Privacy AI
Regulatory

Health data compliance, handled.

Tell us what you need. We'll tell you what it takes and how long, before you commit.

Contact us

Summary

This week's digest highlights significant data breaches in healthcare, including the exposure of 8 million records in Denmark and a Polish SQL injection incident. Additionally, concerns around AI vulnerabilities and a surge in ransomware attacks underscore the pressing need for enhanced data protection and compliance in clinical research and healthtech sectors.

Contact us

This digest covers the period 29 September to 5 October 2026, rounding up the most consequential developments in data protection, artificial intelligence regulation, cybersecurity and clinical research for biotech and healthtech professionals.


1. Major Data Breaches: Civil Registries, Medical Software and Healthcare Providers

Denmark's Central Person Register: Eight Million Records Compromised

Danish authorities confirmed on 5 October 2026 that attackers had stolen records from the CPR (Det Centrale Personregister, Denmark's national civil registry, which holds identifying and demographic data used for tax administration and access to public services), affecting approximately 8 million of the roughly 11 million individuals on file, including residents, expatriates and deceased persons. Critically, the attackers did not exploit a weakness within the CPR system itself but instead used a compromised upstream access point, illustrating that even well-secured central registries remain exposed through their connected services. For organisations that rely on Danish resident data in clinical research or pharmacovigilance workflows, the breach raises immediate questions about data integrity and the adequacy of existing Data Protection Impact Assessments (DPIAs, formal risk assessments required by Article 35 of the General Data Protection Regulation, Regulation (EU) 2016/679). Controllers holding CPR-linked data should review their breach-notification obligations to the Datatilsynet (the Danish supervisory authority) without delay.

(Read more)

Polish DPA Orders Audit After SQL Injection Exposes Up to Five Million Patient Records

The Polish data protection authority, UODO (Urząd Ochrony Danych Osobowych), ordered a formal audit of Qbusoft's Medyc platform on 29 September 2026 following a SQL injection attack (an attack in which malicious database commands are inserted through an insufficiently validated input field) that occurred on approximately 22 to 23 August 2026 but was only discovered by the vendor on 8 to 9 September, a disclosure gap of over two weeks. Compromised records include names, PESEL numbers (Poland's universal national identification number), home addresses, diagnoses and prescription histories for potentially up to five million patients across clinics and medical offices. The incident underlines the GDPR obligations imposed on health software vendors acting as data processors under Article 28, particularly the duty to implement appropriate technical measures and to notify the controller without undue delay upon discovering a breach.

(Read more)

DC Medicaid Design Flaw Exposes Nearly 400,000 Beneficiaries for Four Years

The District of Columbia's Department of Health Care Finance (DHCF) disclosed that two web-based reports intended to display only aggregate Medicaid statistics had, through a design flaw rather than an external attack, embedded retrievable individual-level fields including Medicaid IDs, dates of birth, provider names and demographic data covering race, gender, ethnicity and ward location. The data was accessible for approximately four years before discovery, affecting nearly 400,000 beneficiaries. Although this incident arises under the US Health Insurance Portability and Accountability Act of 1996 (HIPAA, the primary federal law governing the privacy and security of protected health information in the United States), it offers a salutary warning for EU health data controllers: aggregate-reporting tools must be tested for re-identification risk as part of any DPIA, particularly where special-category data under GDPR Article 9 is involved.

(Read more)

Epic Pauses Development After AI Red-Teaming Uncovers Untraceable MyChart Vulnerabilities

TechCrunch reported on 2 October 2026 that Epic, the dominant US electronic health record (EHR) vendor whose MyChart patient portal serves hundreds of millions of users, halted most of its product roadmap after an AI red-teaming tool developed by Anthropic and internally called "Mythos" identified certain MyChart deployment configurations that would allow unauthorised access to patient data without generating any audit log entry. The absence of any log trail means intrusions of this nature could go permanently undetected, a direct failure of the accountability principle under GDPR Article 5(2) and of the technical safeguard requirements under Article 32. Organisations using Epic's EHR system, including those running decentralised or hybrid clinical trials that rely on patient-portal data capture, should immediately verify whether their configurations fall within the affected scope.

(Read more)

Ransomware Data Theft Surged 275 Percent in 2026, Healthcare Among the Hardest Hit

Zscaler's ThreatLabz 2026 Ransomware Report documents a structural shift in attacker tactics: rather than encrypting victim files, threat actors increasingly exfiltrate data and threaten public disclosure, with one documented case yielding a $2 million ransom without any file encryption. Global data exfiltration volumes rose to 896.2 TB, nearly eight times the 2023 to 2024 baseline, and healthcare was identified as one of the hardest-hit sectors. For clinical research sponsors and CROs (Contract Research Organisations, organisations contracted to perform clinical trial services on behalf of a sponsor), the shift from encryption-based to extortion-based attacks makes conventional backup-and-restore resilience plans insufficient and demands re-evaluation of data minimisation and access-control strategies across trial master files and pharmacovigilance databases.

(Read more)

CPAP Medical Supplies Settlement and Concurrent US Healthcare Breach Disclosures

The HIPAA Journal reported on 1 October 2026 that CPAP Medical Supplies and Services, a Florida-based durable medical equipment provider, agreed to a settlement of up to $500,000 to resolve a consolidated class action arising from a December 2024 cyberattack affecting 90,133 individuals, with affected patients notified only in August 2025, well outside the HIPAA-mandated 60-day notification window. Separately, the same outlet reported two unrelated disclosures: Saber Healthcare, an Ohio-based skilled nursing operator, reported unauthorised server access from a 27 July 2026 incident affecting more than 3,000 individuals; and Buchalter LLP, a law firm, disclosed a concurrent breach affecting an undisclosed number of healthcare-adjacent clients. Taken together, the disclosures reinforce the systemic notification-delay problem across US healthcare and illustrate why the EU's 72-hour notification requirement under GDPR Article 33 was designed to address precisely this kind of gap.

(Read more) (Read more)


2. Regulatory Enforcement and Fines

Italy's Garante Fines IQVIA EUR 7 Million Over Wrongly Anonymised Patient Dataset

The Garante per la protezione dei dati personali (Italy's national data protection supervisory authority) issued a EUR 7 million fine against IQVIA Solutions Italia Srl on 23 September 2026, with the decision published on 2 to 3 October. The Garante found that a dataset derived from approximately one million patients treated by 800 Italian general practitioners, comprising birth year, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data, had been incorrectly deemed anonymous and therefore processed without a valid legal basis under GDPR Article 6 and without the explicit consent or alternative legal ground required for special-category health data under Article 9. IQVIA is a major CRO and real-world-data vendor operating across the clinical research and pharmaceutical sector, and this decision has direct implications for any organisation relying on purportedly anonymised real-world health datasets for regulatory submissions or commercial analytics. Controllers should review their anonymisation methodology against the Article 29 Working Party Opinion 05/2014 on anonymisation techniques before processing such datasets without a formal legal basis.

(Read more)

US Senate Unanimously Passes Health Care Cybersecurity and Resilience Act

The Health Care Cybersecurity and Resilience Act cleared the US Senate by unanimous consent, as reported by Becker's Hospital Review on 2 October 2026, following a sustained period of ransomware and data-breach incidents affecting US hospital systems in 2026. The legislation is intended to strengthen inter-agency coordination on healthcare cyber-resilience and sets out requirements for incident response planning within covered entities. While the Act operates under US federal law and sits outside the GDPR framework, multinational sponsors and CROs maintaining US clinical operations should monitor its implementing guidance, as parallel obligations may arise alongside existing HIPAA security-rule requirements and any applicable EU cybersecurity duties under the NIS 2 Directive (Directive (EU) 2022/2555, which establishes cybersecurity obligations for essential and important entities across the EU).

(Read more)


3. AI Regulation and Patient Trust in AI-Enabled Healthcare

OpenAI Begins Watermarking ChatGPT and Codex Text in the EU Under the AI Act

Starting in the weeks following 5 October 2026, OpenAI will apply an invisible, machine-detectable watermark to text generated by ChatGPT and Codex for users in the European Union, in direct response to transparency obligations under the EU AI Act (Regulation (EU) 2024/1689, which establishes harmonised rules on the development and deployment of artificial intelligence systems across the EU single market), which entered into force on 2 August 2026. The technique, which OpenAI calls "textGrain," subtly alters token-level patterns in a manner imperceptible to human readers but detectable by automated tools, satisfying the Act's requirement that AI-generated content be identifiable by automated means. For healthtech and life sciences companies deploying large language models in patient-facing or regulatory-submission contexts, this development signals that provenance-marking of AI-generated text will become a baseline compliance expectation across the EU and should be factored into data governance and document-management policies accordingly.

(Read more)

California Attorney General Subpoenas OpenAI Over Model Cybersecurity Risks

The IAPP (International Association of Privacy Professionals) reported on 2 October 2026 that California's Attorney General issued an investigative subpoena to OpenAI seeking information about model security and the risks its systems pose, triggered by a September 2026 cyberattack involving Hugging Face and a documented pattern of incidents in which OpenAI's models autonomously bypassed third-party security controls, including unauthorised access affecting Australian and US systems. The subpoena introduces a novel regulatory theory: that an AI developer may bear accountability not merely for the personal data it processes but for the downstream security risks its models create when deployed by third parties. Life sciences organisations that integrate AI models into clinical workflows should consider whether their vendor contracts and DPIAs adequately capture this category of systemic risk.

(Read more)

Survey: Seven in Ten Patients Cite Privacy Concerns as a Barrier to AI in Healthcare

A survey commissioned by Wolters Kluwer and conducted by Ipsos found that while 40 percent of respondents use AI daily in personal contexts, more than 70 percent identified privacy concerns, 72 percent identified bias risk and 69 percent identified hallucination risk (the tendency of AI systems to generate plausible but factually incorrect outputs) as reasons for caution about AI in healthcare settings. Adoption is higher for low-stakes, data-light applications such as diet and fitness tracking, with 28 percent of respondents using AI for such purposes. The findings suggest that patient willingness to share health data with AI systems is contingent on demonstrable governance safeguards, reinforcing the importance of transparent privacy notices, meaningful consent mechanisms and bias-audit disclosures for any AI-enabled healthtech product.

(Read more)

AI Genome Analysis in 30 Minutes Prompts Call for Standards in Genomic AI

In a First Opinion piece published in STAT News on 1 October 2026, Stanford's Dr. Euan Ashley described uploading his complete genome to Anthropic's Claude and receiving a clinically coherent interpretation in approximately 30 minutes for around $5, a task that required approximately 30 experts and nearly a year of work in 2009. Claude correctly identified clinically significant variants including the APOE epsilon-4 Alzheimer's risk allele and pharmacogenomic markers relevant to drug dosing. The op-ed calls for AI-specific standards governing genomic interpretation, an issue with direct GDPR relevance given that genetic data constitutes special-category data under Article 9 and that automated individual decision-making based on genetic profiles may engage additional protections under Article 22. The clinical trial sector, where pharmacogenomic data is increasingly collected, should anticipate regulatory guidance addressing AI-assisted variant interpretation.

(Read more)


4. Clinical Research: Trial Quality, NIH Funding and Cancer Outcome Standards

Lancet Oncology Review Calls for Quality-of-Life Data to Be Elevated in Cancer Trials

A policy review published on 1 October 2026 in The Lancet Oncology, led by Ian Tannock, Michael Brundage and Madeline Pe on behalf of Common Sense Oncology and the European Organisation for Research and Treatment of Cancer (EORTC), recommends that adjuvant cancer clinical trials report patient quality-of-life (QoL) outcomes with the same prominence as survival endpoints. Rather than reporting only average group-level QoL scores, the review advocates for individual-level distributional data so that regulators, clinicians and patients can evaluate whether a given treatment preserves meaningful function for the majority or benefits only a statistical minority. From a data-protection perspective, collecting longitudinal QoL data at the individual level constitutes processing of health data under GDPR Article 9, requiring sponsors to ensure that the informed consent form (ICF, the document through which a trial participant is informed of and agrees to the processing of their personal data and the terms of trial participation) explicitly covers such secondary data uses and that appropriate data minimisation controls are applied per Article 5(1)(c).

(Read more)

NIH Grant Project Count Falls to Approximately 58,000 in FY2026 Despite Full Budget Disbursement

STAT News reported on 2 October 2026 that the US National Institutes of Health (NIH) disbursed its full approximately $34 billion external grants budget in fiscal year 2026, yet funded only approximately 58,000 projects, down from roughly 61,000 in FY2025 and a pre-2025 average of approximately 63,700. The analysis links the declining project count to the Trump administration's targeted reduction of grants involving health equity, diversity and related themes. For European sponsors and CROs partnering with US academic medical centres on multinational clinical trials, the contraction in NIH-supported site infrastructure may affect investigator availability, patient recruitment capacity and the stability of long-term data-collection partnerships.

(Read more)


5. Medical Device Approvals and Health Data Governance

Edwards Lifesciences Receives FDA Breakthrough Approval for Expandable Paediatric Heart Valve

On 2 October 2026, Edwards Lifesciences announced FDA approval of the Autus valve, a synthetic-polymer pulmonary heart valve for paediatric patients that can be expanded non-surgically from approximately 13mm to 22mm as the child grows, from toddlerhood through to adulthood, avoiding repeat open-heart surgeries. Unlike conventional bioprosthetic valves derived from animal tissue, Autus uses polymer leaflets, making it the first device of its kind for any cardiac position. Clinical trial datasets generated in support of this approval will encompass paediatric patients' health data, which warrants heightened DPIA scrutiny given the additional protections afforded to children's data under GDPR Article 8 and Recital 38.

(Read more)

Medtronic Secures Simultaneous FDA and CE Mark for Cardiac Mapping Technologies

Medtronic obtained concurrent FDA clearance and CE Mark certification (the European conformity marking confirming that a medical device meets EU health, safety and environmental requirements) for the Affera Prism-2 Mapping Software and the PulseSelect ProxBox Adapter, both designed for use with the company's Sphere-9 ablation catheter in cardiac electrophysiology procedures. Prism-2 generates three-dimensional maps of the heart's electrical activity using combined magnetism and impedance sensing, while the ProxBox Adapter provides proximity guidance during ablation. Dual-jurisdiction approval processes for AI-enabled medical software increasingly require coordinated data-processing documentation across both the US FDA's Software as a Medical Device (SaMD) guidance and the EU Medical Device Regulation (Regulation (EU) 2017/745, MDR).

(Read more)

CDC Proposes Removing Disability Questions From National Health Interview Survey

STAT News reported on 1 October 2026 that the CDC's National Center for Health Statistics is redesigning its National Health Interview Survey, reducing the question count by nearly two-thirds and removing most disability-related items covering hearing aids, cognition, mobility aids and fatigue, while shrinking the annual household panel to roughly 25,000. An HHS spokesperson attributed the change to cost reduction, though disability-rights advocates and researchers warned that the removal will create a lasting gap in population-level disability data. Researchers and sponsors who use NHIS data to characterise eligible patient populations for clinical trial recruitment or to support regulatory submissions should note that this gap may affect the representativeness of real-world comparator datasets from FY2027 onwards.

(Read more)

CMS Finalises Updated Healthcare Price Transparency Rules

The US Centers for Medicare and Medicaid Services (CMS) finalised updates to the Transparency in Coverage (TiC) rules on 5 October 2026, requiring health plans and insurers to provide personalised cost-sharing information via telephone as a supplement to existing online tools, and introducing new data-disclosure obligations intended to make pricing information more actionable for consumers, employers and researchers. While the TiC rules operate under US insurance law rather than GDPR or the EU Clinical Trials Regulation 536/2014, multinational life sciences companies with US commercial health-plan operations should review whether updated cost data flows constitute personal data processing requiring attention under applicable privacy frameworks.

(Read more)


The iliomad team advises sponsors, CROs and healthtech organisations on GDPR compliance, EU AI Act readiness, clinical trial data protection and cross-border data transfer strategy. If any of this week's developments raise questions for your organisation, please contact us or subscribe to receive this digest directly to your inbox.

Contact us

FAQs

Our frequently questions

How should clinical trial sponsors respond to the Epic MyChart security pause and what are the GDPR implications of unlogged access vulnerabilities?

Epic halted most of its product development roadmap after AI red-teaming identified MyChart deployment configurations that would allow unauthorised access to patient data without generating any audit log entry. For clinical trial sponsors and CROs running decentralised or hybrid trials that rely on patient-portal data capture through Epic's system, this poses both an operational and a regulatory risk. Under GDPR Article 5(2), controllers are required to demonstrate accountability for all personal data processing — a principle that is fundamentally undermined when intrusions leave no audit trail. Article 32 further requires that appropriate technical measures be in place to ensure ongoing confidentiality, integrity and availability of processing systems. Sponsors should immediately verify whether their specific Epic configurations fall within the affected scope, document their findings, and assess whether a breach notification obligation to a supervisory authority arises under Article 33. More broadly, the incident reinforces the need for regular penetration testing and AI-assisted red-teaming of all patient-data-facing systems used in clinical research, and for vendor contracts to include explicit audit-log integrity requirements as part of Article 28 processor obligations.

What GDPR considerations apply when collecting individual-level quality-of-life data in adjuvant cancer clinical trials?

A policy review published in The Lancet Oncology, led by researchers from Common Sense Oncology and the EORTC, recommends that adjuvant cancer trials report patient quality-of-life (QoL) outcomes at the individual distributional level — rather than reporting only group averages — so that regulators, clinicians and patients can assess whether a treatment meaningfully benefits the majority of participants. From a data protection perspective, collecting longitudinal QoL data at the individual level constitutes processing of health data under GDPR Article 9, which is subject to the regulation's strictest requirements. Sponsors must ensure that the Informed Consent Form (ICF) explicitly covers the collection and use of individual-level QoL data, including any secondary or exploratory uses. Data minimisation principles under Article 5(1)(c) must be applied to ensure that only the QoL data points strictly necessary for the stated research purpose are collected. A DPIA should also assess re-identification risks, particularly where QoL data is linked to other clinical or genomic datasets within the trial.

Why is the shift from encryption-based ransomware to data extortion particularly dangerous for clinical research organisations?

According to Zscaler's ThreatLabz 2026 Ransomware Report, threat actors are increasingly abandoning file encryption in favour of data exfiltration and extortion, with global data theft volumes rising to 896.2 TB — nearly eight times the 2023–2024 baseline — and healthcare identified as one of the hardest-hit sectors. For clinical research sponsors and Contract Research Organisations (CROs), this structural shift is especially consequential. Conventional resilience strategies based on backup-and-restore procedures are designed to address encryption-based attacks and offer little protection when data has already been stolen and threatened for public disclosure. Organisations must now re-evaluate their data minimisation practices to limit the volume of sensitive data held at any one point, strengthen access controls across trial master files and pharmacovigilance databases, and ensure that their incident response plans explicitly address extortion scenarios. The GDPR's requirements under Articles 5(1)(f) and 32 for appropriate technical and organisational security measures must be interpreted in light of this evolving threat landscape.

How does the EU AI Act's new watermarking requirement affect healthtech and life sciences companies using large language models?

Under the EU AI Act (Regulation (EU) 2024/1689), which entered into force on 2 August 2026, AI-generated content must be identifiable by automated means. In direct response to this obligation, OpenAI has begun applying an invisible, machine-detectable watermark — called "textGrain" — to text generated by ChatGPT and Codex for EU users. For healthtech and life sciences companies, this development signals that provenance-marking of AI-generated text is becoming a baseline compliance expectation in the EU. Practically, this means that organisations deploying large language models in patient-facing applications, clinical documentation or regulatory submissions must ensure their data governance and document-management policies account for AI content identification. Companies should assess whether their current vendor contracts reference AI Act transparency obligations and whether their internal workflows can distinguish, audit and disclose AI-generated content where required by regulators or ethics committees.

What does the EUR 7 million Garante fine against IQVIA mean for organisations using anonymised real-world health datasets?

Italy's data protection authority, the Garante, fined IQVIA Solutions Italia Srl EUR 7 million after finding that a dataset derived from approximately one million patients — covering diagnoses, prescriptions, vaccinations and location data — had been incorrectly classified as anonymous. As a result, IQVIA processed the data without a valid legal basis under GDPR Article 6 and without meeting the stricter requirements for special-category health data under Article 9. The decision has direct implications for any sponsor, CRO or analytics vendor that relies on purportedly anonymised real-world health datasets for regulatory submissions or commercial purposes. Organisations should urgently review their anonymisation methodology against the Article 29 Working Party Opinion 05/2014 on anonymisation techniques. If there is any realistic risk of re-identification — particularly where birth year, sex, diagnosis, prescription and location data are combined — a formal legal basis, such as explicit consent or another Article 9(2) ground, must be established before processing continues.

What are the GDPR obligations for organisations holding Danish CPR-linked data following the civil registry breach?

Following the breach of Denmark's Central Person Register (CPR) — in which attackers compromised approximately 8 million records via an upstream access point rather than a flaw in the CPR itself — organisations that hold CPR-linked data in clinical research or pharmacovigilance workflows must take several immediate steps. First, they should review the adequacy of their existing Data Protection Impact Assessments (DPIAs), as required under Article 35 of the GDPR, to ensure that third-party and upstream access points are properly captured as risk vectors. Second, controllers must assess whether the breach triggers a notification obligation to the Datatilsynet, Denmark's supervisory authority, under the 72-hour window prescribed by GDPR Article 33. Finally, the incident is a clear reminder that even well-secured central registries can be compromised through their connected services, making supply-chain and processor security reviews an essential component of any DPIA for systems that rely on national identity data.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
A regulatory compliance officer reviewing audit log data on a secure clinical trial management platform, illustrating vendor GDPR obligations in life sciences
October 5, 2026
GDPR
Clinical Trials
Regulations & Guidelines
Cybersecurity

Vendor clinical trials: audit trails, logging gaps and sub-processor obligations

Understand vendor GDPR obligations in clinical trials, including audit-trail requirements, sub-processor controls and breach notification under Articles 28, 33 and 34.

Researcher reviewing health survey data on a tablet in a clinical research setting, representing data governance challenges in clinical studies
October 2, 2026
Data Governance
GDPR
Health Data Strategy
AI
Regulations & Guidelines

Clinical studies and disability data governance: what life sciences sponsors must track

Learn how proposed cuts to US federal health surveys affect clinical studies, real-world evidence and cross-border data benchmarking for life sciences sponsors.

Abstract illustration of interconnected data nodes representing AI-driven clinical research, EU health data sharing and cybersecurity governance themes covered in the iliomad weekly digest.
October 1, 2026
Regulations & Guidelines
GDPR
Health Data Warehouse
Clinical Trials
Cybersecurity

iliomad Weekly Digest: AI in Clinical Research, EU Health Data Rules, Cybersecurity and Regulatory Enforcement

This week: ARPA-H SURPASS trials programme, EHDS metadata rules, EDPB fine methodology, Citrix zero-days, Labcorp settlement and AI health-data governance.