Houston Trade-Secret Investigation Puts Restructuring and Offboarding Controls Back in the Spotlight
A search warrant executed at UT MD Anderson Cancer Center has spotlighted an issue every research institution, hospital system, and employer of specialized visa talent should watch closely: what happens to sensitive data in the window between an adverse employment action and an employee’s actual departure.
What the Affidavit Alleges
According to a search warrant filed in Harris County and reporting by KPRC 2, investigators allege that an instructor at UT MD Anderson Cancer Center transferred more than 3 terabytes of biomedical research data to a personal external hard drive shortly after being placed on paid administrative leave. No charges have been filed, and the employees involved have not been publicly named.
Per the affidavit, the sequence began on July 31 when the employee connected a personal hard drive to an MD Anderson-issued laptop. The employee had requested a limited USB exception to connect a medical device and download approximately 500 megabytes of data. Investigators allege that instead, the employee copied files from a shared MD Anderson drive — reportedly including biomedical research folders, genomic research data, manuscripts, presentations, experiment files, and documents tied to federal research grants — and transferred more than 3 terabytes onto the external drive. The affidavit describes two connection windows that same afternoon: one beginning around 12:35 p.m. and ending at 12:41 p.m., and a second beginning around 5:23 p.m.
Both employees, a married couple working in MD Anderson’s Molecular Oncology and Experimental Radiation Oncology departments were placed on paid administrative leave the same day the transfers allegedly occurred. The warrant also references a separate, parallel thread: an internal compliance and criminal investigation into an alleged freight-forwarding business the couple may have run out of their home, potentially involving counterfeit goods, which if substantiated would implicate their H-1B visa status. The affidavit further references a document allegedly reviewed by one of the employees containing questions about leaving the United States for China while the investigation was pending.
Investigators characterized the alleged conduct as consistent with “a typical pattern for employees facing dismissal and losing their visa” — namely, an attempt to depart with proprietary material before an anticipated termination becomes final. The warrant does not allege that any data was sold, shared, or transferred outside the United States, and MD Anderson has stated it is “actively working with relevant authorities” and has already “taken steps to protect the institution’s data.”
The University of Texas Police Department executed the warrant on August 17, seizing computers, phones, external hard drives, and other devices for forensic examination. As of this writing, UT Police has not commented further, and MD Anderson has not confirmed the employees’ current status.
The Legal Framework at Play
Trade-secret theft by employees implicates a layered federal and state framework, and this matter — even at the investigatory, pre-charge stage — sits squarely inside it:
- The Defend Trade Secrets Act (DTSA), 18 U.S.C. § 1836, provides a federal civil cause of action for trade-secret misappropriation and permits civil seizure orders in extraordinary circumstances to prevent dissemination of stolen material.
- The Economic Espionage Act (EEA), 18 U.S.C. §§ 1831–1839, criminalizes the theft of trade secrets, with enhanced penalties under § 1831 where the theft is intended to benefit a foreign government, instrumentality, or agent. The affidavit’s reference to a document weighing departure to China — without more — does not establish a § 1831 nexus, but it is the kind of fact pattern that routinely triggers scrutiny of whether one exists.
- Texas state law independently protects trade secrets under the Texas Uniform Trade Secrets Act (Tex. Civ. Prac. & Rem. Code §§ 134A.001 et seq.), and unauthorized access to protected computer systems may separately implicate the Texas Penal Code’s computer-crimes provisions and/or the federal Computer Fraud and Abuse Act, 18 U.S.C. § 1030.
- Immigration status adds a distinct layer of complexity. H-1B status, per 8 U.S.C. § 1101(a)(15)(H)(i)(b) and its implementing regulations at 8 C.F.R. § 214.2(h), is tied to a specific sponsoring employer and a specific specialty occupation. Termination — or even an extended unpaid or administrative-leave period without a clear return-to-work path — can jeopardize an employee’s authorized status, and institutions should be attentive to how that reality intersects with data-access timing.
Why This Matters Beyond Houston: Lessons for Restructurings and Plant/Facility Closures
This case did not arise out of a reduction-in-force, merger, or facility closure — but the fact pattern maps directly onto the risk window that opens during any of those events. Whenever an employer signals an adverse action — administrative leave, a RIF notice, a plant closure announcement, a business unit wind-down — there is a predictable, and often under-managed, interval in which a departing employee retains system access and physical proximity to sensitive data. The MD Anderson matter is a useful case study in exactly how that interval can be exploited, intentionally or not.
Practical takeaways for counsel advising on workforce transitions:
- Sequence access revocation with the adverse action itself, not after it. The affidavit alleges the transfers occurred the same day the employees were placed on leave. Employers should have a documented protocol that revokes or restricts system, badge, and remote-access privileges concurrently with — not after — the notice of leave, termination, or facility closure.
- Scrutinize exception requests, especially near a known transition point. The employee here allegedly obtained a limited USB exception for a stated, narrow purpose (roughly 500 MB for a medical device) and is alleged to have used it to move over 3 terabytes. Any device or access exception granted during a pending investigation, performance action, or restructuring window warrants heightened, if not real-time, monitoring — not a one-time approval and no follow-up.
- Build data-loss-prevention (DLP) alerts around volume anomalies, not just content categories. A jump from an authorized ~500 MB request to multi-terabyte transfers is the kind of anomaly that modern DLP tooling is built to catch — but only if it is configured to flag volume and timing outliers, not solely keyword or file-type triggers.
- Treat visa-status employees in transition as a distinct risk category — carefully, and without pretext. This is a genuinely delicate area: employers cannot single out visa-holders for adverse treatment, and doing so improperly creates its own legal exposure. But where an employee’s continued work authorization is itself in question because of an independent investigation or termination decision, HR, immigration counsel, and IT security should be coordinating on timing — not operating on separate tracks that leave data access unaddressed while status questions are pending.
- Inventory what “sensitive” actually covers before the transition, not during it. The alleged transfer here reportedly included genomic research data, manuscripts, and materials tied to federal grants — categories that carry their own compliance obligations (e.g., NIH data-sharing and grant-compliance terms) independent of trade-secret law. Institutions undergoing restructuring, lab consolidation, or facility closure should complete a data-classification inventory before initiating workforce changes, not scramble to reconstruct one after a suspected exfiltration.
- Coordinate the civil, criminal, and regulatory tracks early. MD Anderson’s public statement that it is “working with relevant authorities” reflects a now-standard reality: a single fact pattern can simultaneously implicate criminal referral, a DTSA civil action, federal grant-compliance reporting, and immigration consequences. Institutions should loop in outside counsel across these tracks promptly rather than sequentially.
Factual Inquiries for Counsel
- Confirm current employment status of the named employees and whether termination has since occurred.
- Confirm whether any grand jury proceeding or formal charging instrument has been filed since the August 17 warrant execution.
- Confirm the scope of MD Anderson’s internal DLP/USB-exception policy as it existed on July 31, and whether it was followed as written.
- Confirm whether any of the federal grants referenced in the affidavit carry independent data-security reporting obligations that may have been triggered.
- Confirm the current visa status of the employees and whether any USCIS action is pending or anticipated.
A Closing Note
No charges have been filed in this matter, and the allegations described above come from a search warrant affidavit — not a verdict, plea, or indictment. The individuals involved are entitled to the presumption that the allegations remain just that until tested. What the filing does offer, however, is a timely and concrete illustration of a structural risk that recurs across restructurings, layoffs, and facility closures well beyond this case: the gap between an adverse employment decision and the actual severance of an employee’s access to sensitive systems is where trade-secret exposure most often lives. Institutions that treat that gap as a design problem — solved before the transition begins — fare considerably better than those that discover it only after a forensic examination becomes necessary.