Biotech & Research
Laboratory compliance and research data integrity
Threshold in 28 CFR 202.205(a), which sets other human omic data at 1,000 U.S. persons; personal health data sits at 10,000 under 202.205(d).
Biotechnology and research organizations handle sensitive research data, biological materials, and intellectual property requiring specialized security controls. Thalorin supports biotech compliance with laboratory security, research data protection, and the regulatory requirements specific to life sciences research.
A human genomic dataset becomes regulated at 101 people. Under 28 CFR 202.205(a), the Department of Justice treats human genomic data as bulk above 100 U.S. persons and other human omic data above 1,000; personal health data crosses at 10,000 under 202.205(d). The count runs across the preceding twelve months. 28 CFR 202.303 then prohibits any covered data transaction that gives a country of concern or a covered person access to bulk human omic data, or to human biospecimens from which such data could be derived. The rule took effect at 12:01 a.m. Eastern on 8 April 2025.
For omic data there is no compliant path. 28 CFR 202.401(b) puts bulk human omic data, and the biospecimens it derives from, outside the restricted-transaction regime entirely — the CISA security requirements at 202.248 do not buy it back. Other categories differ: a vendor, employment, or investment agreement reaching bulk personal health data is only restricted, and 202.1001 required a data compliance program by 6 October 2025, audited annually under 202.1002. Exemptions at 202.510 and 202.511 cover FDA authorisations and other clinical investigations, so one specimen can be exempt on one protocol and covered on the next.
Registered laboratories consistently underestimate how much of the Federal Select Agent Program is an information systems problem. 42 CFR 73.11(c)(9) requires the written security plan to isolate or authenticate every external connection to the systems that manage security for the registered space, revoke access as roles change, control malicious code, run configuration management with regular patching, and provide backup measures for when access control fails. The clock is unforgiving in a different register: 42 CFR 73.19 requires immediate notification of a theft, loss, or release by telephone, facsimile, or email, with APHIS/CDC Form 3 following inside seven calendar days.
What Thalorin holds is the object, not the checklist. A specimen, a dataset, an instrument, and a registered room each carry the obligations attached to them — the inventory audit 42 CFR 73.11(e) triggers when a principal investigator arrives or departs, the bulk threshold a cohort crossed last month — so a change in the laboratory raises the affected controls rather than waiting to be found at the next inspection.
Healthcare faces mounting cybersecurity challenges
Bulk begins at 101 people
28 CFR 202.205(a) sets the human genomic threshold at more than 100 U.S. persons, an order of magnitude below every other data category in the rule. A single cohort study crosses it without anyone reclassifying the dataset.
A policy written to be superseded
The 2024 DURC and PEPP policy took effect on 6 May 2025. Executive Order 14292, signed the day before, gave OSTP 120 days to revise or replace it, so the operative text is whichever version the award names.
Immediate means by telephone
42 CFR 73.19 requires notification of a theft, loss, or release immediately on discovery, by telephone, facsimile, or email — before the facts are settled. Form 3 within seven calendar days follows the call rather than replacing it.
Compliance became a payment term
Executive Order 14292 requires life-science contracts and grants to state that compliance is material to the Government's payment decisions for purposes of 31 U.S.C. 3729(b)(4), and permits up to five years of funding ineligibility.
How Thalorin helps
Research data integrity controls
Bind each dataset to the protocol, instrument, and operator that produced it with an append-only change record, so an integrity question resolves to a specific run instead of to the laboratory's recollection.
Laboratory system security
Evidence the information security provisions 42 CFR 73.11(c)(9) requires: isolated or authenticated external connections, access revoked as roles change, malicious code controls, configuration management with regular patching, and backup measures when access control fails.
Select agent compliance
Track registration, the Responsible Official's annual inspection of each registered space under 42 CFR 73.9(a)(6), and the inventory audits 73.11(e) triggers on relocation, principal investigator change, or a theft or loss.
Grant compliance documentation
Carry the certifications a life-science award now imposes against that award, including the Executive Order 14292 terms on dangerous gain-of-function research, so a renewal is answered from evidence rather than from memory.
IP protection workflows
Treat a release of controlled technology to a foreign person inside the United States as the deemed export 15 CFR 734.13(a)(2) says it is, and record where the 734.8 fundamental research exclusion is being relied upon.
Biosecurity integration
Hold the incident response plan 42 CFR 73.14 requires — theft, loss, release, inventory discrepancies, and information systems security breaches in one document — coordinated with the entity-wide plans it must not contradict.
Biotech & Research: common questions
Is our genomic dataset bulk under the DOJ data security rule?
If it covers more than 100 U.S. persons, yes. 28 CFR 202.205(a) sets that threshold for human genomic data and 1,000 U.S. persons for other human omic data; personal health data sits at 10,000 under 202.205(d). The count runs over the preceding twelve months and aggregates across transactions involving the same U.S. person and covered person. 28 CFR 202.303 then prohibits any covered data transaction giving a country of concern or covered person access to it, and 202.401(b) shuts the restricted-transaction route for omic data and biospecimens.
Which dual use research policy applies to our institutional review?
Whichever version your award terms incorporate — and that text is under a revision directed by executive order. The United States Government Policy for Oversight of Dual Use Research of Concern and Pathogens with Enhanced Pandemic Potential was issued on 6 May 2024, effective 6 May 2025, superseding the 2012 and 2014 DURC policies and the P3CO Framework. Executive Order 14292 of 5 May 2025 gave OSTP 120 days to revise or replace it, so confirm the incorporated text before assuming the 2024 Category 1 and 2 duties apply.
How quickly must a select agent theft or loss be reported?
Immediately on discovery, by telephone, facsimile, or email, to CDC or APHIS and to appropriate federal, state, or local law enforcement, under 42 CFR 73.19(a). The initial report must name the agent, estimate the quantity and the window in which the loss occurred, identify the building and room, and list the law enforcement agencies notified. A completed APHIS/CDC Form 3 follows within seven calendar days. Thefts and losses are reportable even if the material is later recovered.
Which select agent experiments need approval before we run them?
42 CFR 73.13(a) makes three classes conditional on approval by the HHS Secretary: deliberate transfer of, or selection for, a drug resistance trait in select agents not known to acquire it naturally where that could compromise disease control in humans, veterinary medicine, or agriculture; deliberate formation of synthetic or recombinant DNA containing genes for select toxins lethal below an LD50 of 100 ng/kg body weight; and creation of SARS-CoV or SARS-CoV-2 chimeric viruses. Approval is requested in writing and can be revoked.
Can a foreign national in our US laboratory work on controlled technology?
It depends on whether the technology is subject to the EAR. Releasing controlled technology or source code to a foreign person inside the United States is an export under 15 CFR 734.13(a)(2) — a deemed export — and may require a licence. 15 CFR 734.8(a) removes technology that arises during, or results from, fundamental research and is intended to be published from the EAR entirely, which is why most academic work is unaffected. Proprietary or contractually restricted work is not fundamental research.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Biotech & Research.
See how one evidence artifact satisfies Biotech & Research requirements alongside every other framework you carry.