Long-lived data, quantum risk: harvest-now-decrypt-later in biomedical research

Board-ready intelligence on AI law · Quantum governance · Post-quantum transition
Genomic data doesn’t expire. The HNDL threat model makes PQC migration a present governance decision for research institutions.

Quantum governance · Biomedical risk

Genomic data doesn’t expire. The HNDL threat model makes PQC migration a present governance decision for research institutions.

Published by Quentir Systems LLC · June 2026 · 7 min read

The most dangerous thing about some data is how long it stays sensitive. Genomic sequences, long-term clinical trial data, and medical IP can carry confidentiality lifespans measured in decades. Against the harvest-now-decrypt-later (HNDL) threat model, that longevity turns a future technology risk into a present governance decision.

Board takeaway. Biomedical HNDL risk is not only a cryptography problem. It is a data stewardship problem. Genomic and clinical research data can remain sensitive for decades, can implicate relatives as well as participants, and cannot be revoked or rotated like a password. That makes the migration sequence a governance decision today, even if the relevant quantum computer arrives later.

This is a published intelligence brief, built to inform your own decisions. Claims are tied to named sources, with dates below.

The threat model: why “later” is a present problem

Harvest-now-decrypt-later is a documented threat scenario in which an adversary captures encrypted data today — at relatively low cost — and stores it against the day when a cryptographically relevant quantum computer (CRQC) exists to decrypt it. Current quantum-vulnerable encryption algorithms, including RSA and elliptic-curve cryptography, can be broken by a CRQC running Shor’s algorithm.

The critical variable is data shelf-life. If the confidentiality value of a dataset will outlast the time between now and the emergence of a CRQC, that dataset is at risk today. Uncertainty about exactly when fault-tolerant quantum hardware will arrive does not reduce that risk — it affects only the window available to act.

Harvest-now-decrypt-later does not require a quantum computer to exist today. It requires only that an adversary believes one will exist before the captured data loses its value. For long-lived sensitive data, that condition is already plausible.

Why biomedical research is a sharp case

Biomedical research data sits at a unique intersection of three factors that amplify quantum risk:

Why biomedical data is different from ordinary confidential data. Many confidential records lose sensitivity as contracts expire, negotiations close, or business conditions change. Biomedical data often moves the other way. Its interpretive value can increase as analytical methods improve. A dataset that was collected for one research purpose can become more revealing when combined with future reference datasets, population studies, or quantum-enabled analysis. De-identification reduces risk, but it is not the same as deletion, and genomic data carries a family dimension that ordinary corporate records do not.

This is why the HNDL question should be asked at the dataset level, not only at the system level: how long must the data remain confidential, how reversible would exposure be, and what consent or trust commitments attach to it?

Long confidentiality lifespans. A genomic sequence does not become less sensitive over time — if anything, the interpretive value of genomic data increases as analytical capabilities improve. Clinical trial results have regulatory, IP, and scientific significance for decades. Research archives routinely contain datasets protected for 30, 50, or more years.

Irreversibility. Unlike a leaked password, a genomic sequence cannot be changed. Re-identification of nominally de-identified genomic data has been demonstrated in peer-reviewed research and is not hypothetical. A patient cannot consent again after their genomic identity has been exposed; the harm is permanent.

Consent and trust obligations. Research participants consent to their data being used and protected under specific conditions. The confidentiality commitments embedded in that consent are not conditional on the current state of cryptographic technology. If the systems holding that data are quantum-vulnerable, the institution is carrying an obligation it may not be able to honor.

The Hippocratic Quantum framework

Quentir’s Hippocratic Quantum framework — developed in the founder’s peer-reviewed work and grounded in the principles of responsible quantum innovation — names three governance anchors specifically relevant to biomedical quantum-AI contexts:

Consent: Quantum-enabled capabilities, including enhanced data-mining and re-identification, interact with the consent framework under which research data was collected. Governance should assess whether the consent obtained is compatible with current and near-future quantum-AI capabilities applied to that data.

Irreversibility: In biomedical contexts, harms from data exposure are often irreversible. The governance standard for irreversible-harm risks is higher than for reversible ones — precautionary posture, earlier migration, documented rationale for any delay.

Translational discipline: Quantum technologies are being applied to biomedical research — drug discovery, protein folding, genomic analysis — before their safety and security implications are fully understood. Governance should include explicit assessment of where quantum-enhanced capabilities interact with data not originally collected under a quantum-risk assumption.

What to assess now

What long-lived sensitive data do we hold in quantum-vulnerable systems? The starting point is a data inventory ranked by two dimensions: sensitivity (re-identification risk, IP value, regulatory status) and longevity (how long this data must remain confidential). Data that scores high on both dimensions is the priority population for PQC migration planning.

A practical HNDL triage. Rank biomedical datasets across five dimensions:

  1. Shelf-life: how long confidentiality must hold.
  2. Re-identification risk: whether the data can reasonably be linked back to a participant or family line as reference datasets improve.
  3. Irreversibility: whether exposure can be remediated, rotated, or contained.
  4. Research and IP value: whether the archive contains trial data, genomic data, platform know-how, or other information whose value persists.
  5. Dependency: which lab systems, cloud services, vendors, archives, and transfer paths still depend on quantum-vulnerable cryptography.

The output should be a short list of priority datasets and systems, not a general instruction to “be quantum ready.”

What is the current cryptographic posture of our research data stores? This requires an inventory of the encryption algorithms protecting long-lived datasets, and a gap analysis against current PQC standards (NIST FIPS 203/204/205). Many research institutions operate legacy infrastructure — data repositories, archival systems, secure enclaves — that has not been updated to reflect the NIST finalization.

Who owns migration accountability? In a research institution, data governance often sits across multiple domains — the CISO, the research data office, the ethics committee, and the PIs who collected the data. A migration plan for long-lived research data requires a named owner at the institutional level, not distributed responsibility across research programs.

Governance does not require a precise estimate of when a CRQC will arrive. It requires acknowledging that the confidentiality life of the data at risk is plausibly longer than the time available to act — and that the time to act is now.

A dataset-level triage example

A genomic cohort archive with twenty-year consent obligations, family-line identifiability, cloud storage and third-party lab access should rank ahead of short-lived operational records. The point is not to declare the archive quantum-unsafe today. It is to recognize that irreversible disclosure harm, consent expectations and vendor encryption dependencies make some biomedical datasets earlier candidates for PQC evidence work.

How Quentir reads it

Quentir’s intelligence work maps the HNDL threat model, the Hippocratic Quantum governance framework, and the PQC migration calendar to named, time-stamped sources — readiness material for research leadership, ethics bodies, and boards, built to inform your own decisions.

Quentir resource. For biomedical institutions, HNDL is not only a cyber issue. Quentir’s Hippocratic Quantum — HNDL in Biomedical Research applies the Hippocratic Quantum anchors — consent, irreversibility, translational discipline — to datasets that cannot simply be rotated, revoked, or reissued. For board-level migration sequencing across the wider estate, pair it with The PQC Migration Roadmap for Boards, 2026.

Sources: NIST Post-Quantum Cryptography project and FIPS 203/204/205 (Aug 2024); Hippocratic Quantum framework (peer-reviewed, Mauritz Kop); HNDL threat documentation (NSA, ENISA); European Data Protection Board, Guidelines 01/2025 on Pseudonymisation; selected genomic re-identification literature, including Gymrek et al., Science (2013), and Shringarpure & Bustamante, American Journal of Human Genetics (2015). Published: June 17, 2026.

HNDL readiness for biomedical data

Start with the HNDL Readiness Brief, then use the PQC Roadmap for board-level migration sequencing.

What the paid edition adds. The HNDL Readiness Brief is the fixed-scope edition of this analysis: an executive summary, the full threat model, the Hippocratic Quantum framework applied to biomedical data, a readiness-gap checklist for research leadership, and named refresh triggers — a citable document with a dated evidence spine under a single-organization internal-use license. Every Signature Brief and Signature Report, plus the full archive, is also included in the All-access membership.

This analysis is published intelligence produced by Quentir Systems LLC. It does not constitute legal, medical, or regulatory advice and creates no advisory or client relationship. Consult qualified advisers for advice specific to your organization’s situation.

© 2026 Quentir Systems LLC
Previous
Previous

AI Act Article 50: what you must disclose about AI-generated content, and when

Next
Next

The board’s PQC clock just moved up: why post-quantum migration is a 2026 governance item