Strengthening Trust and Leadership: Reflections on National Institutes of Health (NIH) 2026 Community Days: Securing NIH Controlled-Access Data and Our Data Protection Journey

Wednesday, September 2, 2026

By: Maureen Falvella, NIH CIO

On April 13 and 14, I had the privilege of leading the National Institutes of Health (NIH) 2026 Community Days: Securing NIH Controlled-Access Data webinars to engage directly with our stakeholders, researchers, and the broader public about the critical work we’re undertaking to protect controlled-access data. These sessions were designed to foster transparency around our security and operational standards, update the community on new resources and requirements, and reinforce our shared responsibility in safeguarding participant trust. I am deeply grateful for the vibrant participation and thoughtful questions that were raised, which underscores the importance and urgency of our mission.

Protecting participants’ trust requires one standard: secure, consistent protections for NIH controlled-access data—whether it is processed within a NIH Controlled-Access Data Repository (CADR) or a research institution’s IT systems. This principle drove the Extramural Community Days agenda, where we discussed not only what needs to be done, but why rigorous data protection is more essential than ever. Our commitment goes beyond compliance; it’s about honoring the trust participants place in us and ensuring the integrity of scientific research that impacts lives.

The risks facing Americans’ health and genomic data are not theoretical—they are real, documented, and evolving. Adversaries seek to leverage diverse datasets for economic gain, surveillance, and even military advantage. We’ve seen threat actors link wearable data (like smartwatches), health records, and geographical information to identify military movements and compromising information on global leaders. Alarmingly, we’re witnessing a 300% increase in data breaches within the healthcare sector and a 37% rise in ransomware attacks.i Most research institutions haven't been required until recently to follow specific security standards, making them softer targets than hospitals or government agencies. The threat surface expands daily, and adversarial AI accelerates these risks, exponentially increasing the possibility of re-identification of deidentified health information.

In response, NIH has been building a framework to address exactly these threats through robust data protection standards. The Community Days webinars provided a comprehensive overview of security and data access standards for researchers using NIH controlled-access repositories. We highlighted the NIST Special Publication 800-171 series—a foundational resource that institutions can leverage to comply with NIH Security Best Practices. Additionally, we discussed how NIH Is strengthening identity proofing using modern technologies such as NIH Research Auth Service (RAS), Login.gov, and ID.me.

NIH’s data protection journey did not begin overnight. This has been a multi-year effort that began in 2022, marked by continuous improvement and collaboration. Early on, we focused on securing human-derived genomic datasets regardless of if the data was processed in a NIH controlled-access data repository or within a researcher’s IT systems. In February 2024, Executive Order 14117 provided a pivotal directive to safeguard Americans’ bulk sensitive personal data, setting clear expectations for federal agencies—including NIH—to tighten controls and mitigate emerging risks. Building on this momentum, the Department of Justice finalized a rule in January 2025 that restricts certain data transactions, especially those involving countries identified as posing security concerns.

NIH has taken direct action to support these federal mandates by issuing key guide notices. In April 2025, NOT-OD-25-160 formally prohibited countries of concern from accessing NIH controlled-access data, reinforcing our protective stance. Then, in September 2025, NOT-OD-25-159 established unified security and operational standards for all NIH controlled-access data repositories, ensuring every user and institution operates under the same rigorous requirements. Each of these steps represents our commitment to evolving alongside the threat landscape and to upholding the federal standards designed to protect participant trust and the integrity of biomedical research. These Extramural Community Days mark another milestone in our ongoing process, reflecting both our progress and our unwavering commitment to securing the data entrusted to us.

Diligence is a daily practice at NIH. We continuously monitor threats, conduct regular audits, and partner with external experts to keep our defenses strong. This vigilance is our commitment to participants and the scientific community—one we uphold through action and accountability.

As we move forward, I want to reassure the community that NIH will remain at the forefront of data protection. We welcome your engagement, feedback, and partnership as we collectively uphold the highest standards of security, transparency, and scientific excellence. Together, we can protect participant trust, advance groundbreaking research, and maintain U.S. leadership in biomedical science.

View the Community Days recordings. (Scroll down to Resources)

i Verizon 2020 Data Breach Incident Report

This page last reviewed on September 2, 2026