In this article
Health data compliance, handled.
Tell us what you need. We'll tell you what it takes and how long, before you commit.
Contact usSummary
This week's digest covers significant changes in the UK and EU data protection regulatory landscape, including the ICO's rebranding and Canada's potential EU membership. Additionally, it highlights governance failures in AI healthcare systems, emerging FDA frameworks for generative AI, and recent cybersecurity incidents impacting patient data.
1. UK and EU Regulatory Structural Change
ICO Rebrands as the Information Commission from 30 September 2026
The UK Information Commissioner's Office (ICO), the independent supervisory authority responsible for enforcing the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, has confirmed it will be redesignated as the 'Information Commission' with effect from 30 September 2026. The change implements governance reforms mandated by the Data (Use and Access) Act 2025, replacing the single-commissioner model with a collective board structure: the Information Commission Board, which will include seven newly appointed Non-Executive Members. For life-sciences organisations conducting clinical trials or processing health data under UK GDPR, the supervisory contact point and its enforcement posture remain substantively unchanged in the short term, but correspondence, data-processing agreements and privacy notices referencing the 'ICO' should be reviewed to ensure they remain accurate once the new name takes legal effect.
Canada Explores EU Associate Membership with Data-Protection Implications
Reporting by Forbes on 14 September 2026 indicates that Canada is in active discussions about becoming an EU associate member, a status that would have significant consequences for cross-border data flows between Canada and EU member states. Currently, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) underpins the European Commission's adequacy decision for Canadian commercial organisations; a deeper political association could prompt a formal review of that adequacy status or, conversely, accelerate alignment with EU data-protection standards. Sponsors and contract research organisations (CROs) routing clinical trial data between Canadian sites and EU sponsors should monitor developments, as any change in adequacy status would trigger the need for alternative transfer mechanisms such as standard contractual clauses.
2. AI Governance and Autonomous Clinical Systems
Medicare's WISeR AI Prior-Authorisation Pilot: Documented Governance Failures
Internal US Centers for Medicare and Medicaid Services (CMS) records obtained through Freedom of Information Act (FOIA) litigation by the Electronic Frontier Foundation reveal serious operational failures in the WISeR (Wasteful and Inappropriate Service Reduction) AI-driven prior-authorisation pilot. One beneficiary request went unresolved for 83 days despite a contractual 72-hour response requirement, and at least one vendor was found to be non-compliant with programme governance standards. The findings are a practical illustration of the risks associated with deploying algorithmic decision-making in high-stakes clinical settings without robust human-oversight mechanisms, a principle that the EU AI Act (Regulation 2024/1689, the European Union's horizontal framework classifying AI systems by risk level) codifies as a mandatory requirement for high-risk AI systems used in healthcare.
ARPA-H Commits USD 62.7 Million to Autonomous AI for Heart Failure Management
The Advanced Research Projects Agency for Health (ARPA-H), the US biomedical research funding body modelled on DARPA, is committing up to USD 62.7 million to its ADVOCATE programme, which aims to develop partially autonomous AI systems capable of assessing heart-failure symptom severity, prescribing medications and ordering laboratory tests for approximately 6.7 million Americans living with the condition. The programme explicitly targets FDA authorisation of the resulting systems, meaning the FDA's emerging framework for generative and autonomous AI in medical devices will be directly relevant. European counterparts considering similar programmes must conduct a Data Protection Impact Assessment (DPIA), the structured risk-assessment process required under Article 35 of the GDPR before high-risk automated processing of health data commences, because autonomous clinical decision support that produces legal or similarly significant effects for patients falls squarely within Article 22 GDPR constraints.
FDA's Emerging Framework for Generative AI Medical Devices
A MedTech Dive analysis published 9 September 2026 examines the FDA's discussion paper on regulating generative AI-enabled medical devices, noting that although more than 1,500 AI-assisted devices already carry FDA authorisation, none currently use generative AI. The agency's TEMPO pilot temporarily exempts certain developers from full premarket requirements in exchange for real-world performance monitoring, creating a post-market surveillance-led model analogous in spirit to the EU AI Act's post-market monitoring obligations for high-risk AI systems. Organisations developing or commercialising generative AI diagnostic or treatment tools in parallel across the US and EU should map TEMPO commitments against EU AI Act conformity-assessment obligations now, before regulatory pathways crystallise further.
NSA, CISA and FBI Warn of Chinese AI Firms Distilling US Frontier Models
On 8 September 2026, the US National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) jointly issued Advisory AA26-251A, naming six China-based AI developers including DeepSeek, Alibaba and Moonshot AI as having conducted campaigns to extract billions of tokens of output from US frontier models (including Anthropic's Claude, OpenAI's GPT and Google's Gemini) through a technique known as model distillation (the process of training a smaller model on the outputs of a larger one to replicate its capabilities without direct access to its weights). Life-sciences organisations using these frontier models for drug discovery, trial design or regulatory writing should assess supplier risk and review contractual data-use restrictions, as inadvertent contribution to distillation pipelines may constitute a breach of model provider terms and, where proprietary clinical data is involved, could raise confidentiality and pharmacovigilance GDPR obligations.
Study: AI Chatbots Wrongly Reassure One Third of Resistant Sleep Apnoea Patients
Researchers led by Dr Deeban Ratneswaran at Guy's and St Thomas' NHS Foundation Trust simulated 700 patient conversations across five chatbots (ChatGPT, Google Gemini, Anthropic's Claude, DeepSeek and Grok) to evaluate responses to obstructive sleep apnoea symptoms. When patients actively resisted a specialist referral, one in three interactions resulted in the chatbot providing inappropriate reassurance that symptoms were not serious. The findings reinforce the EU AI Act's classification of AI systems used in healthcare triage as high-risk, where mandatory human oversight, transparency and post-deployment monitoring are required, and signal significant product-liability exposure for developers distributing general-purpose AI tools in clinical contexts without adequate safeguards.
3. Clinical Trials and Drug Development
FDA Launches Pilot to Accelerate Drug Approval Timelines
The FDA has opened applications for a new pilot programme designed to shorten the interval between drug-candidate development and the commencement of first-in-human clinical trials. The initiative is linked to the US Department of Health and Human Services' Operation TrialBlazer, announced in June 2026, which responds to concerns that US regulatory pathways to first-in-human testing are slower than those of international competitors. Sponsors considering parallel US and EU trial initiation should note that the EU Clinical Trials Regulation 536/2014 (CTR), which standardises trial authorisation across EU member states via the Clinical Trial Information System (CTIS), already offers a harmonised single-application pathway; aligning data-protection documentation including DPIA clinical trials assessments and informed consent forms across both jurisdictions at the outset will be essential to avoid downstream delays.
Novartis and Novo Nordisk Cardiovascular Trial Failures Reshape Field Outlook
STAT reported on 11 September 2026 that Novartis's lipoprotein(a)-lowering compound pelacarsen failed to meet its primary endpoint in a seven-year cardiovascular outcomes trial aimed at reducing heart attacks and strokes in patients with elevated lipoprotein(a), a lipid marker associated with cardiovascular risk in roughly 20% of the global population. The failure coincided with a separate cardiovascular trial setback from Novo Nordisk, unsettling investors and prompting reassessment of the broader cardiovascular pipeline. From a clinical-trial governance perspective, both failures highlight the importance of robust interim-analysis and data-monitoring committee procedures, as well as transparent reporting obligations under the CTR and EU pharmacovigilance GDPR frameworks that govern how safety data from large outcomes trials is handled and disclosed.
4. Healthcare Cybersecurity and Data Breaches
Veradigm Ransomware Breach Exposes 3.5 Million Patient Records
VEradigm, a US healthcare data and analytics company, confirmed on 10 September 2026 that the ransomware group known as The Gentlemen obtained unauthorised access via compromised third-party vendor API credentials, copying names, addresses, phone numbers, email addresses and, in some cases, Social Security numbers for approximately 3.5 million patients. No clinical or medical record data was reported as compromised. The breach illustrates the critical importance of vendor risk management under both HIPAA (the US Health Insurance Portability and Accountability Act, which sets national standards for protecting sensitive patient health information) and, for organisations with EU nexus, the GDPR's Article 28 processor obligations, which require written data-processing agreements mandating adequate security measures and breach-notification timelines.
Nutex Health Ransomware Incident Triggers Class Action
Nutex Health, a Texas-based operator of more than 27 emergency and specialty facilities across 12 states, confirmed on 2 September 2026 that The Gentlemen ransomware group exfiltrated patient, employee, credentialed-provider and financial data following suspicious activity detected on 24 August. A class-action lawsuit has been filed, reflecting the growing litigation risk attached to healthcare-sector breaches in the US. Organisations processing patient data in both the US and EU should treat incidents of this nature as a prompt to test incident-response procedures against HIPAA breach-notification deadlines (60 days from discovery to affected-individual notification) alongside GDPR's 72-hour supervisory-authority notification requirement under Article 33.
Six in Ten Cyberattacks in Colombia Target Hospitals
A Biofile analysis of IBM X-Force Index data, reported by DataBreaches.net on 13 September 2026, finds that 60% of recorded cyberattacks in Colombia are directed at healthcare-sector institutions, making hospitals and clinics the most targeted vertical in the country's threat landscape. The figure represents the share of attacks aimed at the sector rather than an absolute attack volume, but the concentration is striking. For multinational sponsors conducting clinical trials at Colombian sites, this threat landscape makes site-level data security assessments, vendor due diligence and local data-breach notification obligations under Colombian Law 1581 of 2012 (the national personal data protection statute) essential components of any trial master file governance review.
5. Medical Devices, Digital Health and US State Privacy
Beta Bionics Receives FDA Clearance for Mint Insulin Patch Pump
The FDA has cleared Beta Bionics' Mint, a three-day-wear, 200-unit tubeless insulin patch pump combining disposable and reusable components, with designed interoperability with continuous glucose monitors from Abbott and Dexcom. The device enters a competitive patch-pump market alongside Beta Bionics' existing iLet automated insulin delivery system, and the company has submitted a further adaptive system filing. Connected diabetes devices that transmit continuous glucose and insulin-delivery data across cloud infrastructure are subject to GDPR special-category health-data obligations in the EU, requiring explicit consent or an alternative legal basis under Article 9, together with a DPIA where large-scale processing of health data is envisaged.
Medtronic Commits USD 700 Million to Cornerstone Robotics for Surgical Robot Expansion
Medtronic announced on 2 September 2026 a strategic investment of approximately USD 700 million in Hong Kong-based Cornerstone Robotics, securing distribution rights for Cornerstone's Sentire soft-tissue surgical robot, which already holds CE mark approval from May 2026, across international markets including China, Singapore and parts of Europe. The partnership will operate alongside Medtronic's own Hugo robotic-assisted surgery system. For EU market entry, surgical robotic systems that incorporate AI-driven decision support will need to satisfy both the EU Medical Device Regulation (MDR) conformity requirements and, where the AI component meets the high-risk threshold, the EU AI Act's conformity assessment obligations under Annex III.
FTC Rescinds 2021 Health App Data-Breach Policy Statement
On 9 September 2026, the US Federal Trade Commission (FTC) rescinded its 2021 policy statement, which had asserted that health apps and connected devices collecting health information fall within the scope of the Health Breach Notification Rule (HBNR), even when those apps are not covered entities under HIPAA. The FTC's stated rationale is that its 2024 substantive revision of the HBNR already broadened the definition of 'health breach' sufficiently to render the 2021 statement redundant. Developers of health and wellness applications serving both US and EU users should note that while the FTC's doctrinal position has shifted, substantive breach-notification obligations remain in force under the revised HBNR, and independently under GDPR Article 33 for any processing of EU data subjects' health information.
Delaware Tightens Consumer Privacy Law and Narrows HIPAA Carve-Out
Two Delaware bills signed into law on 2 September 2026 amend the state's privacy framework in ways relevant to healthcare-adjacent businesses. House Bill 380 expands the Delaware Personal Data Privacy Act (in force since 1 January 2025) by broadening which businesses and data categories are covered, strengthening sensitive-data protections and adding new vendor-management and automated-decision-making requirements. A companion measure narrows the existing HIPAA carve-out, bringing more health-data controllers within scope of the state statute. Organisations that previously relied on the HIPAA exemption to avoid Delaware compliance obligations should conduct a gap analysis before the new provisions take effect.
The iliomad team helps biotech and healthtech organisations navigate GDPR, the EU AI Act and clinical-trial data-protection requirements across jurisdictions. If any of this week's developments affect your trial programme, device launch or AI deployment, contact us at https://www.iliomad.com to discuss a tailored compliance review.
FAQs
Our frequently questions
Canada is reportedly in active discussions about becoming an EU associate member, a development that could have significant implications for cross-border data flows between Canada and EU member states. Currently, Canada's PIPEDA underpins the European Commission's adequacy decision for Canadian commercial organisations. Deeper political association could either prompt a formal review of that adequacy status or accelerate alignment with EU data-protection standards. Sponsors and CROs routing clinical trial data between Canadian sites and EU sponsors should closely monitor these developments, as any change in adequacy status would require the implementation of alternative transfer mechanisms — such as Standard Contractual Clauses (SCCs) — to maintain lawful data transfers.
Connected medical devices that transmit health data — such as the FDA-cleared Beta Bionics Mint insulin patch pump, which continuously shares glucose and insulin-delivery data via cloud infrastructure — are subject to GDPR special-category health data obligations in the EU. Organisations must establish explicit consent or another valid legal basis under Article 9 GDPR, and must conduct a DPIA where large-scale health data processing is envisaged. For AI-enabled surgical systems, such as Medtronic's Cornerstone Robotics partnership, EU market entry requires compliance with both the EU Medical Device Regulation (MDR) conformity requirements and, where the AI component meets the high-risk threshold under Annex III of the EU AI Act, the applicable conformity assessment obligations.
On 8 September 2026, the NSA, CISA and FBI jointly issued Advisory AA26-251A, warning that several China-based AI developers — including DeepSeek, Alibaba and Moonshot AI — have been extracting billions of tokens of output from US frontier models such as Claude, GPT and Gemini through a technique called model distillation. Life-sciences organisations using these frontier models for drug discovery, trial design or regulatory writing should assess supplier risk and review contractual data-use restrictions. Inadvertent contribution to distillation pipelines may breach model provider terms of service, and where proprietary clinical data is involved, could trigger confidentiality obligations and pharmacovigilance GDPR requirements.
Healthcare organisations that suffer ransomware attacks — such as the Veradigm breach exposing 3.5 million patient records or the Nutex Health incident triggering a class-action lawsuit — face overlapping regulatory obligations. Under HIPAA, affected individuals must be notified within 60 days of discovery. Under GDPR Article 33, supervisory authorities must be notified within 72 hours of becoming aware of a breach. GDPR Article 28 also requires written data-processing agreements with third-party vendors that mandate adequate security measures and breach-notification timelines. Organisations should regularly test their incident-response procedures against both frameworks, particularly where third-party vendor API credentials are involved, as seen in the Veradigm case.
Deploying AI in high-stakes clinical settings — such as prior authorisation, triage, or autonomous treatment decisions — carries significant governance risks, as illustrated by failures in the US Medicare WISeR pilot, where one beneficiary request went unresolved for 83 days despite a 72-hour contractual requirement. The EU AI Act (Regulation 2024/1689) classifies AI systems used in healthcare as high-risk and mandates robust human-oversight mechanisms, transparency, and post-deployment monitoring. Additionally, autonomous clinical decision support that produces legal or similarly significant effects for patients falls under Article 22 GDPR constraints, and a Data Protection Impact Assessment (DPIA) under Article 35 GDPR is required before such processing commences.
The UK Information Commissioner's Office (ICO) will be redesignated as the 'Information Commission' on 30 September 2026, following governance reforms introduced by the Data (Use and Access) Act 2025. The single-commissioner model will be replaced by a collective board structure called the Information Commission Board, which will include seven newly appointed Non-Executive Members. While the supervisory and enforcement functions remain largely unchanged in the short term, organisations should review all correspondence, data-processing agreements, and privacy notices that reference the 'ICO' to ensure they remain accurate once the new name takes legal effect.
Connected medical devices that continuously transmit health data — such as Beta Bionics' newly FDA-cleared Mint insulin patch pump, which integrates with Abbott and Dexcom continuous glucose monitors — are subject to GDPR special-category health-data obligations when operated in the EU. Manufacturers and distributors must establish a lawful basis under Article 9 GDPR (such as explicit consent) for processing sensitive health data. Where large-scale processing of health data is envisaged, a Data Protection Impact Assessment (DPIA) is also required. Additionally, AI-driven components in surgical or diagnostic devices must satisfy both EU MDR conformity requirements and, where applicable, EU AI Act Annex III conformity assessment obligations.
The Veradigm breach (3.5 million patient records exposed via compromised third-party vendor API credentials) and the Nutex Health breach (patient, employee and financial data exfiltrated by the same ransomware group, The Gentlemen) highlight critical vendor risk management failures. Under HIPAA, affected individuals must be notified within 60 days of discovery. Under GDPR Article 33, supervisory authorities must be notified within 72 hours. Organisations with US and EU data exposure must also ensure their data-processing agreements under GDPR Article 28 mandate adequate security measures and breach-notification timelines from all third-party processors and vendors.
On 8 September 2026, the NSA, CISA and FBI jointly issued Advisory AA26-251A, warning that six China-based AI developers — including DeepSeek, Alibaba and Moonshot AI — have conducted campaigns to extract billions of tokens from US frontier models (such as Claude, GPT and Gemini) through model distillation. Life-sciences organisations using these frontier models for drug discovery, trial design or regulatory writing should assess supplier risk and review contractual data-use restrictions. Inadvertent contribution to distillation pipelines may breach model provider terms and, where proprietary clinical data is involved, could raise confidentiality and pharmacovigilance GDPR obligations.
Organisations developing autonomous AI systems for clinical decision support — such as those being funded through the US ARPA-H ADVOCATE programme — must conduct a Data Protection Impact Assessment (DPIA) before commencing high-risk automated processing of health data, as required under Article 35 of the GDPR. Additionally, autonomous clinical decision support that produces legal or similarly significant effects for patients falls within the constraints of Article 22 GDPR. Organisations operating across the US and EU should also map FDA TEMPO pilot commitments against EU AI Act conformity-assessment obligations to ensure dual-jurisdiction compliance.
Internal CMS records obtained through FOIA litigation revealed serious operational failures in the WISeR (Wasteful and Inappropriate Service Reduction) AI-driven prior-authorisation pilot. One beneficiary request went unresolved for 83 days despite a contractual 72-hour response requirement, and at least one vendor was found non-compliant with programme governance standards. These failures illustrate the risks of deploying algorithmic decision-making in high-stakes clinical settings without robust human-oversight mechanisms — a principle that the EU AI Act (Regulation 2024/1689) codifies as a mandatory requirement for high-risk AI systems used in healthcare.
The UK Information Commissioner's Office (ICO) will be redesignated as the 'Information Commission' from 30 September 2026, following governance reforms under the Data (Use and Access) Act 2025. The single-commissioner model is being replaced by a collective board structure — the Information Commission Board — with seven newly appointed Non-Executive Members. For life-sciences organisations processing health data or conducting clinical trials under UK GDPR, the enforcement posture remains largely unchanged in the short term. However, organisations should review correspondence, data-processing agreements and privacy notices that reference the 'ICO' to ensure accuracy once the new name takes legal effect.
Find out how iliomad can help your company.
Only visible in production
We'll get back to you as soon as possible.

Data transfer compliance in global clinical trials: a sponsor's guide
Understand data transfer compliance obligations for global clinical trials under GDPR, SCCs and local frameworks. A practical guide for sponsors from iliomad.

MR-001 CNIL: what clinical trial sponsors must know about French health data compliance
Understand MR-001 CNIL obligations for clinical trial sponsors in France, from Article 32 security requirements to breach notification and cross-border data transfers.

ICF Boilerplate and Open-Access Database Disclosures: What Clinical Trial Sponsors Must Know
Learn how US site ICF boilerplate on commercial products and open-access genetic databases affects sponsor data governance, Common Rule compliance and GDPR obligations.


