Abstract
The U.S. life sciences sector now operates under a layered national-security compliance regime. The federal compliance regime is comprised of four pillars: The DOJ’s Data Security Program (DSP), codified at 28 C.F.R. Part 202,1 prohibits or restricts U.S. persons from engaging in covered data transactions that provide countries of concern - China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela - with access to bulk U.S. sensitive personal data, including a categorical prohibition for bulk human ‘omic data and biospecimens; (2) The NIH Biospecimens Security Policy (NOT-OD-25-160)2 prohibits the direct or indirect distribution of NIH-funded human biospecimens of U.S. persons to institutions in those countries; (3) The BIOSECURE Act (Section 851, FY2026 NDAA)3 creates staged prohibitions on using biotechnology equipment or services from designated companies in federal contracts and grants; and (4) The FDA has adopted an increasingly security-focused posture, announcing in June 2025 that it will review clinical trials relying upon the DSP’s research exception to send American citizens’ living cells to countries of concern.
State-level legislation adds another layer of complexity: Texas, Florida, Utah, and South Dakota have enacted genomic or genetic-data statutes imposing requirements not satisfied by federal compliance alone.
This Article evaluates the compliance regime and its impact on life sciences organizations and proposes a compliance framework to help stakeholders navigate federal and state requirements.
Introduction: When National Security Invaded the Lab
On June 18, 2025, the FDA announced an immediate review of new clinical trials involving the transfer of American citizens’ living cells to China and other countries of concern. Former FDA Commissioner Dr. Marty Makary stated: “The previous administration turned a blind eye and allowed American DNA to be sent abroad - often without the knowledge or understanding of trial participants.”4 The FDA will require companies to demonstrate full transparency, ethical consent, and domestic handling of sensitive biological materials.
The FDA’s announcement was the latest salvo in an eighteen-month federal effort to close off foreign-adversary access to American life sciences infrastructure. Executive Order 14117 (February 28, 2024),5 itself an expansion of Executive Order 13873 (May 15, 2019), directed the Attorney General to promulgate regulations prohibiting or restricting certain data transactions with countries of concern. The resulting DSP, effective April 8, 2025, constitutes the primary federal regulation implementing this EO. NIH subsequently issued its Biospecimens Security Policy (September 24, 2025), and Congress enacted the BIOSECURE Act as part of the Fiscal Year 2026 National Defense Authorization Act.
The real compliance challenge lies where the regulations intersect. A transaction exempt under the DSP may nonetheless violate NIH policy. A data transfer satisfying HIPAA’s de-identification standards may still be prohibited under the DSP. A clinical trial qualifying for the DSP’s FDA-regulated exemption may face heightened FDA scrutiny. And federal compliance does not necessarily satisfy state genomic-data statutes.
Part I: The Regulatory Landscape
Table 1 summarizes the principal regulatory regimes, triggering activities, and compliance challenges. Each regulation has independent jurisdictional reach and enforcement authority. None is fully preempted by the others.
Part II: The DOJ’s Data Security Program
The DSP is an export control regulation for data, targeting channels through which foreign adversaries might access Americans’ sensitive personal data through commercial relationships rather than direct acquisition. Compliance begins with asking four threshold questions: who qualifies as a covered person, what data triggers coverage, which transactions are prohibited versus restricted, and what compliance obligations attach?
|
Table 1.
|
|
Regime
|
What It Regulates
|
Typical Life Sciences Trigger
|
Compliance Challenges
|
|
DOJ Data Security Program (28 C.F.R. Part 202)
|
Covered data transactions enabling country-of-concern access to bulk U.S. sensitive personal data; flat prohibition for bulk human ‘omic data and biospecimen-derived ‘omic data
|
Vendor/CRO/lab arrangements; data hosting; remote access; analytics; any arrangement involving access to covered datasets
|
“Access” looks through affiliates, subcontractors, remote support. Compliance program mandatory for restricted transactions. Ten-year recordkeeping. Reports-on-demand authority with subpoena power.
|
|
NIH Biospecimens Security Policy (NOT-OD-25-160)
|
NIH-funded human biospecimens of U.S. persons, regardless of identifiability or volume
|
NIH-supported studies and biorepositories; sample distribution; site and lab selection decisions
|
Flat prohibition on direct or indirect distribution to countries of concern; no bulk threshold; three narrow exceptions with documentation burden; single specimen triggers compliance.
|
|
BIOSECURE Act (§ 851, FY2026 NDAA)
|
Federal procurement and funding involving biotechnology equipment or services from designated “biotechnology companies of concern”
|
Sponsors and CROs using equipment or services from entities designated as “biotechnology companies of concern” via the OMB or 1260H list process (currently including WuXi AppTec, BGI Genomics, MGI Tech, or Complete Genomics) in federal contracts or grants
|
Categorical exclusion - cannot be remediated through controls. Phased implementation: OMB must publish BCC list by December 2026; FAR revision by mid-2028; operative prohibitions take effect 60–90 days thereafter. OMB-managed designation process for additional companies.
|
|
FDA Electronic Records & Clinical Investigations (21 C.F.R. Part 11; guidance)
|
Reliability and integrity of electronic records; safety and transparency of clinical investigations including cross-border biological material transfers
|
eSource/eCRFs, EDC platforms, lab data flows, trial systems, audit trails, access controls; cell-transfer and DNA-export clinical trials
|
Part 11 controls are technical foundation for DSP security requirements. June 2025 announcement: new cell-transfer trials halted; FDA requiring domestic handling and full transparency.
|
|
State Regulatory Example: Texas Genomic Privacy Act (Tex. Health & Safety Code Ch. 174)6
|
Genome sequencing data of Texas residents handled by covered entities
|
Medical and research facilities, companies, and nonprofits conducting genomic research or testing involving Texas residents
|
Flat prohibition on foreign-adversary storage/access; no bulk threshold; annual AG certification; $10,000/violation civil penalty; private right of action up to $5,000 statutory damages/violation.
|
A. Threshold Questions: Countries of Concern and Covered Persons
The DSP’s applicability turns on: what are the countries of concern, and who qualifies as a covered person. The Attorney General has designated six countries of concern: China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia, and Venezuela. The question of who qualifies as a covered person is considerably broader.
A covered person includes, (i) any foreign entity 50% or more owned by a country of concern or another covered person, (ii) any foreign entity organized under the laws of, or having its principal place of business in, a country of concern, (iii) any foreign individual who is an employee or contractor of a country-of-concern entity or primarily residing there, or (iv) any entity or individual designated by the Attorney General. (See Figure 1.)
B. The Regulatory Scope: What Data Is Covered
The DSP covers six categories of bulk U.S. sensitive personal data: precise geolocation data, biometric identifiers, human genomic data and other human ‘omic data, personal health data, personal financial data, and covered personal identifiers linked to other categories. Life sciences organizations will most commonly encounter the genomic, ‘omic, and health data categories.
Human ‘omic data receives special attention and a flat prohibition rather than merely a restriction. The rule recognizes four subcategories, each with its own bulk threshold measured over the preceding 12 months: human genomic data (more than 100 U.S. persons) and human epigenomic, proteomic, and transcriptomic data (more than 1,000 U.S. persons each).
Human biospecimens include tissue, blood, urine, and other human-derived material, expressly including blood plasma. The sole exclusion is for biospecimens intended solely for diagnosing, treating, or preventing a disease in that recipient.
The de-identification trap: HIPAA de-identification does not provide a safe harbor. The DSP counts data toward bulk thresholds “whether identified, de-identified, anonymized, encrypted, or pseudonymized.” Data shareable through a HIPAA-compliant research pathway may nonetheless constitute bulk U.S. sensitive personal data subject to DSP prohibitions or restrictions.
C. Transaction Categories: Prohibited Versus Restricted
The DSP divides regulated transactions into prohibited and restricted categories. Prohibited transactions are categorical bans without compliance-program cure. The most significant for life sciences is the flat bulk human ‘omic data prohibition. No U.S. person may knowingly engage in a covered data transaction involving access to bulk human ‘omic data, or to human biospecimens from which bulk human ‘omic data could be derived. Derivability, not derivation, is the operative standard.
Restricted transactions are those the DSP permits subject to compliance conditions - specifically, CISA Security Requirements and a mandatory Data Compliance Program. The three classes are vendor agreements, employment agreements, and investment agreements involving covered persons and bulk U.S. sensitive personal data.
D. Mandatory Compliance Program Elements for Restricted Transactions
For restricted transactions, the DSP imposes a mandatory Data Compliance Program with five core elements: (1) risk-based data flow verification with auditable logging of data types, volumes, party identities, and end-use; (2) vendor validation through screening against the DSP’s Covered Persons List, OFAC SDN List, BIS Entity List, FCC Covered List, and NDAA § 1260H list; (3) written policies describing the compliance program and CISA security implementation, annually certified by a responsible officer; (4) annual independent audit by a qualified auditor who is not a covered person; and (5) ten-year recordkeeping with annual senior-official certification.
E. The Clinical Trial Exemption
Section 202.511 carves out an exemption for transactions ordinarily incident to FDA-regulated clinical investigations, as well as transactions incident to clinical care data or post-marketing surveillance data necessary to support or maintain FDA authorization, provided such data is de-identified or pseudonymized. This exemption reflects DOJ’s judgment that the humanitarian value of drug development, combined with existing FDA oversight, outweighs the case for categorical restriction. (See Figure 2.)
Part III: NIH Biospecimen Security Requirements: The Physical Sample Layer
While the DSP focuses on data, the NIH Biospecimens Security Policy (NOT-OD-25-160, effective October 24, 2025) addresses the samples themselves. It applies to every entity holding human biospecimens of U.S. persons collected, obtained, stored, used, or distributed using NIH funding, regardless of mechanism type or funding level.
A. Scope: Broader Than You Think
The NIH policy adopts the DSP’s country-of-concern designations but is in important respects broader. First, there are no bulk thresholds. Even a single biospecimen from a single U.S. person is within scope. Second, it reaches biospecimens regardless of whether the resulting ‘omic data would independently trigger DSP coverage.
B. The Core Prohibition and Its Three Narrow Exceptions
Entities holding NIH-funded human biospecimens of U.S. persons are prohibited from directly or indirectly distributing those biospecimens to institutions or parties in countries of concern. Three narrow exceptions permit sharing: (1) transactions required or authorized by federal law or international agreements; (2) rare and compelling circumstances where country-of-concern facilities possess needed capabilities not available elsewhere; and (3) at the individual’s request for that individual’s own diagnosis, prevention, or treatment. Documentation of exceptions is mandatory.
C. Practical Friction Points for AMCs, Sites, and Labs
The NIH policy creates immediate constraints on laboratory selection and site feasibility assessments. An AMC using a central laboratory with PRC ownership, or whose biorepository is managed by a covered person, risks indirect distribution. Material Transfer Agreements and biorepository terms must be updated. IRBs and sponsored research offices must now assess whether proposed sample logistics comply with the policy, which may create friction with sponsors whose preferred laboratory plans include PRC-affiliated facilities.
Part IV: FDA, Part 11, and the BIOSECURE Act
The FDA’s Part 11 regulations governing electronic records establish a baseline control framework whose requirements map closely onto the DSP’s security expectations: system validation, accurate record copies, record protection, system access limited to authorized individuals, and secure audit trails. Organizations with robust Part 11 compliance programs have a head start on DSP security requirements; those with material Part 11 gaps face compounding risk.
The BIOSECURE Act creates staged prohibitions on using biotechnology equipment or services from designated “biotechnology companies of concern” in federal contracts, grants, and loans. Unlike the DSP, which permits restricted transactions subject to a compliance program, the BIOSECURE Act’s prohibitions are categorical. A federal contractor or grantee using covered equipment or services from a designated company violates the statute. There is no compliance cure. The phased implementation timeline requires OMB to publish the initial designated-company list by December 2026, followed by FAR revision, with operative prohibitions taking effect approximately 2028–2029.
Part V: The Regulatory Intersection—The Real Compliance Risk
The most dangerous compliance territory is where requirements overlap, conflict, or create compounding obligations.
A. ‘Access’ Is Broader Than ‘Shipment’
The DSP defines access without regard to physical transfer. Remote IT support, analytics services, quality review, and affiliate staffing models can create access even when data or samples never physically leave the United States. A pharmaceutical company using a CRO whose data management operations employ citizens of a country of concern who primarily reside there has created a potential access pathway, regardless of where data physically resides. A follow-the-sun IT support model in which after-hours database administration is performed by personnel in China creates access even where no data is exported in any conventional sense.
B. Biospecimens and Derived Data: Overlapping but Non-Identical Prohibitions
The NIH policy governs biospecimen distribution as a physical-sample prohibition. The DSP prohibits transactions involving “human biospecimens from which bulk human ‘omic data could be derived.” A sample sent to a U.S. laboratory that subcontracts genomic analysis to a PRC-affiliated entity may violate both: the NIH’s prohibition on indirect distribution, and the DSP’s prohibition on access to derivable ‘omic data. A practical example is pharmacokinetic plasma samples shipped for drug concentration analysis, which are expressly listed as covered biospecimens and may contain trace cell-free DNA—meaning they likely do not qualify for the DSP’s sole exclusion (biospecimens intended solely for diagnosing, treating, or preventing disease in that recipient). The precautionary approach is to treat such plasma as a covered biospecimen.
C. The De-Identification Gap: HIPAA Compliance ≠ DSP Compliance
The DSP counts data toward bulk thresholds “whether identified, de-identified, anonymized, encrypted, or pseudonymized.” An organization that has de-identified a dataset under HIPAA’s Safe Harbor or Expert Determination method is not thereby exempt from DSP prohibitions. Research institutions that built HIPAA compliant data-sharing infrastructure must now conduct parallel DSP analysis for any data sharing involving covered persons.
D. Contracts Versus Operations: The Most Common Failure Point
The greatest compliance exposure arises from the gap between what contracts promise and actual vendor operations. A contract may specify U.S.-only service delivery, but actual operations may route covered-data access through shared service centers, cross-border quality control, or follow-the-sun IT staffing in countries of concern. The DSP requires verifying “the end-use of the data and the method of data transfer,” meaning the vendor chain must be reviewed operationally, not just contractually. Contractual obligations should flow down to subcontractors to ensure vendors do not engage in onward transactions with covered persons. Audit rights should reach system access logs, personnel location records, and the full subcontracting chain.
Part VI: Stakeholder-Specific Compliance Challenges
The practical implications of compliance differ materially across stakeholder categories.
A. Pharmaceutical Sponsors
U.S. sponsors’ country-of-concern exposure flows primarily through CRO, laboratory, vendor, and collaborator chains. Under the DSP, the sponsor bears compliance obligations regardless of where in the operational model the country-of-concern access occurs. Key challenges include documenting in-scope versus exempt decisions for each transaction, mapping corporate ownership through the full vendor chain, assessing BIOSECURE Act applicability for NIH-funded studies, and revising trial design to meet FDA’s domestic handling expectations.
B. Contract Research Organizations
CROs face systemic challenges because their global operating models, which are their primary competitive advantage which are their primary competitive advantage, precisely create the types of dispersed access the DSP targets. A large CRO may operate data management centers in multiple countries, employ biostatisticians who are citizens of countries of concern, have IT infrastructure managed from offshore service centers, and subcontract laboratory work to providers with PRC ownership. Principal challenges include demonstrating that global operating models comply with DSP security requirements, subcontractor governance and flowing DSP restrictions through the full subcontract chain and managing contractual exposure to sponsors.
C. Laboratories
Central and specialty laboratories face unique risks from sample chain-of-custody management, remote instrument administration, and corporate ownership structures. If a laboratory is a U.S.-organized subsidiary of a country-of-concern parent, access by its foreign parent, affiliates, and personnel can still create prohibited or restricted DSP exposure. Key challenges include ownership structures creating covered-person access risk, remote instrument administration routing system access through countries of concern, BIOSECURE Act equipment triage, and sample chain-of-custody documentation satisfying both NIH policy and DSP ten-year recordkeeping.
D. Academic Medical Centers and Clinical Sites
AMCs may face the most layered challenge. A single institution can simultaneously be a clinical site subject to the DSP through vendor agreements, a research institution subject to NIH biospecimen policy through federal funding, a HIPAA-covered entity, and potentially subject to state genomic-data statutes. Key challenges include NIH-funded biospecimen constraints conflicting with sponsors’ preferred laboratory plans, vendor and cloud-platform relationships involving AI and analytics services from covered persons, and state-law obligations (such as Texas’ annual AG certification and private right of action) not satisfied by federal compliance.
E. Technology Vendors and Platforms
Technology vendors, including EDC platforms, cloud computing services, AI analytics platforms, and LIMS providers, face DSP restricted transaction requirements because their vendor agreements typically involve providing access to bulk U.S. sensitive personal data. Key challenges include implementing CISA security requirement compliance, maintaining Part 11-compliant audit trails satisfying both FDA and DSP requirements, and providing clients with required diligence artifacts, audit reports, and annual certifications.
Part VII: A Defensible Compliance Framework
Meeting these requirements demands a dedicated, cross-functional governance initiative. Existing HIPAA programs and GCP quality systems are not enough; the DSP, NIH policy, and BIOSECURE Act do not map onto traditional life sciences compliance frameworks.
Governance. The DSP requires compliance managers with ”organizational senior-level authority, sufficient technical expertise,” and appropriate resources,7 with annual officer certification. The steering group should integrate legal, privacy, IT security, clinical operations, and vendor management.
Front-End Diligence. Before engaging in any transaction implicating the DSP or BIOSECURE Act, deploy a standardized diligence package. Key elements include: (1) corporate ownership and control mapping to identify covered persons; (2) access geography mapping covering where access will actually be performed, not merely where data is stored; (3) screening against the DSP Covered Persons List, OFAC SDN List, BIS Entity List, FCC Covered List, NDAA § 1260H list, and BIOSECURE Act designated companies; and (4) subcontractor disclosure requirements.
Data and Sample Flow Mapping. Reconcile intended data and sample flow as documented in contracts and protocols against the vendor’s actual operationalized flow. The gap between what a contract says and what a vendor’s global operation does is where enforcement risk accumulates. Chain-of-custody documentation must satisfy both NIH policy and DSP ten-year recordkeeping requirements.
Contract Controls. Contracts with CROs, laboratories, and technology vendors must include: explicit prohibition on routing covered-data access through countries of concern; prohibition on onward transfers to covered persons without prior written consent; audit rights reaching system access logs, personnel location data, and subcontracting arrangements; annual vendor certifications of compliance with DSP, NIH, BIOSECURE Act, and state-law requirements; change notification for ownership, structure, or service delivery model changes; termination rights tied to changes in law, ownership, or access-control breach; risk allocation provisions addressing vendor liability for DSP violations, including indemnification for regulatory penalties and enforcement costs; and recordkeeping cooperation for DSP ten-year retention requirements.
Technical Controls. Part 11, CISA security requirements, and HIPAA security safeguards share substantial overlap - role-based access controls, encryption, and access logging appear across all three. Organizations that design technical architecture to satisfy all three simultaneously reduce implementation cost and create artifacts serving as evidence across multiple enforcement contexts.
Part VIII: Enforcement Risk and Next Steps
The enforcement architecture carries financial and criminal consequences exceeding traditional life sciences regulatory frameworks. Civil penalties under the DSP reach approximately $368,136 per violation or twice the transaction value. Willful violations carry criminal penalties of up to twenty years’ imprisonment. The BIOSECURE Act layers on contract termination, debarment, and grant forfeiture. State laws like the Texas Genomic Privacy Act carry potential exposure of $10,000 per-violation civil penalties and a private right of action with statutory damages up to $5,000 per violation.
Three primary risk drivers will shape the enforcement landscape: (1) documentation quality - an organization with good controls but inadequate documentation is, for enforcement purposes, in the same position as an organization with no controls, given the DSP’s ten-year retention and reports-on-demand authority; (2) mismatch between contracts and operational access - organizations whose agreements promise U.S.-only delivery while operations route access through covered persons face potential knowing-direction liability; and (3) cross-border biospecimen handling visibility - the intersection of NIH, DSP, FDA, and BIOSECURE Act requirements means organizations must maintain end-to-end chain-of-custody documentation sufficient to demonstrate compliance with all four regimes.
State legislatures are also expanding the compliance landscape. Texas’s Genomic Act of 2025 (effective September 1, 2025)6 represents the leading edge of this state-law development. The Texas statute imposes a flat prohibition on foreign-adversary storage, requires that genome sequencing data be inaccessible to persons in such countries, bans genome sequencers produced by foreign adversaries, mandates annual Attorney General certification, and creates a private right of action. Utah’s Genetic Information Amendments, HB 182, takes a different approach, containing explicit federal-state alignment by exempting clinical trial data where storage or access is otherwise “permitted under 28 C.F.R. Part 202.”8 Florida targets laboratory genetic-sequencing software and foreign-country-of-concern licensure ties,9 while South Dakota regulates direct-to-consumer genetic-data practices.10
Immediate Actions. Organizations should: (1) conduct a rapid inventory of all vendor, CRO, and laboratory relationships involving access to human genomic data, ‘omic data, or biospecimens and assess each against DSP, NIH, and BIOSECURE Act requirements; (2) review clinical trial protocols involving sample transfer to or data access from countries of concern and assess whether FDA’s June 2025 statements require design or consent modifications; (3) audit the gap between contractual representations and actual operational models; (4) stand up the DSP-required Data Compliance Program if not already in place (the October 6, 2025 implementation date has passed); (5) map BIOSECURE Act exposure and begin transition planning for designated-entity relationships; and (6) engage state genomic-data obligations for institutions in or treating residents of Texas, Florida, Utah, and South Dakota.
Conclusion: The New Compliance Imperative
The national-security regulatory landscape now layers a geopolitical framework onto the data flows, sample logistics, and vendor relationships that make modern clinical research possible. This architecture will not simplify. The DSP’s country-of-concern list may expand, the BIOSECURE Act’s designated-entities list will likely grow, and state legislatures continue adding requirements.
A defensible compliance program requires integrated governance, front-end diligence, operational monitoring, and contract controls that reflect how vendors actually operate. Organizations that build these programs now will be best positioned to continue developing life-saving therapies in a world where national security and life sciences have become inextricably linked.
References
- Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons, 28 CFR Part 202 (2025).
- National Institutes of Health. Policy for Securing Human Biospecimens and Data Thereof Against Foreign Threat Actors. Notice NOT-OD-25-160. Published September 24, 2025.
- BIOSECURE Act of 2025, § 851 of the National Defense Authorization Act for Fiscal Year 2026, (enacted December 18, 2025).
- US Food and Drug Administration. FDA Halts New Clinical Trials That Export Americans’ Cells to Foreign Labs in Hostile Countries for Genetic Engineering [press release]. June 18, 2025.
- Exec Order No 14117, 89 Fed Reg 15421 (February 28, 2024).
- Texas Genomic Act of 2025, Tex Health & Safety Code ch 174 (2025).
- US Department of Justice, National Security Division. Data Security Program: Compliance Guide. 2025.
- Utah Genetic Information Amendments, Utah Code § 26B-2-244(3)(d) (enacted via HB 182).
- Fla ch 2025-96 (2025).
- SD Codified Laws § 37-24-60 (2024).
About the Authors
Michael (Mike) Halaiko, CIPP/E, a shareholder in Baker Donelson’s Baltimore and Washington, D.C. offices, leads the firm’s Life Sciences and Health Technology Group. Mike advises pharmaceutical, biotechnology, clinical research, and health technology organizations on the regulatory, privacy, contracting, and operational risk. His work includes global data privacy, AI governance, clinical research compliance, vendor and research agreements, and the practical challenges of collaborating across sponsors, CROs, SMOs, and technology providers.
Alexandra P. Moylan, CIPP/US, AIGP, a shareholder in Baker Donelson’s Baltimore office, helps health care and life sciences organizations navigate privacy, data governance, AI, and clinical research requirements. She works with organizations on IRB operations, research data use and sharing, health information privacy, and emerging governance frameworks, bringing a practical perspective to how regulated data can be used responsibly in pharmaceutical research and outsourcing relationships.
Madison “MJ” McMahan, an associate in Baker Donelson’s Nashville office, focuses on data privacy, cybersecurity, AI governance, technology transactions, and litigation involving regulated data and emerging technologies. She counsels clients on U.S. and international privacy compliance, cybersecurity risk, incident response, product counseling, and technology agreements, with experience that is particularly relevant to outsourced research, digital health tools, and AI-enabled life sciences operations.