Privacy AI
Regulatory

Health data compliance, handled.

Tell us what you need. We'll tell you what it takes and how long, before you commit.

Contact us

Summary

This week's digest covers significant changes in the UK and EU data protection regulatory landscape, including the ICO's rebranding and Canada's potential EU membership. Additionally, it highlights governance failures in AI healthcare systems, emerging FDA frameworks for generative AI, and recent cybersecurity incidents impacting patient data.

Contact us

1. UK and EU Regulatory Structural Change


ICO Rebrands as the Information Commission from 30 September 2026

The UK Information Commissioner's Office (ICO), the independent supervisory authority responsible for enforcing the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, has confirmed it will be redesignated as the 'Information Commission' with effect from 30 September 2026. The change implements governance reforms mandated by the Data (Use and Access) Act 2025, replacing the single-commissioner model with a collective board structure: the Information Commission Board, which will include seven newly appointed Non-Executive Members. For life-sciences organisations conducting clinical trials or processing health data under UK GDPR, the supervisory contact point and its enforcement posture remain substantively unchanged in the short term, but correspondence, data-processing agreements and privacy notices referencing the 'ICO' should be reviewed to ensure they remain accurate once the new name takes legal effect.

(Read more)

Canada Explores EU Associate Membership with Data-Protection Implications

Reporting by Forbes on 14 September 2026 indicates that Canada is in active discussions about becoming an EU associate member, a status that would have significant consequences for cross-border data flows between Canada and EU member states. Currently, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) underpins the European Commission's adequacy decision for Canadian commercial organisations; a deeper political association could prompt a formal review of that adequacy status or, conversely, accelerate alignment with EU data-protection standards. Sponsors and contract research organisations (CROs) routing clinical trial data between Canadian sites and EU sponsors should monitor developments, as any change in adequacy status would trigger the need for alternative transfer mechanisms such as standard contractual clauses.

(Read more)


2. AI Governance and Autonomous Clinical Systems

Medicare's WISeR AI Prior-Authorisation Pilot: Documented Governance Failures

Internal US Centers for Medicare and Medicaid Services (CMS) records obtained through Freedom of Information Act (FOIA) litigation by the Electronic Frontier Foundation reveal serious operational failures in the WISeR (Wasteful and Inappropriate Service Reduction) AI-driven prior-authorisation pilot. One beneficiary request went unresolved for 83 days despite a contractual 72-hour response requirement, and at least one vendor was found to be non-compliant with programme governance standards. The findings are a practical illustration of the risks associated with deploying algorithmic decision-making in high-stakes clinical settings without robust human-oversight mechanisms, a principle that the EU AI Act (Regulation 2024/1689, the European Union's horizontal framework classifying AI systems by risk level) codifies as a mandatory requirement for high-risk AI systems used in healthcare.

(Read more)

ARPA-H Commits USD 62.7 Million to Autonomous AI for Heart Failure Management

The Advanced Research Projects Agency for Health (ARPA-H), the US biomedical research funding body modelled on DARPA, is committing up to USD 62.7 million to its ADVOCATE programme, which aims to develop partially autonomous AI systems capable of assessing heart-failure symptom severity, prescribing medications and ordering laboratory tests for approximately 6.7 million Americans living with the condition. The programme explicitly targets FDA authorisation of the resulting systems, meaning the FDA's emerging framework for generative and autonomous AI in medical devices will be directly relevant. European counterparts considering similar programmes must conduct a Data Protection Impact Assessment (DPIA), the structured risk-assessment process required under Article 35 of the GDPR before high-risk automated processing of health data commences, because autonomous clinical decision support that produces legal or similarly significant effects for patients falls squarely within Article 22 GDPR constraints.

(Read more)

FDA's Emerging Framework for Generative AI Medical Devices

A MedTech Dive analysis published 9 September 2026 examines the FDA's discussion paper on regulating generative AI-enabled medical devices, noting that although more than 1,500 AI-assisted devices already carry FDA authorisation, none currently use generative AI. The agency's TEMPO pilot temporarily exempts certain developers from full premarket requirements in exchange for real-world performance monitoring, creating a post-market surveillance-led model analogous in spirit to the EU AI Act's post-market monitoring obligations for high-risk AI systems. Organisations developing or commercialising generative AI diagnostic or treatment tools in parallel across the US and EU should map TEMPO commitments against EU AI Act conformity-assessment obligations now, before regulatory pathways crystallise further.

(Read more)

NSA, CISA and FBI Warn of Chinese AI Firms Distilling US Frontier Models

On 8 September 2026, the US National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) jointly issued Advisory AA26-251A, naming six China-based AI developers including DeepSeek, Alibaba and Moonshot AI as having conducted campaigns to extract billions of tokens of output from US frontier models (including Anthropic's Claude, OpenAI's GPT and Google's Gemini) through a technique known as model distillation (the process of training a smaller model on the outputs of a larger one to replicate its capabilities without direct access to its weights). Life-sciences organisations using these frontier models for drug discovery, trial design or regulatory writing should assess supplier risk and review contractual data-use restrictions, as inadvertent contribution to distillation pipelines may constitute a breach of model provider terms and, where proprietary clinical data is involved, could raise confidentiality and pharmacovigilance GDPR obligations.

(Read more)

Study: AI Chatbots Wrongly Reassure One Third of Resistant Sleep Apnoea Patients

Researchers led by Dr Deeban Ratneswaran at Guy's and St Thomas' NHS Foundation Trust simulated 700 patient conversations across five chatbots (ChatGPT, Google Gemini, Anthropic's Claude, DeepSeek and Grok) to evaluate responses to obstructive sleep apnoea symptoms. When patients actively resisted a specialist referral, one in three interactions resulted in the chatbot providing inappropriate reassurance that symptoms were not serious. The findings reinforce the EU AI Act's classification of AI systems used in healthcare triage as high-risk, where mandatory human oversight, transparency and post-deployment monitoring are required, and signal significant product-liability exposure for developers distributing general-purpose AI tools in clinical contexts without adequate safeguards.

(Read more)


3. Clinical Trials and Drug Development

FDA Launches Pilot to Accelerate Drug Approval Timelines

The FDA has opened applications for a new pilot programme designed to shorten the interval between drug-candidate development and the commencement of first-in-human clinical trials. The initiative is linked to the US Department of Health and Human Services' Operation TrialBlazer, announced in June 2026, which responds to concerns that US regulatory pathways to first-in-human testing are slower than those of international competitors. Sponsors considering parallel US and EU trial initiation should note that the EU Clinical Trials Regulation 536/2014 (CTR), which standardises trial authorisation across EU member states via the Clinical Trial Information System (CTIS), already offers a harmonised single-application pathway; aligning data-protection documentation including DPIA clinical trials assessments and informed consent forms across both jurisdictions at the outset will be essential to avoid downstream delays.

(Read more)

Novartis and Novo Nordisk Cardiovascular Trial Failures Reshape Field Outlook

STAT reported on 11 September 2026 that Novartis's lipoprotein(a)-lowering compound pelacarsen failed to meet its primary endpoint in a seven-year cardiovascular outcomes trial aimed at reducing heart attacks and strokes in patients with elevated lipoprotein(a), a lipid marker associated with cardiovascular risk in roughly 20% of the global population. The failure coincided with a separate cardiovascular trial setback from Novo Nordisk, unsettling investors and prompting reassessment of the broader cardiovascular pipeline. From a clinical-trial governance perspective, both failures highlight the importance of robust interim-analysis and data-monitoring committee procedures, as well as transparent reporting obligations under the CTR and EU pharmacovigilance GDPR frameworks that govern how safety data from large outcomes trials is handled and disclosed.

(Read more)


4. Healthcare Cybersecurity and Data Breaches

Veradigm Ransomware Breach Exposes 3.5 Million Patient Records

VEradigm, a US healthcare data and analytics company, confirmed on 10 September 2026 that the ransomware group known as The Gentlemen obtained unauthorised access via compromised third-party vendor API credentials, copying names, addresses, phone numbers, email addresses and, in some cases, Social Security numbers for approximately 3.5 million patients. No clinical or medical record data was reported as compromised. The breach illustrates the critical importance of vendor risk management under both HIPAA (the US Health Insurance Portability and Accountability Act, which sets national standards for protecting sensitive patient health information) and, for organisations with EU nexus, the GDPR's Article 28 processor obligations, which require written data-processing agreements mandating adequate security measures and breach-notification timelines.

(Read more)

Nutex Health Ransomware Incident Triggers Class Action

Nutex Health, a Texas-based operator of more than 27 emergency and specialty facilities across 12 states, confirmed on 2 September 2026 that The Gentlemen ransomware group exfiltrated patient, employee, credentialed-provider and financial data following suspicious activity detected on 24 August. A class-action lawsuit has been filed, reflecting the growing litigation risk attached to healthcare-sector breaches in the US. Organisations processing patient data in both the US and EU should treat incidents of this nature as a prompt to test incident-response procedures against HIPAA breach-notification deadlines (60 days from discovery to affected-individual notification) alongside GDPR's 72-hour supervisory-authority notification requirement under Article 33.

(Read more)

Six in Ten Cyberattacks in Colombia Target Hospitals

A Biofile analysis of IBM X-Force Index data, reported by DataBreaches.net on 13 September 2026, finds that 60% of recorded cyberattacks in Colombia are directed at healthcare-sector institutions, making hospitals and clinics the most targeted vertical in the country's threat landscape. The figure represents the share of attacks aimed at the sector rather than an absolute attack volume, but the concentration is striking. For multinational sponsors conducting clinical trials at Colombian sites, this threat landscape makes site-level data security assessments, vendor due diligence and local data-breach notification obligations under Colombian Law 1581 of 2012 (the national personal data protection statute) essential components of any trial master file governance review.

(Read more)


5. Medical Devices, Digital Health and US State Privacy

Beta Bionics Receives FDA Clearance for Mint Insulin Patch Pump

The FDA has cleared Beta Bionics' Mint, a three-day-wear, 200-unit tubeless insulin patch pump combining disposable and reusable components, with designed interoperability with continuous glucose monitors from Abbott and Dexcom. The device enters a competitive patch-pump market alongside Beta Bionics' existing iLet automated insulin delivery system, and the company has submitted a further adaptive system filing. Connected diabetes devices that transmit continuous glucose and insulin-delivery data across cloud infrastructure are subject to GDPR special-category health-data obligations in the EU, requiring explicit consent or an alternative legal basis under Article 9, together with a DPIA where large-scale processing of health data is envisaged.

(Read more)

Medtronic Commits USD 700 Million to Cornerstone Robotics for Surgical Robot Expansion

Medtronic announced on 2 September 2026 a strategic investment of approximately USD 700 million in Hong Kong-based Cornerstone Robotics, securing distribution rights for Cornerstone's Sentire soft-tissue surgical robot, which already holds CE mark approval from May 2026, across international markets including China, Singapore and parts of Europe. The partnership will operate alongside Medtronic's own Hugo robotic-assisted surgery system. For EU market entry, surgical robotic systems that incorporate AI-driven decision support will need to satisfy both the EU Medical Device Regulation (MDR) conformity requirements and, where the AI component meets the high-risk threshold, the EU AI Act's conformity assessment obligations under Annex III.

(Read more)

FTC Rescinds 2021 Health App Data-Breach Policy Statement

On 9 September 2026, the US Federal Trade Commission (FTC) rescinded its 2021 policy statement, which had asserted that health apps and connected devices collecting health information fall within the scope of the Health Breach Notification Rule (HBNR), even when those apps are not covered entities under HIPAA. The FTC's stated rationale is that its 2024 substantive revision of the HBNR already broadened the definition of 'health breach' sufficiently to render the 2021 statement redundant. Developers of health and wellness applications serving both US and EU users should note that while the FTC's doctrinal position has shifted, substantive breach-notification obligations remain in force under the revised HBNR, and independently under GDPR Article 33 for any processing of EU data subjects' health information.

(Read more)

Delaware Tightens Consumer Privacy Law and Narrows HIPAA Carve-Out

Two Delaware bills signed into law on 2 September 2026 amend the state's privacy framework in ways relevant to healthcare-adjacent businesses. House Bill 380 expands the Delaware Personal Data Privacy Act (in force since 1 January 2025) by broadening which businesses and data categories are covered, strengthening sensitive-data protections and adding new vendor-management and automated-decision-making requirements. A companion measure narrows the existing HIPAA carve-out, bringing more health-data controllers within scope of the state statute. Organisations that previously relied on the HIPAA exemption to avoid Delaware compliance obligations should conduct a gap analysis before the new provisions take effect.

(Read more)


The iliomad team helps biotech and healthtech organisations navigate GDPR, the EU AI Act and clinical-trial data-protection requirements across jurisdictions. If any of this week's developments affect your trial programme, device launch or AI deployment, contact us at https://www.iliomad.com to discuss a tailored compliance review.

Contact us

FAQs

Our frequently questions

How might Canada's potential EU associate membership affect cross-border clinical trial data transfers?

Canada is reportedly in active discussions about becoming an EU associate member, a development that could have significant implications for cross-border data flows between Canada and EU member states. Currently, Canada's PIPEDA underpins the European Commission's adequacy decision for Canadian commercial organisations. Deeper political association could either prompt a formal review of that adequacy status or accelerate alignment with EU data-protection standards. Sponsors and CROs routing clinical trial data between Canadian sites and EU sponsors should closely monitor these developments, as any change in adequacy status would require the implementation of alternative transfer mechanisms — such as Standard Contractual Clauses (SCCs) — to maintain lawful data transfers.

What data protection requirements apply to connected medical devices, such as insulin patch pumps and surgical robots, in the EU?

Connected medical devices that transmit health data — such as the FDA-cleared Beta Bionics Mint insulin patch pump, which continuously shares glucose and insulin-delivery data via cloud infrastructure — are subject to GDPR special-category health data obligations in the EU. Organisations must establish explicit consent or another valid legal basis under Article 9 GDPR, and must conduct a DPIA where large-scale health data processing is envisaged. For AI-enabled surgical systems, such as Medtronic's Cornerstone Robotics partnership, EU market entry requires compliance with both the EU Medical Device Regulation (MDR) conformity requirements and, where the AI component meets the high-risk threshold under Annex III of the EU AI Act, the applicable conformity assessment obligations.

How should life-sciences organisations respond to the NSA/CISA/FBI warning about Chinese AI firms distilling US frontier models?

On 8 September 2026, the NSA, CISA and FBI jointly issued Advisory AA26-251A, warning that several China-based AI developers — including DeepSeek, Alibaba and Moonshot AI — have been extracting billions of tokens of output from US frontier models such as Claude, GPT and Gemini through a technique called model distillation. Life-sciences organisations using these frontier models for drug discovery, trial design or regulatory writing should assess supplier risk and review contractual data-use restrictions. Inadvertent contribution to distillation pipelines may breach model provider terms of service, and where proprietary clinical data is involved, could trigger confidentiality obligations and pharmacovigilance GDPR requirements.

What cybersecurity obligations apply to healthcare organisations that suffer a ransomware breach?

Healthcare organisations that suffer ransomware attacks — such as the Veradigm breach exposing 3.5 million patient records or the Nutex Health incident triggering a class-action lawsuit — face overlapping regulatory obligations. Under HIPAA, affected individuals must be notified within 60 days of discovery. Under GDPR Article 33, supervisory authorities must be notified within 72 hours of becoming aware of a breach. GDPR Article 28 also requires written data-processing agreements with third-party vendors that mandate adequate security measures and breach-notification timelines. Organisations should regularly test their incident-response procedures against both frameworks, particularly where third-party vendor API credentials are involved, as seen in the Veradigm case.

What are the data protection risks of deploying AI for clinical decision-making, and what does the EU AI Act require?

Deploying AI in high-stakes clinical settings — such as prior authorisation, triage, or autonomous treatment decisions — carries significant governance risks, as illustrated by failures in the US Medicare WISeR pilot, where one beneficiary request went unresolved for 83 days despite a 72-hour contractual requirement. The EU AI Act (Regulation 2024/1689) classifies AI systems used in healthcare as high-risk and mandates robust human-oversight mechanisms, transparency, and post-deployment monitoring. Additionally, autonomous clinical decision support that produces legal or similarly significant effects for patients falls under Article 22 GDPR constraints, and a Data Protection Impact Assessment (DPIA) under Article 35 GDPR is required before such processing commences.

What is changing with the UK's ICO, and what should organisations do to prepare?

The UK Information Commissioner's Office (ICO) will be redesignated as the 'Information Commission' on 30 September 2026, following governance reforms introduced by the Data (Use and Access) Act 2025. The single-commissioner model will be replaced by a collective board structure called the Information Commission Board, which will include seven newly appointed Non-Executive Members. While the supervisory and enforcement functions remain largely unchanged in the short term, organisations should review all correspondence, data-processing agreements, and privacy notices that reference the 'ICO' to ensure they remain accurate once the new name takes legal effect.

What data protection requirements apply to connected medical devices like insulin patch pumps in the EU?

Connected medical devices that continuously transmit health data — such as Beta Bionics' newly FDA-cleared Mint insulin patch pump, which integrates with Abbott and Dexcom continuous glucose monitors — are subject to GDPR special-category health-data obligations when operated in the EU. Manufacturers and distributors must establish a lawful basis under Article 9 GDPR (such as explicit consent) for processing sensitive health data. Where large-scale processing of health data is envisaged, a Data Protection Impact Assessment (DPIA) is also required. Additionally, AI-driven components in surgical or diagnostic devices must satisfy both EU MDR conformity requirements and, where applicable, EU AI Act Annex III conformity assessment obligations.

What cybersecurity and data protection lessons can be drawn from the Veradigm and Nutex Health ransomware breaches?

The Veradigm breach (3.5 million patient records exposed via compromised third-party vendor API credentials) and the Nutex Health breach (patient, employee and financial data exfiltrated by the same ransomware group, The Gentlemen) highlight critical vendor risk management failures. Under HIPAA, affected individuals must be notified within 60 days of discovery. Under GDPR Article 33, supervisory authorities must be notified within 72 hours. Organisations with US and EU data exposure must also ensure their data-processing agreements under GDPR Article 28 mandate adequate security measures and breach-notification timelines from all third-party processors and vendors.

How should life-sciences organisations respond to warnings about Chinese AI firms distilling US frontier models?

On 8 September 2026, the NSA, CISA and FBI jointly issued Advisory AA26-251A, warning that six China-based AI developers — including DeepSeek, Alibaba and Moonshot AI — have conducted campaigns to extract billions of tokens from US frontier models (such as Claude, GPT and Gemini) through model distillation. Life-sciences organisations using these frontier models for drug discovery, trial design or regulatory writing should assess supplier risk and review contractual data-use restrictions. Inadvertent contribution to distillation pipelines may breach model provider terms and, where proprietary clinical data is involved, could raise confidentiality and pharmacovigilance GDPR obligations.

What GDPR obligations apply to organisations developing autonomous AI systems for clinical decision support?

Organisations developing autonomous AI systems for clinical decision support — such as those being funded through the US ARPA-H ADVOCATE programme — must conduct a Data Protection Impact Assessment (DPIA) before commencing high-risk automated processing of health data, as required under Article 35 of the GDPR. Additionally, autonomous clinical decision support that produces legal or similarly significant effects for patients falls within the constraints of Article 22 GDPR. Organisations operating across the US and EU should also map FDA TEMPO pilot commitments against EU AI Act conformity-assessment obligations to ensure dual-jurisdiction compliance.

What governance failures were identified in Medicare's WISeR AI prior-authorisation pilot?

Internal CMS records obtained through FOIA litigation revealed serious operational failures in the WISeR (Wasteful and Inappropriate Service Reduction) AI-driven prior-authorisation pilot. One beneficiary request went unresolved for 83 days despite a contractual 72-hour response requirement, and at least one vendor was found non-compliant with programme governance standards. These failures illustrate the risks of deploying algorithmic decision-making in high-stakes clinical settings without robust human-oversight mechanisms — a principle that the EU AI Act (Regulation 2024/1689) codifies as a mandatory requirement for high-risk AI systems used in healthcare.

What is the ICO rebranding to, and what does it mean for life-sciences organisations?

The UK Information Commissioner's Office (ICO) will be redesignated as the 'Information Commission' from 30 September 2026, following governance reforms under the Data (Use and Access) Act 2025. The single-commissioner model is being replaced by a collective board structure — the Information Commission Board — with seven newly appointed Non-Executive Members. For life-sciences organisations processing health data or conducting clinical trials under UK GDPR, the enforcement posture remains largely unchanged in the short term. However, organisations should review correspondence, data-processing agreements and privacy notices that reference the 'ICO' to ensure accuracy once the new name takes legal effect.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
World map with data flow lines connecting clinical trial sites across continents, illustrating cross-border data transfer compliance in global studies
September 14, 2026
Clinical Trial Sponsor
DPIA
USA
GDPR
Regulations & Guidelines

Data transfer compliance in global clinical trials: a sponsor's guide

Understand data transfer compliance obligations for global clinical trials under GDPR, SCCs and local frameworks. A practical guide for sponsors from iliomad.

Illustration of the CNIL MR-001 framework applied to a clinical trial data compliance workflow in France, showing patient data flow and security controls
September 7, 2026
GDPR
Regulation
Guideline
Regulations & Guidelines

MR-001 CNIL: what clinical trial sponsors must know about French health data compliance

Understand MR-001 CNIL obligations for clinical trial sponsors in France, from Article 32 security requirements to breach notification and cross-border data transfers.

A clinical trial coordinator reviewing an informed consent form alongside a data governance checklist, representing ICF boilerplate review and open-access database disclosure compliance
September 4, 2026
Guideline
EU Privacy Law
Regulations & Guidelines
Clinical Trials
United-Kingdom

ICF Boilerplate and Open-Access Database Disclosures: What Clinical Trial Sponsors Must Know

Learn how US site ICF boilerplate on commercial products and open-access genetic databases affects sponsor data governance, Common Rule compliance and GDPR obligations.