NIH Genomic Data
NIH Controlled‑Access Genomic Data
Security requirements for NIH controlled‑access human genomic data repositories under NIH Notice NOT‑OD‑24‑157.
Effective January 25, 2025: NIH requires all Approved Users of NIH controlled‑access human genomic data to attest that any institutional systems used to store, process, access, transmit, or download such data, on‑campus, cloud‑based, or third‑party, comply with NIST SP 800‑171 cybersecurity standards. This requirement is outlined in NIH Notice NOT‑OD‑24‑157.
If your project uses any of the repositories below, the systems you use to handle that data must meet NIST 800‑171. Engage Research IT and Information Security early, ideally during proposal development, so the right environment is in place before you request access.
Repositories & definitions
-
dbGaP · Database of Genotypes and Phenotypes
Subject to NOT-OD-24-157NIH repository of genotype and phenotype data from biomedical research studies.
-
BioData Catalyst · NHLBI
If genomic data are usedCloud-based ecosystem for heart, lung, blood, and sleep research data.
-
AnVIL · NHGRI Analysis, Visualization & Informatics Lab-Space
Subject to NOT-OD-24-157Cloud platform for genomic data access, analysis, and sharing.
-
NCI Genomic Data Commons · GDC
Subject to NOT-OD-24-157Unified data platform for cancer genomic and clinical data.
-
CDS – Trusted Partner · Cloud Data Sharing
Compliant with NIST 800-171NIH-supported secure cloud environments hosting controlled-access biomedical data, already NIST 800-171 compliant.
-
Kids First Data Resource
Subject to NOT-OD-24-157Pediatric cancer and structural birth defects genomics.
-
INCLUDE Data Hub
Subject to NOT-OD-24-157Central hub for Down syndrome research data.
-
Restricted Portion of SRA · Sequence Read Archive
Subject to NOT-OD-24-157Secure access to human sequencing data with consent restrictions.
-
NIMH Data Archive · NDA
If genomic data are usedRepository of human subject data from mental health and related studies.
-
NIAAA Data Archive · NIAAADA
If genomic data are usedRepository of alcohol-related biomedical and behavioral research data.
-
ABCD Study · Adolescent Brain Cognitive Development
If genomic data are usedLargest long-term study of brain development and child health in the U.S.
-
Brain/NeMo · Neuroscience Multi-omic Data Archive
Subject to NOT-OD-24-157Multi-omic brain data resource under the NIH BRAIN Initiative.
-
CommonMind Consortium Knowledge Portal
Subject to NOT-OD-24-157Open-access genomic data for psychiatric and neurological disorders.
-
PsychENCODE Knowledge Portal
Subject to NOT-OD-24-157Genomic and epigenomic data resource for psychiatric disorders.
-
NIAGADS · NIA Genomics of Alzheimer’s Disease
Subject to NOT-OD-24-157Genomic data sharing resource for Alzheimer’s disease.
-
AMP-PD · Accelerating Medicines Partnership – Parkinson’s Disease
Subject to NOT-OD-24-157Partnership resource for Parkinson’s disease genomics and biomarkers.
-
PDBP · Parkinson’s Disease Biomarkers Program
Subject to NOT-OD-24-157Repository for clinical, biomarker, and genetic Parkinson’s research data.
-
PEGS · Personalized Environment & Genes Study
Subject to NOT-OD-24-157Studies linking genomic, environmental, and health data.
-
NIMH Repository & Genomics Resources
Subject to NOT-OD-24-157Repository of biospecimens and data for psychiatric genomics research.
-
NIDCR FaceBase
Subject to NOT-OD-24-157Data hub for craniofacial and dental developmental biology.
- Subject to NOT-OD-24-157
- Subject if human genomic data
- Already NIST 800-171 compliant
Compliance checklist
If your project uses any of the repositories below, the systems you use to handle that data must meet NIST 800‑171. Engage Research IT and Information Security early, ideally during proposal development, so the right environment is in place before you request access.
- Verify that all systems (on-campus, cloud, or third-party) used to manage the data are compliant with NIST SP 800-171.
- Ensure data is stored and processed only within institutionally approved secure environments, no local storage on personal devices or unapproved servers.
- Confirm encryption for data at rest and in transit.
- Implement role-based access controls (RBAC) and limit access to authorized project personnel only.
- Maintain audit logs for all data access, transfer, and processing activities.
- Train faculty, staff, and students with access on compliance requirements and secure handling.
- Establish a DUA or MOU between PI and IT specifying shared responsibilities, environment security (IT) and data security/usage (PI).
- Report any suspected or confirmed data security incidents immediately to the institutional CISO / Research Compliance Office.
- Review and renew Data Use Certifications (DUCs) as required by NIH when access is requested or extended.
- Regularly review NIH guidance and repository-specific requirements to stay up to date with compliance changes.
Setting up a compliant environment?
Research IT and Information Security can help scope a NIST 800‑171 environment and shared‑responsibility agreement for your genomic data project.