Secure Biomedical Data Lakes for Regenerative Research
Keywords:
data lake security, biomedical data, GDPR compliance, access control, inference attack prevention, cryptographic protection, regenerative research, zero trustAbstract
Biomedical data lakes in regenerative medicine research contain some of the most sensitive categories of personal data recognised by GDPR: genetic data, health data, and data concerning biometric identifiers -- all of which attract the highest levels of regulatory protection and carry the most severe penalties for data breaches. The security of these data lakes must address threats at multiple levels: network-level attacks targeting data in transit, storage- level breaches targeting data at rest, access control failures enabling unauthorised data access, insider threats from privileged users, and inference attacks that reconstruct individual patient information from aggregate statistical outputs. Existing data lake security frameworks address network and storage security adequately but lack the biomedical-specific access control models, inference attack prevention, and automated GDPR compliance monitoring required for multi-institution regenerative medicine research data lakes. This paper proposes the Secure Biomedical Data Lake (SBDL-Sec) framework, a comprehensive security architecture for biomedical data lakes in regenerative research extending the BBDE SBDL infrastructure (Bianchi, 2025) with five security components: a biomedical access control model (BACM) implementing purpose-limited, role-based access control with data minimisation enforcement; a cryptographic data protection layer (CDPL) providing end-to-end encryption with patient-level key management; an inference attack prevention system (IAPS) detecting and blocking statistical queries that risk re-identification of individual patients; an automated GDPR compliance monitor (AGCM) continuously assessing data lake operations against GDPR requirements; and a security incident detection and response system (SIDRS) providing real-time threat detection and automated response. SBDL-Sec is evaluated in a red team security assessment at the RBCAP 6-institution deployment. BACM correctly enforces access control in 99.84% of tested access attempts. CDPL adds mean 284 ms latency overhead to data access with AES-256-GCM encryption. IAPS detects 94.6% of simulated inference attacks. AGCM identifies 100% of planted GDPR compliance violations. Red team penetration testing found zero critical or high-severity vulnerabilities in SBDL-Sec-protected data lake. The study contributes the SBDL-Sec specification, red team evaluation methodology for biomedical data lakes, and a security reference architecture for regenerative medicine research data infrastructure.
