On a Tuesday in mid-April, the UK Biobank — one of the largest and most comprehensive health-tracking studies in the world — received a troubling e-mail from an anonymous researcher. The sender had discovered what appeared to be sensitive information from hundreds of thousands of the study’s participants for sale on Xianyu, an e-commerce website owned by the Chinese technology company Alibaba.
With the help of Alibaba and the governments of the United Kingdom and China, the UK Biobank managed to get the listing removed. Still, the incident raised concerns about data security, spurred an internal investigation and led the biobank to cut off access for researchers while it built new infrastructure to secure its data. After nearly five months offline, the biobank has said it will begin to re-open to researchers this month.
Using biobanks to boost research: a how-to guide
The UK Biobank contains genetic information and troves of other biomedical data, including medical-imaging files, health history and lifestyle information, from 500,000 people who agreed to take part in the decades-long study. It’s one of several biobanks available to researchers globally. But researchers say that the UK Biobank is particularly valuable. “We’ve learned more about human biology from the work from UK Biobank than I think we have from any other single resource,” says Daniel MacArthur, a geneticist at the Garvan Institute of Medical Research in Sydney, Australia. Reasons for this include the large number of participants and the volume and diversity of the data collected, MacArthur adds. “But fundamentally, it’s also because they made it highly accessible, and that meant researchers all around the world were able to use that resource.”
The incident suggests that this openness might have its downsides — at least without stringent security measures. According to the results of the UK Biobank’s internal investigation, published on 4 June, there have been three instances, all linked to institutions in China, in which participant data were offered for sale online. All the listings have been taken down and the UK Biobank has banned these institutions from further access. And Alibaba has implemented automated searches to remove listings that reference the biobank.
This isn’t the first time that research data sets have dealt with a data-security issue. In March, shortly before the latest security incident, UK newspaper The Guardian reported that, on dozens of occasions, data from the UK Biobank had accidentally been uploaded by researchers onto the public code repository GitHub, and showed how the data could potentially be linked back to an individual study participant. And in 2023, hackers accessed sensitive data, such as names, addresses and ancestry information, from millions of users of the consumer genetic-testing company 23andMe.
The UK Biobank and 23andMe have since reassessed their security protocols and made updates to their platforms to put stricter controls on access. (23andMe was sued by affected users and agreed to pay more than US$40 million in compensation earlier this year.) These changes are happening amid a broader trend of biorepositories increasing restrictions on who can access their data and how. Many researchers say that the benefits of these changes to data security outweigh the drawbacks, but some worry that these restrictions might prevent legitimate users from using the data to their full potential.
Getting the right balance between data accessibility and security is crucial, says Joe Watts, director of data policy at the UK Biobank, who is based in Cambridge, UK. “We take the protection of our participants’ data extremely seriously and use great care to remove identifiable information and vet researchers and institutions,” he says. “We recognize that we can do more, and we are adding extra security measures.”
Controlled access
When the UK Biobank was first opened to the scientific community in 2012, it operated on what some describe as a ‘lending library’ system, in which researchers who obtained approval were able to download raw data to analyse on their own devices.
... continue reading