Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

N

NIS2 Directive

The NIS2 Directive, Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, replaced the 2016 NIS Directive and had to be transposed by Member States by 17 October 2024, with national laws entering into force during 2024 and 2025. It widens the range of regulated sectors, harmonises security and reporting obligations, and strengthens supervision and sanctions.

The Directive applies to "essential" and "important" entities in Annex I and II sectors that meet size thresholds (generally medium and large enterprises) or are otherwise designated. The health sector is in Annex I and covers healthcare providers, EU reference laboratories, entities carrying out research and development of medicinal products, manufacturers of basic pharmaceutical products and preparations, and manufacturers of medical devices considered critical during a public health emergency; manufacturers of other medical devices and in vitro diagnostics fall under Annex II. Regulated entities must adopt risk management measures covering policies, incident handling, business continuity, supply chain security, secure development, encryption, access control and multi-factor authentication, and training (Art. 21); management bodies must approve the measures and are personally accountable. Significant incidents must be reported to the national CSIRT or competent authority with an early warning within 24 hours, an incident notification within 72 hours and a final report within one month (Art. 23). Fines reach EUR 10 million or 2% of worldwide turnover for essential entities.

NIS2 operates alongside the GDPR: a cyber incident affecting personal data may require both a NIS2 report and a personal data breach notification, and Art. 21 measures overlap substantially with Art. 32 security of processing. For pharmaceutical, biotech and MedTech companies, NIS2 turns information security from a good practice into a supervised legal duty with board-level accountability; mapping which group entities are in scope in which Member State is the first step, since transposition varies. ISO 27001 certification, which iliomad holds, provides a recognised framework for demonstrating compliance.