Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

H

HIPAA (Health Insurance Portability and Accountability Act)

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is the US federal statute whose administrative simplification provisions, implemented by the Department of Health and Human Services in 45 CFR Parts 160 and 164, protect the privacy and security of individually identifiable health information. Its main components are the Privacy Rule (2003), which governs uses and disclosures of protected health information (PHI); the Security Rule (2005), which requires administrative, physical and technical safeguards for electronic PHI; the Breach Notification Rule (2009, under the HITECH Act), which requires notification of individuals, HHS and sometimes the media following a breach of unsecured PHI; and the Enforcement Rule. Enforcement is by the HHS Office for Civil Rights, with civil penalties per violation category adjusted annually and criminal penalties for knowing misuse.

HIPAA applies to "covered entities", meaning health plans, healthcare clearinghouses and healthcare providers that transmit health information electronically in connection with standard transactions, and to their "business associates", vendors that create, receive, maintain or transmit PHI on their behalf under a business associate agreement. It does not apply to health information held by entities outside this perimeter, such as most wellness app developers, employers or, crucially, pharmaceutical sponsors receiving trial data, although those may be subject to state privacy laws (California's CCPA/CPRA, Washington's My Health My Data Act) and to FTC enforcement. Research uses of PHI by covered entities require either a HIPAA authorisation from the patient (typically embedded in the informed consent package), a waiver by an IRB or privacy board, use of a limited data set under a data use agreement, or de-identification under the Safe Harbor or Expert Determination methods.

HIPAA and the GDPR differ in structure: HIPAA is sector- and entity-based while the GDPR is comprehensive; HIPAA treats properly de-identified data as outside its scope while the GDPR treats coded data as pseudonymised personal data; HIPAA has no equivalent of the GDPR's transfer rules, DPO or DPIA; and the GDPR has no equivalent of the HIPAA authorisation. A transatlantic trial therefore needs both frameworks mapped: US sites operate under HIPAA and the Common Rule, EU sites under the GDPR and the CTR, and the sponsor must reconcile consent language, de-identification versus pseudonymisation and breach procedures. See iliomad's HIPAA compliance services and the CPRA page.