Why Is Anonymized Clinical Data a National Security Risk?

Anonymized clinical data is a national security concern precisely because anonymization protects the wrong thing. Removing identifiers protects individual patients, which is what privacy regulation was built to do. It does nothing to reduce the value of the data set as a whole, and the aggregate is what a state actor wants. Anne Herold Li, Shareholder and New York Managing Partner at Brownstein Hyatt Farber Schreck, makes this argument from an unusual vantage point for a trial lawyer: she holds a Master of Public Health from Emory, and she describes how an epidemiologist reads a data set. An epidemiologist has no particular interest in any one patient record. The population is the object of study. On Open Door Salon, she and Raja Mikkili, Vice President of Core Technologies and Security at Arcutis Biotherapeutics, explain why a company that has correctly anonymized its data may have concluded it is safe when it is not.
What does a company believe it has accomplished by anonymizing data?
Compliance, and a closed question. Herold Li describes the standard position she encounters.
"Everyone's like, oh, my data's anonymized. I've protected the personal health information of my subjects by anonymizing the data. It's divorced. You know, I don't even have access to the personalized data."
That belief is not wrong on its own terms. The obligation being satisfied is a real one, and it was correctly discharged. The problem is that it answers a different question than the one a security team should now be asking.
Why does anonymization fail to reduce the strategic value?
Because the identifiers were never the valuable part. Herold Li separates the two interests cleanly.
"Personalized data is what, you know, we as individuals are worried about. But it's actually that anonymized large data set, which is what the government is worried about."
Then she grounds it in her own training, which is what makes the argument land rather than sound theoretical.
"You know, as an epidemiologist, I don't care really about personalized data. I mean, I care, but like I don't care. I'm interested in population level data, large populations of data for analysis."
The conclusion follows directly.
"The third party actor threat that's a state actor is interested in population level data."
A state actor pursuing a public-health or biotechnology capability wants to know how a population responds to a therapy, what the distribution of outcomes looks like, and where the signal sits across thousands of subjects. Stripping the names does not degrade any of that. In some analyses it improves the data set by removing noise.
Is there a regulatory gap here?
Herold Li thinks so, and she is specific about which direction the gap runs.
"And so there needs to be some kind of regulation about this anonymized data that's not there to protect just the individual, but it needs to protect the population as a whole."
She sees existing statutes reaching toward the problem without addressing it head-on.
"And they're trying to get at it broadly with the Biosecure, with the COINS Act, with different tools."
The BIOSECURE Act was enacted as Section 851 of the FY2026 National Defense Authorization Act, and it operates on procurement and supply-chain relationships rather than on data classification. That is an indirect instrument for a data problem, which is Herold Li's point. The reach of that statute is examined further in our earlier pieces on whether the BIOSECURE Act will be expanded and whether it applies to private companies.
Why does biotech lack the data rules other industries have?
Because the sectors that built those rules had a clearer definition of what needed protecting. Mikkili raises the comparison as an open question to Herold Li rather than a complaint.
"Look, you know, most of the industries like the aerospace and defense, the financial, the banking industries, you know, they came up with this regulation of how to protect the data specifically, right? They've defined that data that needs to be protected."
Biotech's version is more ambiguous, and he notes that a company can sometimes sidestep the regulated category entirely.
"Now, although there's PII that exists within the healthcare slash biotech, some biotechs may be able to navigate without having to deal with PII because there's data modernization opportunities."
That is the structural trap in one sentence. A company can reduce its regulated-data footprint, satisfy its privacy obligations, and end up holding a data set that is just as interesting to a foreign intelligence service as it was before, with fewer rules attached to it.
What would make the industry take third-party data risk seriously?
Mikkili's answer is that a sufficiently visible failure has already happened in adjacent healthcare infrastructure.
"We've seen the Change Healthcare incident that crippled many of the healthcare exchanges in the industry."
"What if there is something that a regulation can do for the biotechs to wake up and realize what a third party risk that exists out there and what they need to do to be protected?"
He is asking whether the sector needs a rule, or whether it needs an incident. The honest reading of the conversation is that the industry has now had several incidents and has not yet produced the rule.
What should a company do differently?
Re-classify the aggregate. If the protected-data inventory lists identifiers and regulated personal information, then the largest and most complete study data sets may be sitting outside it, cleared for wider internal access precisely because they were anonymized. Treat the aggregate as a controlled asset in its own right, with its own access policy, and make sure the collaboration agreements governing it say what each party may do with it. That contractual question is the subject of who owns the data in a biotech collaboration agreement, and it is the same data set on both sides of the problem.
This post draws on the recorded, on-the-record conversation with Raja Mikkili and Anne Herold Li on Open Door Salon. Watch or listen to the full episode, Nation States Aren't Targeting Big Pharma, or read more about Anne Herold Li and Raja Mikkili.
Open Door Salon brings the people who build, fund, and fight for global healthcare into one room. If your organization wants to reach that audience, see our sponsorship options.
