Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

I

ISO/IEC 27001 (information security management)

ISO/IEC 27001 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). An ISMS is a risk-based framework of policies, processes and controls that protects the confidentiality, integrity and availability of information. The current edition, ISO/IEC 27001:2022, follows the harmonised structure of management-system standards (context, leadership, planning, support, operation, performance evaluation, improvement) and references 93 controls in Annex A, grouped into organisational, people, physical and technological themes, with implementation guidance in ISO/IEC 27002:2022. Organisations certified against the 2013 edition had to transition by October 2025. Certification is granted by accredited bodies after audit and maintained through annual surveillance and three-yearly recertification.

Related standards extend the ISMS: ISO/IEC 27701 adds privacy information management requirements for controllers and processors, mapping to GDPR obligations; ISO/IEC 27017 and 27018 address cloud security and protection of personal data in public clouds; ISO 27799 applies 27002 to health informatics; ISO/IEC 27005 covers information security risk management; and ISO/IEC 42001 applies the same architecture to AI management. In France, the HDS certification for hosting of health data builds on ISO 27001.

ISO 27001 has no formal legal status under the GDPR, but certification is widely used as evidence of "appropriate technical and organisational measures" under Art. 32 security of processing and as a proxy for processor guarantees under Art. 28; the NIS2 Directive allows Member States to require or recognise certification, and the MDR cybersecurity expectations and AI Act Art. 15 robustness requirements map onto ISMS controls. Sponsors and CROs therefore routinely require ISO 27001 (or SOC 2 Type II) from EDC, eCOA, cloud and safety-database vendors in their vendor assessments, while remembering that certification scope matters: a certificate covering only a data centre says little about application security or the vendor's staff. iliomad holds ISO 27001, 27005 and 9001 certifications and applies the standard's risk methodology in its DPIAs.