Skip to main content

UK Biobank breach highlights need for stronger data security in research

Date

Following the recent UK Biobank breach, LIDA highlights the importance of Trusted Research Environments.

The UK Biobank Breach

Recent developments surrounding the UK Biobank data breach have brought renewed attention to the importance of secure data management in health research. As a valuable biomedical resource, UK Biobank data underpins studies aimed at improving public health outcomes. However, recent incidents have highlighted vulnerabilities in how sensitive and/or personal datasets may be accessed, handled and shared.

Investigations by The Guardian and others, indicate that multiple instances of UK Biobank data were inadvertently exposed through public online repositories. In many cases, researchers had downloaded datasets directly to local machines and stored them within directories linked to version control systems. When these repositories were later pushed online, most commonly to Git based platforms, the data was unintentionally made publicly accessible. Although takedown requests were issued, the nature of such exposures means that complete containment cannot be guaranteed, and the full extent of the breach may remain unknown.

In response to earlier risks, UK Biobank had transitioned in 2024 from direct data downloads to its Research Analysis Platform (RAP), a cloud based environment designed to improve data security. However, the platform still allowed data to be downloaded, resulting in some users downloading entire datasets and attempting to distribute or sell them via online marketplaces. As a result, access to the RAP service has now been suspended while remediation efforts are underway.

These events underscore a fundamental challenge in modern data science: balancing accessibility with security. At the Leeds Institute for Data Analytics (LIDA), this balance is robustly managed through a Trusted Research Environment (TRE) that is purpose built to safeguard sensitive data while enabling research for the public good.

The role of Trusted Research Environments

Adam Keeley, LIDA Data Analytics Team Manager, emphasised that the root of the issue lies in how research data is accessed and controlled:

“When datasets are downloaded locally, they become much harder to govern. What we’ve seen here is a combination of human error and system design, where data could be moved into environments that were not secure, and then unintentionally shared. Once that happens, it is incredibly difficult to fully recover or understand the scale of exposure.”

LIDA’s TRE, known as LASER, aims to address this by ensuring that research data remains within a secure, monitored environment at all times and that access and analysis can only take place within the platform itself.

LASER is also designed with stringent controls on both data ingress and egress. Where researchers are permitted to share data for publication, all outputs are first assured by our Data Scientists for compliance with necessary legal and data agreements, prior to extraction. Unlike systems that allow data to be downloaded to local devices or unrestricted data extraction, LASER prevents direct connections to public code repositories or other external services, which significantly reduces the likelihood of accidental or malicious data exposure.

Technical data security at LIDA is complemented by a comprehensive wrap around service model. A dedicated team of data scientists and Information Governance experts provide ongoing data management, technical support, governance oversight, and user guidance. This ensures that as well as enabling researchers to deliver high impact research, they are continuously supported to improve how they handle sensitive data based on the latest legal requirements and best practice.

Highlighting this distinction, Andrea Rylands, LIDA Information Governance Manager noted:

“A properly implemented TRE fundamentally changes the risk profile. In LASER, there is no pathway for data to be copied into uncontrolled spaces or uploaded to public platforms. However, technology is only one part of the solution; supporting researchers with clear data management processes, training, and responsive governance is just as important. That level of collaborative transparency and assurance is not possible when data is distributed through platforms that permit data to be downloaded”.

LIDA has a long-established track record of supporting research involving highly sensitive and personal data through its TRE, enabling 115 research projects involving 519 Data Assets and amounting to £96.9M over 5 years that have delivered benefits to researchers and partners.

Continuing to grow cutting edge research and the public’s trust

Public trust is fundamental to the continued success of research in the UK, particularly when it relies on the use of sensitive or personal data. Individuals must feel confident that their information is being handled with care, used responsibly, and protected by robust safeguards at every stage. Without this trust, participation and data sharing may decline, limiting the potential for scientific discovery and improvements in patient care and outcomes.

It is therefore essential that the technical systems, environments and governance processes supporting research are designed with security, transparency, and accountability at their core. By demonstrating that data can be used safely and ethically, the research community can help to sustain public confidence and ensure that vital research continues to deliver benefits for society.

While the recent breach highlights the serious risks that arise from sharing sensitive data for the purposes of research, it also presents an opportunity for the research, data science and IT communities to learn lessons and improve.

As Adam Keeley, concluded: “The lesson here is not to limit or restrict research, but to enable data to be accessed and analysed within a TRE, ensuring cutting edge research thrives whilst maintaining the public’s trust.”

Find out more about LASER

 References