Health data holds great value for research and development, even long after it was originally collected. It can shed light on questions beyond those that initially motivated the collection. Therefore, data infrastructures are being established to store health data for long periods of time. Biobanks and registries keep samples and data available for researchers who apply to use them to investigate new questions. This long-term sharing of research participants’ health data places high demands on data security and oversight. Researchers applying for data access undergo rigorous review and must sign detailed agreements.
But what can happen to participants’ health data after a biobank or registry approves the researchers’ application and transfers the data to them? In the spring of 2026, it was discovered that health data from UK Biobank was being offered for sale on overseas commercial online platforms. The participants’ data had already been de-identified, and the sales offer was immediately removed from the platforms once discovered. While it is unlikely that anyone was harmed by the incident, it highlights a vulnerability in the system.
In an article, Yusuke Inoue (formerly a visiting researcher at CRB) and Jennifer Viberg Johansson discuss this incident as an illustration of the need for more long-term responsibility regarding participants’ health data. Carefully reviewing the researchers’ application prior to granting data access is not enough. The authors argue that responsibility for participants’ health data should encompass the data’s entire lifecycle: before, during, and after access.
Yusuke Inoue and Jennifer Viberg Johansson call this continuous governance of health data infrastructures – but what does that entail? It implies, among other things, that the committees deciding on data access have a responsibility that extends beyond the initial decision. There must be mechanisms to continuously ensure that data accessed by researchers is handled correctly throughout the period of use, and to intervene if problematic handling of the data is detected. The authors argue that these mechanisms should be proportionate to the risks involved, to ensure that continuous governance does not unnecessarily impede responsible research or routine, low-risk data usage.
Shared health-related data may cross numerous boundaries during its lifecycle and may also be utilized by commercial entities. Continuous governance therefore entails responsibility for how data is shared following the decision on access, and how it is handled by parties other than the institution originally granted access. The authors emphasize that commercial use of health data is not inherently problematic; on the contrary, it is a prerequisite for translating medical research into innovations that benefit patients. Yet, continuous governance involves a responsibility to ensure that unauthorized onward transfer of data does not occur and that data is used in accordance with the conditions and purposes expected by both participants and society at large.
Health data infrastructures are not merely technical systems, the authors write. They are public institutions that cease to function if people lose trust in them and are no longer willing to contribute their data. A crucial aspect of continuous governance is, therefore, ongoing public communication regarding how participants’ health data is transferred and used after access has been granted, as well as the risks that may arise at later stages of the health data lifecycle. It is also important to act quickly and openly when problematic data usage is discovered – which is precisely what was done when it was discovered that health data from UK Biobank was being offered for sale.
The aim of Yusuke Inoue and Jennifer Viberg Johansson’s proposal for continuous governance is not to make sharing health data more difficult, but to make it easier to do the right thing, ensuring that incidents like the one involving UK Biobank do not happen again.
Read their arguments for continuous governance here: Ethics of Health Data Infrastructures: Toward Continuous Governance and Public Trust.

Written by…
Pär Segerdahl, Associate Professor at the Centre for Research Ethics & Bioethics and editor of the Ethics Blog.
Inoue Y, Viberg Johansson J. Ethics of Health Data Infrastructures: Toward Continuous Governance and Public Trust. Journal of Medical Internet Research, 2026, doi: 10.2196/104402
Approaching future issues

0 Comments
1 Pingback