Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

Z

Zero trust architecture

Zero trust architecture is a cybersecurity model built on the principle "never trust, always verify": no user, device, application or network segment is trusted by default, whether inside or outside the traditional corporate perimeter, and every access request is authenticated, authorised and continuously evaluated against policy based on identity, device health, location, behaviour and the sensitivity of the resource. The reference description is NIST Special Publication 800-207 (2020), and the model is promoted by ENISA, the US Cybersecurity and Infrastructure Security Agency and national agencies such as the UK NCSC and France's ANSSI as the answer to cloud adoption, remote work and the failure of perimeter-based defences against lateral movement by attackers.

Core components include strong identity and access management with multi-factor authentication and single sign-on; least-privilege and just-in-time access; device posture assessment and endpoint detection; micro-segmentation of networks so that a compromised system cannot reach others; encryption of all traffic; continuous monitoring, logging and analytics; and policy engines that grant access per session rather than per network. Zero trust is an architecture and a programme rather than a product, typically implemented over several years.

For life sciences organisations, zero trust addresses the realities of clinical research: data spread across sponsors, CROs, sites, laboratories and cloud vendors; thousands of external users (investigators, monitors, vendor staff) accessing EDC, eCOA and safety systems; and ransomware groups that specifically target hospitals and pharmaceutical companies. Legally, zero trust measures map directly onto the Art. 32 GDPR duty to ensure security of processing appropriate to the risk of health data, onto the risk management measures of Art. 21 of the NIS2 Directive (access control, multi-factor authentication, network security, supply chain security), onto the cybersecurity requirements for connected medical devices and onto Art. 15 of the AI Act on robustness and cybersecurity of high-risk AI systems. ISO/IEC 27001 Annex A controls provide the management framework, and zero trust maturity is an increasingly common question in vendor assessments and investor due diligence.