Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

B

Business associate agreement (BAA)

A business associate agreement (BAA) is the written contract required by the US HIPAA Privacy and Security Rules (45 CFR 164.502(e) and 164.504(e)) between a covered entity (healthcare provider, health plan or clearinghouse) and a business associate, that is, a person or organisation that creates, receives, maintains or transmits protected health information on the covered entity's behalf for functions such as claims processing, data analysis, utilisation review, billing, IT hosting, transcription or legal and consulting services. Since the 2013 Omnibus Rule, business associates are directly liable under HIPAA and must in turn conclude BAAs with their subcontractors.

A BAA must establish the permitted and required uses and disclosures of PHI by the business associate; prohibit other uses; require appropriate safeguards and compliance with the Security Rule for electronic PHI; require reporting of unauthorised uses, disclosures and breaches of unsecured PHI to the covered entity; require the business associate to ensure that subcontractors agree to the same restrictions; require assistance with individuals' rights of access, amendment and accounting of disclosures; require that PHI be made available to HHS for compliance purposes; and require return or destruction of PHI at termination. HHS publishes sample provisions, and BAAs are commonly attached to master services agreements and cloud contracts.

The BAA is the functional cousin of the GDPR's Art. 28 data processing agreement, but the two are not interchangeable. A BAA is required only within the HIPAA perimeter (a pharmaceutical sponsor receiving trial data from a US site is not a business associate and does not sign one, whereas an EDC vendor hosting data for a hospital may be), while a DPA is required for every processor regardless of sector. A BAA does not address international transfers, DPIAs or data subject rights in GDPR terms, and a DPA does not satisfy HIPAA's specific content requirements. Vendors serving both US healthcare customers and EU life sciences companies therefore typically maintain both instruments, and iliomad's contractual review checks that the two are consistent, particularly on breach timelines, subcontractor flow-down and data return. See also iliomad's HIPAA services.