Why MDS Cytogenetic Data Is Uniquely Sensitive
Myelodysplastic syndrome (MDS) is not diagnosed from a single test. A complete picture requires bone marrow biopsy pathology, karyotype analysis, and next-generation sequencing (NGS) panels covering genes such as SF3B1, ASXL1, and TP53. Those results feed into a risk score. The International Prognostic Scoring System-Molecular (IPSS-M) combines cytogenetic data with somatic mutation profiles to group patients into categories that directly inform transplant referral and protocol eligibility. NEJM Evidence published the IPSS-M validation study showing its greater accuracy over older scoring systems for predicting leukemia-free survival.
This data is critical to care. It determines whether a patient is referred for allogeneic stem cell transplant. It shapes every major clinical decision across the duration of the disease. It is also, by definition, protected health information (PHI) under HIPAA - and it travels.
In a typical MDS care episode, a karyotype report leaves the cytogenetics lab, enters the ordering hematologist's electronic health record (EHR), is shared with a multidisciplinary tumor board, and then goes to a transplant center, a community oncologist, and sometimes an external clinical trial coordinator. Each transfer point carries a compliance obligation. In many clinics, some of those transfers happen without proper protection.
The Providers Involved and the Data They Handle
MDS management involves multiple providers:
- A hematologist or hematologic oncologist managing the disease
- A pathologist reading bone marrow morphology and blast percentages
- A cytogenetics lab - often a reference lab outside the treating institution - reporting karyotype findings
- A transplant center conducting its own pretransplant workup
- A primary care or referring physician receiving updates
Each provider relationship creates new security needs. When a karyotype result or NGS report moves between these parties, both the HIPAA Privacy Rule and Security Rule apply. Business Associate Agreements (BAAs) must cover every vendor or partner that touches PHI. Many clinics don't identify these gaps until after a breach or audit.
Where Multi-Provider MDS Workflows Break Down
The failure points are predictable. They happen at handoffs - where data moves between systems.
Reference lab portals create a common first gap. A cytogenetics result is uploaded to the lab's portal. The hematologist retrieves it, then forwards the PDF to the transplant center's coordinator by email. That email is almost certainly unencrypted. Once sent, the PDF exists outside any audit trail and can't be revoked.
Fax remains common in hematology longer than in most medical settings. A bone marrow biopsy report faxed to a transplant center is HIPAA-covered during transmission, but once printed it has no access control, no audit log, and no way to revoke access if the care relationship ends.
EHR copy-paste creates another exposure. A clinician copies NGS mutation results into a shared coordination note. Everyone with chart access can then see that note, regardless of their role in the MDS episode. This violates HIPAA's minimum-necessary-access rule.
Role-based access is also often poorly configured. When a transplant center gets read access to a patient's electronic chart, they often see billing records, unrelated diagnoses, and mental health notes - not just the cytogenetic data they need. Healthcare IT News has documented how missing or inconsistent audit trail monitoring creates compliance gaps that institutions discover only after the problem is established.
The Breach Risk Is Real
Healthcare data breaches are a serious problem. According to Becker's Hospital Review, the ten largest healthcare data breaches reported in 2025 affected more than 20 million individuals. Hematology and oncology practices are attractive targets because genomic and molecular data can be used to identify people.
The impact on cancer programs can be severe. A study in JCO Oncology Practice found that the two main areas of disruption after a cyberattack are communications failure and loss of electronic medical record access. Both interrupt the coordination that MDS care depends on. Treatment decisions stall. Staff can't get lab results. Transplant referrals pause.
MDS is urgent. At higher risk levels, the disease can progress to acute myeloid leukemia (AML). A communications failure during active MDS treatment is both a compliance problem and a clinical problem that no recovery plan can fully fix.
What HIPAA-Ready Cytogenetic Data Flow Requires
HIPAA is flexible about technical architecture, but requires covered entities to implement reasonable administrative, physical, and technical safeguards. HIMSS has outlined five steps for protecting patient data: know where it is stored, control who can access it, encrypt it in transit and at rest, monitor access continuously, and maintain tested response plans.
For MDS cytogenetic data, these principles translate into concrete requirements:
- Encryption at rest and in transit. Karyotype reports, NGS panel outputs, and IPSS-M calculations stored in the platform should use AES-256 encryption. All data moving between providers should use current encryption (TLS 1.3).
- Granular role-based access control. A transplant center coordinator who needs the cytogenetic result should access only that record. Configurable permission levels at the provider, role, and data-type level make this possible. An all-or-nothing chart access model doesn't work.
- Permanent audit logs. Every record access, export, and external share should generate a timestamped, protected log entry. This is required by the HIPAA Security Rule under audit controls (45 CFR 164.312(b)). Automated log review is the minimum standard for any platform handling oncology genomic data. Manual periodic checks don't meet the standard.
- BAA coverage for every external touchpoint. Any vendor, reference lab portal, or external partner that touches MDS cytogenetic data must be covered by a signed Business Associate Agreement. This includes AI tools used to extract or summarize lab reports. AI systems that don't save patient data after processing reduces the ongoing data custody risk.
- Regional data hosting. For institutions with cross-border patient populations or obligations under state-level genetic privacy statutes, knowing which state or country hosts the data matters. Regional hosting allows institutions to meet both federal HIPAA requirements and applicable state regulations on genetic information.
How Rucja Addresses MDS Data Security
Rucja is designed for the security obligations of multi-provider oncology care, including the specific demands of hematologic malignancies. The platform uses AES-256 encryption for all stored records and TLS 1.3 for all data in transit. You can configure role-based access controls at the provider, clinic, and data-type level. A transplant partner can access only cytogenetic results, without seeing unrelated chart sections.
Every data access event generates a permanent, protected log entry. Logs are kept and searchable, supporting internal compliance reviews and any Office for Civil Rights (OCR) audit. The platform's AI functions, including lab report extraction and protocol summarization, operate under a zero-retention policy: the platform doesn't keep input data after processing finishes.
Regional hosting options allow clinics to keep patient data within their preferred location. All partners must have BAA coverage. For a full breakdown of the technical safeguards Rucja applies, see our article on what hospital-grade security means for patient data.
Clinics managing germline testing alongside somatic mutation profiles will find related guidance in our articles on BRCA genetic data security for ovarian cancer clinics and MRD monitoring in multiple myeloma.
Building a Compliance Architecture That Lasts
A single audit or remediation effort won't create durable compliance. MDS care is long-term. A patient may be followed for years, with cytogenetic rechecks at disease progression and different providers involved at different stages. The data surface expands over time, and more BAA relationships and access permissions are needed as care continues.
Sustainable compliance requires a platform where the default workflow is compliant - where access controls and audit logs are enforced automatically, and clinical staff don't have to judge which channel to use each time a result needs to move. Manual processes eventually break at scale. Workflows that depend on individual behavior fail as organizations grow.
For hematology-oncology practices, the question is not whether cytogenetic data will cross provider boundaries. It will. The question is whether the infrastructure supporting those handoffs meets the standards HIPAA requires and the urgency MDS demands.
Schedule a 30-minute demo to see how the system handles data sharing in your clinic, including role-based access controls and audit log review. Book a demo with the Rucja team.
