primary health data leaves the originating institution, legal agreements often do more to protect it than technical controls. If approved users can download, copy, or move large datasets without strong monitoring, file-size limits, purpose restrictions, and downstream audit requirements, then “authorized access” can become a pathway to exposure even when no hacker breaks into the system. U.S. health care organizations and other entities covered by HIPAA face similar vulnerabilities because the law permits data to be shared, sold, or reused without patient consent if it is de-identified. And unfortunately, de-identification provides a false sense of security. De-Identified Data Is Not Truly Anonymous Consumer health data, among other information, can provide the missing pieces needed to reconnect de-identified clinical or research records to real people. Apple, Fitbit, Garmin, Oura, and various consumer neurotechnology companies fall entirely outside HIPAA’s scope, and one study found that 12 health apps were sending data to 76 third parties. All of it was legal. UK Biobank records were re-identified by cross-referencing them with an individual’s birth month, year, and a single surgery detail, and Rocher has noted that the bar for re-identification is fairly low. The problem is compounded by the nature of biometric signals: heart rhythm, gait, and blood oxygen saturation data, all things commonly tracked by consumer wearables, re-identify individuals at 86 to 100 percent accuracy. Electroencephalography (EEG) recordings as brief as two seconds can pinpoint a specific person. The permanence of data compounds the risk. When the direct-to-consumer genetic testing company 23andMe filed for bankruptcy in 2025, two years after suffering a major data breach, its genomic database was treated as a transferable corporate asset, available to buyers who its users never anticipated. The same dynamic applies to any acquisition of a wearable platform. Entertech, a Chinese firm, holds one of the world’s largest commercial EEG datasets on servers that, under China’s National Intelligence Law, must be made available to state intelligence services on demand. HIPAA Fails To Close Several Security Gaps HIPAA leaves several structural security gaps, beginning with allowing de-identified data to be shared, sold, or reused without permission when 18 specific items, such as names, addresses, phone numbers, and Social Security numbers, are removed. In contrast, European privacy law takes a stronger approach. Under the European Union’s General Data Protection Regulation (GDPR) and the UK GDPR, which is materially similar, data that can still be linked back to a person remains personal data, even if direct identifiers have been removed. That means individuals may still have legal rights, and organizations need a valid legal reason to use the data. The UK Biobank incident shows why these standards matter. Despite the exposure, affected individuals and regulators had potential recourse because the data retained legal protection, providing a strong disincentive for a subsequent incident. In contrast, under HIPAA, similar data might lose any legal protections once the 18 identifiers were removed. In addition to insufficiently protecting de-identified data, HIPAA also has a weaker approach to encryption, which is designed to prevent the theft of the fully identified PHI it is meant to protect. The law treats encryption as “addressable,” which means an organization does not always have to encrypt health data if it documents another reasonable security approach. By contrast, UK and EU data-protection laws generally treat pseudonymized data as personal data when reidentification remains reasonably possible, and require risk-appropriate security measures, including encryption. The encryption gap has become riskier amid looming technological advances. The National Institute of Standards and Technology (NIST), which publishes widely used tech frameworks, finalized new post-quantum cryptography standards in August 2024. However, consumer health data rules do not require organizations to move toward those stronger protections. The result is a double risk: fully identifiable PHI may remain insufficiently protected by older encryption systems, while de-identified health data loses legal protection, even though it can later be reidentified. Both categories can retain long-term intelligence and personal exploitation value if health information is collected today and decrypted, linked, or inferred against future datasets. In 2024, the U.S. Federal Trade Commission updated its 2009 Health Breach Notification Rule to expand some requirements, forcing health apps and other non-HIPAA entities to notify affected parties after a security breach that compromises their data. However, the rule still does not require companies to delete old data nor limit how long they keep it, creating a significant long-tail risk. The Consequences Are Personal, Public, and Strategic The possible repercussions of HIPAA’s security limitations span personal privacy violations, negative public health impacts, and national security threats. The individual consequences of insecure health data are broad and often permanent. Medical records often command far more criminal value than payment-card data because they combine identity, insurance, financial, and health information and cannot be canceled like a credit card. Exposure can enable identity theft, insurance fraud, employment discrimination, financial harm, blackmail, and permanent loss of privacy. Sleep, mood, fertility, medication, and behavioral profiles may affect loan, insurance, employment, or custody decisions if accessed or inferred by the wrong parties. In states where abortion access is restricted after the Supreme Court’s ruling in Dobbs v. Jackson Women’s Health Organization, period-tracking and reproductive health data could also become evidence in investigations or legal proceedings. Biometric and genomic data cannot be changed, which means exposure is irreversible. The national security implications are direct. For example, a Top Secret/Sensitive Compartmented Information (TS/SCI) contractor’s fitness tracker records elevated heart rate, irregular sleep, and psychiatric medication pickup, none of which is HIPAA-protected. Unfortunately, the Food and Drug Administration’s January 2026 general wellness guidance may allow some low-risk, noninvasive consumer devices that measure physiological signals to avoid medical-device oversight when marketed only for wellness uses. If this easily accessible data is cross-referenced against records from the 2015 Office of Personnel Management (OPM) breach, a foreign intelligence service can identify a mental health condition absent from the contractor’s SF-86 security clearance form without ever touching a classified system. Repeated dataset exposures, including hacks, unauthorized downstream sharing, accidental uploads, and commercial resale of data, also erode research participation, as potential participants may fear that their most sensitive information will be exposed and used against them. That weakens pandemic preparedness and public-health research because large, representative datasets are essential for detecting disease trends, understanding risk factors, and developing effective interventions. At the highest end of the risk spectrum, former National Counterintelligence and Security Center Director William Evanina and former representative Hon. Mike Gallagher (R-Wis.) have stated that China is developing bioweapons capable of targeting specific individuals, and China’s Ministry of State Security characterized genetic weapons in 2023 as more concealable than conventional weapons. UK Biobank’s genomic dataset is precisely the population-level mapping that this capability would require. Policymakers Should Protect Health Data by Definition and Default The policy fix for HIPAA’s health care security vulnerabilities should start from a simple premise: health data should receive baseline protection because of what it reveals about a person, not because of the type of company, app, agency, or research platform that happens to hold it. Congress and regulators should close the gaps that allow sensitive health, genetic, biometric, and neural data to lose protection when it moves outside traditional clinical and insurance settings. First, lawmakers should expand HIPAA so currently uncovered consumer health, genetic, biometric, and neural data receive baseline protection regardless of who holds it. A request by the Office of Personnel Management (OPM) for identifiable claims-level health information from Federal Employees Health Benefits and Postal Service Health Benefits carriers shows the same structural risk: protection becomes uncertain when sensitive health data moves from a HIPAA-covered insurer to an agency or platform operating under a different legal framework. HIPAA protection must follow the data. Second, reclassify encryption requirements from the addressable standard, which allows providing alternative “reasonable” protection, to requiring encryption for all entities collecting sensitive health data at scale. Third, require the latest, strongest FIPS 203 and FIPS 204 post-quantum cryptography standards for any entity aggregating population-scale health, genetic, biometric, or neural data from Americans, regardless of the entity’s HIPAA compliance status. Fourth, replace HIPAA’s Safe Harbor pathway, which allows data to be treated as de-identified once 18 specified identifiers are removed, with a stronger, technically verified pseudonymization standard for large datasets. For datasets exceeding 10,000 subjects, organizations should have to demonstrate resistance to reidentification and obtain independent verification that the chosen de-identification or pseudonymization method remains effective when tested against reasonably available external data. This effort should align with the Department of Justice’s Data Security Program, which restricts certain transactions that could give countries of concern access to bulk U.S. sensitive personal data, including genomic, biometric, health, financial, geolocation, and other sensitive data. Fifth, direct the Committee on Foreign Investment in the United States (CFIUS) to treat foreign access rights to population-scale American health data as reviewable national-security risks, not just ownership interests. In other words, foreign access to sensitive health datasets can raise national security concerns, even when a foreign entity does not fully acquire the U.S. company that holds the data. Sixth, direct the Director of National Intelligence (DNI) to produce an unclassified assessment of the biological targeting utility of population-scale health datasets held by foreign-controlled entities and extend the BIOSECURE Act to consumer neurotechnology and wearables. The BIOSECURE Act restricts federal procurement and funding that involves biotechnology companies of concern tied to foreign adversaries; Congress should apply the same logic to consumer technologies that collect neural, biometric, genomic, or physiological data at scale. HIPAA was designed for a clinical and insurance-centered system, and that system no longer encompasses where health data lives. It lives in phones, watches, apps, research platforms, bankrupt companies, broker databases, and AI pipelines, creating enormous vulnerabilities and risks. The law needs to follow the data and address the technology that can exploit it. If policymakers do not adapt to both existing and potential threats, the United States will continue protecting health information in name only while leaving the most valuable and permanent data about Americans exposed. Dr. Georgianna Shea is chief technologist at the Center on Cyber and Technology Innovation (CCTI) and the Transformative Cyber Innovation Lab at the Foundation for Defense of Democracies (FDD).Nicole Chiappone is a seasoned trial lawyer with a career spanning over two decades. She was a member of the Parkland prosecution team and, in that capacity, became extremely well-versed in issues at the intersection of neurology and the law. She is also a member of the American Bar Association and its Cybersecurity and Data Science Committee, and the International Neuroethics Society. For more analysis from FDD, please subscribe HERE. Follow FDD on X @FDD. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.
Protected in Name Only: HIPAA’s Health Data Gap Is Becoming a National Security Risk
Full Article
Original Source
Read the full article at Fdd →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.