Privacy AI
Regulatory

Health data compliance, handled.

Tell us what you need. We'll tell you what it takes and how long, before you commit.

Contact us

Summary

This week's digest highlights CNIL's guidance on DPO conflicts of interest and the DOJ's new bulk data rule impacting life sciences. It also addresses recent healthcare cybersecurity incidents, including a significant data breach involving McKesson, and the EU's AI traceability efforts, crucial for compliance under GDPR and the new AI Act.

Contact us

1. Data Protection Governance and DPO Compliance

CNIL Guidance on DPO Conflicts of Interest

The Commission Nationale de l'Informatique et des Libertés (CNIL, France's national data protection authority) has published practical guidance on identifying and managing conflicts of interest affecting the Data Protection Officer (DPO) role, that is, the individual mandated under Article 37 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) to oversee an organisation's data protection compliance. The CNIL confirms that whilst the GDPR permits DPOs to hold additional responsibilities within an organisation, any such role that involves determining the purposes or means of personal data processing will create a structural conflict. Organisations, including pharmaceutical sponsors and contract research organisations, should map all secondary roles held by their DPO and formalise a remediation process where a conflict is identified.

(Read more)

CNIL Updates Genmod Traceability Tool for Open-Source AI Models

The CNIL has released an updated version of Genmod, a demonstrator tool first published in November 2025 that constructs genealogical maps of open-source artificial intelligence (AI) models by analysing public metadata from repositories such as HuggingFace. The tool identifies both the upstream source models from which a given model derives and the downstream models built upon it, enabling DPOs and regulators to trace how personal data may have propagated through successive training cycles. For life sciences organisations deploying or fine-tuning open-source models on clinical or patient-level datasets, Genmod offers a practical starting point for the traceability obligations that arise under both the GDPR and the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, the EU AI Act).

(Read more)

2. Cross-Border Data Transfers and US Regulatory Developments

DOJ Bulk Sensitive Personal Data Rule: Obligations for Life Sciences

Morgan Lewis has published analysis of the US Department of Justice (DOJ) Bulk Sensitive Personal Data Rule, a federal measure that restricts the transfer of large volumes of categories such as genomic data, biometric data and health records to certain foreign countries of concern. Life sciences companies conducting multinational clinical trials, sharing pharmacovigilance data across borders, or licensing datasets to overseas partners must now assess whether transactions fall within the rule's thresholds and, if so, implement contractual and operational controls before proceeding. The rule operates alongside, rather than in place of, existing GDPR transfer mechanisms such as Standard Contractual Clauses (SCCs), meaning compliance teams must satisfy obligations under both regimes simultaneously.

(Read more)

BINSA Bill and the 'Eurowashing' Risk in Clinical Trials

The Biotech Investment National Security Act (BINSA), introduced in June 2026 as a companion measure to the Comprehensive Outbound Investment National Security Act (COINS Act), proposes federal oversight of pharmaceutical development and clinical research involving entities linked to China. Critics cited in STAT News warn that the draft legislation contains a geographic loophole: sponsors could route trial activities through European subsidiaries or European clinical sites to circumvent restrictions, a practice being termed 'Eurowashing'. For sponsors and contract research organisations operating multinational programmes, the bill represents a further layer of geopolitical risk that must be considered during protocol design and site selection, particularly where data sovereignty obligations under the GDPR already constrain transfer options.

(Read more)

3. Healthcare and Life Sciences Cybersecurity Incidents

McKesson Confirms Cyber Incident Following ShinyHunters Claim

McKesson Corporation, a major US pharmaceutical distribution and healthcare technology company, has confirmed a cyber incident after the threat actor group ShinyHunters publicly claimed to have exfiltrated patient data from its systems. ShinyHunters is a prolific extortion group responsible for several large-scale breaches in recent years; its claim against McKesson follows a similar pattern of public disclosure designed to pressurise victims into ransom payment. Healthcare organisations processing personal health information are reminded that US HIPAA (Health Insurance Portability and Accountability Act) breach notification obligations may be triggered irrespective of whether ransom demands are met.

(Read more)

ShinyHunters Releases 7.1 Million Baxter International Records

ShinyHunters also claimed responsibility for an intrusion into Baxter International's third-party Salesforce environment, posting approximately 7.1 million records on its dark web leak site on 19 August 2026 after Baxter reportedly declined to pay a ransom demanded by 17 August 2026. The incident illustrates the systemic risk that arises when sensitive personal data is processed within third-party cloud platforms, and underlines the importance of robust data processing agreements and vendor due diligence, both of which are required under GDPR Article 28.

(Read more)

Boston Scientific Cyberattack Disrupts Global Device Shipments

Boston Scientific, one of the world's largest medical device manufacturers, disclosed a cybersecurity incident discovered on 25 August 2026 via a filing with the US Securities and Exchange Commission (SEC). The network outage disrupted global order processing and the shipment of cardiac and other medical devices to hospitals, with recovery expected to take several weeks. The dual obligation of SEC disclosure alongside potential GDPR or NIS2 (Directive (EU) 2022/2555, the Network and Information Security Directive) notification requirements illustrates the multi-jurisdictional reporting burden facing global medical technology companies.

(Read more)

Rhysida Group Demands 30 Bitcoin from Berlin State Administration

German authorities confirmed that the Rhysida ransomware group breached Berlin's state administrative network and is demanding a ransom of 30 bitcoin, threatening to publish exfiltrated data if payment is not received. Berlin officials have declined to detail the categories of data accessed, citing an ongoing investigation. Under the GDPR and Germany's implementing legislation, public authorities are subject to the same breach notification requirements as private organisations, including the obligation to notify the relevant supervisory authority within 72 hours of becoming aware of a breach likely to result in risk to individuals.

(Read more)

PEAR Ransomware Group Claims South Plains Rural Health Services Breach

The PEAR ransomware group claims to have exfiltrated approximately 1.4 terabytes of data from South Plains Rural Health Services (SPRHS), including patient medical records and employee information. SPRHS reportedly received notice of the claimed exfiltration around 17 June 2026; under the HIPAA/HITECH (Health Information Technology for Economic and Clinical Health Act) 60-day breach notification rule, affected individuals would have been due notification by approximately 17 August 2026. SPRHS has not publicly confirmed the incident, which itself may attract regulatory scrutiny regarding the timeliness of its response.

(Read more)

DireWolf Ransomware Claims National Kidney Registry Breach

The DireWolf ransomware group, active since May 2025 and reportedly linked to over 100 prior victims, claims to have compromised the National Kidney Registry via a double-extortion attack combining encryption with data exfiltration of approximately 253 gigabytes across eight datasets, totalling roughly 180,000 documents. The sensitivity of organ-transplant coordination data, which may include donor and recipient medical histories and matching information, makes this incident particularly concerning from a patient safety and privacy perspective.

(Read more)

UK HIV Charity George House Trust Caught in Beacon CRM Supply-Chain Breach

George House Trust, an HIV support charity based in Manchester, disclosed that hackers accessed and downloaded sensitive health data belonging to its service users as part of a wider supply-chain compromise affecting Beacon, a customer relationship management (CRM) platform used extensively across the UK charity sector. Estimates suggest up to 1,000 to 1,500 charities may be affected in total. The incident is a stark reminder that UK GDPR (the retained version of Regulation (EU) 2016/679 as it forms part of UK domestic law) requires organisations to ensure that processors engaged under Article 28-equivalent contracts maintain security standards commensurate with the sensitivity of the data processed.

(Read more)

Doctor's Phone Call During Patient Examination Causes Data Breach in Guernsey

Guernsey's Office of the Data Protection Authority (ODPA) has highlighted an incident in which a doctor took a personal phone call during a patient examination, inadvertently allowing identifying details and sensitive health information about a third party to be overheard. The ODPA published the case as part of its annual reporting, noting an overall fall in serious data breaches in Guernsey. The incident serves as a low-technology reminder that data protection failures are as likely to arise from procedural lapses as from cyber attacks, and that staff training remains a foundational control.

(Read more)

4. Enforcement, Fines and Regulatory Accountability

Uber Fined Nearly €825 Million for Algorithmic Driver Deactivations

On 24 August 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) issued a fine of €824,990,000 against Uber B.V. and Uber Technologies Inc., coordinated with the CNIL under the GDPR's one-stop-shop cross-border cooperation mechanism. The sanction relates to Uber's use of fully automated decision-making to deactivate drivers without meaningful human review, in breach of GDPR Article 22, which grants data subjects the right not to be subject to solely automated decisions that produce significant effects. For any organisation operating algorithmic management systems, including those using AI-driven patient triage or clinical decision-support tools, the Uber decision underlines the importance of implementing human oversight and conducting a Data Protection Impact Assessment (DPIA, the structured risk assessment required under GDPR Article 35) before deploying such systems.

(Read more)

Star Health Insurance: ₹3.39-Crore Fine and 13,000 Complaints After 2024 Breach

A retrospective review of Star Health Insurance's 2024 data breach, in which sensitive medical and personal records of policyholders were exposed, documents a regulatory penalty of ₹3.39 crore imposed by India's Insurance Regulatory and Development Authority (IRDAI) for inadequate cyber protections. The breach also generated approximately 13,000 complaints to the insurance ombudsman, reportedly reflecting a wider pattern of claim denials. The case illustrates that data breaches in health insurance can carry compounding regulatory and reputational consequences that extend well beyond the immediate privacy enforcement action.

(Read more)

Saskatchewan Commissioner Recommends Ongoing Credit Monitoring After Autism Services Breach

Saskatchewan's Information and Privacy Commissioner, Grace Hession David, issued a non-binding recommendation that Autism Services of Saskatoon should regularly remind the 2,168 individuals affected by a 2026 data breach to remain vigilant against fraud and identity theft, including monitoring credit reports. The underlying breach exposed a combination of medical records, social insurance numbers and other sensitive identifiers. The recommendation reflects an emerging regulatory expectation in Canada that breach remediation should extend beyond initial notification to include sustained risk-reduction support for affected individuals.

(Read more)

5. Life Sciences Pipeline, Digital Health and AI Transparency

FDA Approves Mimrylo for Polycythemia Vera

The US Food and Drug Administration (FDA) has granted approval to Mimrylo (rusfertide), a weekly self-administered injection developed by Protagonist Therapeutics and to be commercialised by Takeda, for the treatment of polycythemia vera, a slow-growing blood cancer characterised by excessive red blood cell production that elevates the risk of heart attack, stroke and blood clots. The approval is notable as a rare-disease milestone for a condition with historically limited treatment options, and it will require robust pharmacovigilance and post-marketing safety reporting systems to be maintained in accordance with FDA requirements and, where the product reaches EU markets, EudraVigilance obligations.

(Read more)

AusperBio Raises $120 Million Series C for Hepatitis B Phase III Plans

AusperBio Therapeutics, a developer of targeted oligonucleotide therapeutics for chronic hepatitis B, has closed a $120 million Series C financing round led by an undisclosed strategic investor, with participation from RA Capital Management, HanKang Capital, Qiming Venture Partners and CDH Investments, bringing total capital raised since 2024 to $360 million. The funding is intended to advance the programme towards Phase III clinical trials. Sponsors planning Phase III studies across multiple jurisdictions should ensure that data protection obligations under the EU Clinical Trials Regulation (CTR, Regulation (EU) No 536/2014) and relevant national laws are addressed in protocol design and informed consent documentation.

(Read more)

Pew Survey: 74% of Americans Want AI Disclosure from Clinicians

A Pew Research Center survey of 3,488 American adults conducted between 22 and 28 June 2026 found that approximately 74% of respondents want their physician to disclose when AI is involved in their care, with roughly 80% specifically requesting notification when AI is used to analyse medical scans, generate diagnoses or interpret laboratory results. Despite this demand for transparency, the survey indicates that awareness of actual AI use in clinical settings remains low among patients. The findings have direct relevance for healthtech developers and hospital procurement teams, as they signal that patient-facing AI transparency disclosures are rapidly becoming an expectation that regulators, including those enforcing the EU AI Act, are likely to formalise.

(Read more)

Sword Health to Acquire Headspace in Digital Mental Health Consolidation

Sword Health, a virtual physical-therapy and digital health company valued above $4 billion and backed by approximately $493 million in total funding, has disclosed plans to acquire Headspace, the mental health and meditation platform owned by OrangeDot, through a filing with the Massachusetts Health Policy Commission. The transaction is expected to become effective on 14 September 2026. Combinations of this nature, which bring together physical and mental health datasets under a single controller, should be subject to a DPIA to assess the risks arising from the enlarged processing scope, particularly where sensitive health data may be used to inform AI-driven recommendations.

(Read more)

Turkish Competition Authority Investigates Teva Over Patent Practices

Turkey's Rekabet Kurumu (Competition Board) has launched a formal investigation into Teva Pharmaceutical Industries for practices allegedly designed to obstruct generic competitors from entering the market, including manipulation of patent filings and the communication of misleading statements to health authorities concerning the safety and effectiveness of competing medicines. The investigation is broadly analogous to 'pay-for-delay' and misrepresentation cases pursued in the EU under competition law, and it serves as a reminder that regulatory risk for originator pharmaceutical companies extends well beyond data protection into market conduct.

(Read more)

If any of this week's developments affect your organisation's compliance programme, the iliomad team is available to assist with DPO conflict-of-interest reviews, DPIA preparation, cross-border data transfer assessments and clinical trial data protection strategies. Contact us to arrange a consultation.

Contact us

FAQs

Our frequently questions

What is a DPO conflict of interest under GDPR, and how should organisations manage it?

Under GDPR Article 37, a Data Protection Officer (DPO) must be able to perform their duties independently. The CNIL (France's data protection authority) has confirmed that whilst DPOs may hold additional roles within an organisation, any role that involves determining the purposes or means of personal data processing creates a structural conflict of interest. Pharmaceutical sponsors and contract research organisations should map all secondary roles held by their DPO and formalise a remediation process wherever a conflict is identified.

What is the DOJ Bulk Sensitive Personal Data Rule and how does it affect life sciences companies?

The US Department of Justice (DOJ) Bulk Sensitive Personal Data Rule restricts the transfer of large volumes of sensitive data categories — including genomic data, biometric data and health records — to certain foreign countries of concern. Life sciences companies conducting multinational clinical trials, sharing pharmacovigilance data across borders, or licensing datasets to overseas partners must assess whether their transactions fall within the rule's thresholds and implement appropriate contractual and operational controls. Importantly, the rule operates alongside existing GDPR transfer mechanisms such as Standard Contractual Clauses (SCCs), meaning compliance teams must satisfy obligations under both regimes simultaneously.

What are the key cybersecurity and breach notification obligations for healthcare organisations under HIPAA and GDPR?

Healthcare organisations face breach notification obligations under multiple frameworks simultaneously. Under US HIPAA/HITECH, organisations must notify affected individuals within 60 days of discovering a breach involving protected health information, regardless of whether a ransom demand is met. Under the GDPR (and UK GDPR), organisations, including public authorities, must notify the relevant supervisory authority within 72 hours of becoming aware of a breach likely to result in risk to individuals. Recent incidents involving McKesson, Baxter International, the National Kidney Registry and others highlight that ransomware attacks on healthcare entities trigger these obligations and can carry significant regulatory and reputational consequences.

What does Uber's €825 million GDPR fine mean for organisations using automated decision-making systems?

The Dutch Data Protection Authority fined Uber nearly €825 million for using fully automated decision-making to deactivate drivers without meaningful human review, in breach of GDPR Article 22. This provision grants data subjects the right not to be subject to solely automated decisions that produce significant legal or similarly significant effects. For any organisation deploying algorithmic management, AI-driven patient triage, or clinical decision-support tools, the Uber ruling underlines two critical requirements: (1) implementing genuine human oversight into automated processes, and (2) conducting a Data Protection Impact Assessment (DPIA) under GDPR Article 35 before deploying such systems.

Do patients want clinicians to disclose when AI is used in their care, and what are the regulatory implications?

Yes, a Pew Research Center survey of 3,488 American adults (June 2026) found that approximately 74% of respondents want their physician to disclose when AI is involved in their care, rising to around 80% for AI used to analyse medical scans, generate diagnoses, or interpret laboratory results. Despite this demand, patient awareness of actual AI use in clinical settings remains low. For healthtech developers and hospital procurement teams, these findings signal that AI transparency disclosures are rapidly becoming a patient expectation. Regulators enforcing the EU AI Act (Regulation (EU) 2024/1689) are expected to formalise such disclosure requirements, making proactive transparency a strategic compliance priority.

What GDPR obligations arise when two digital health companies merge and combine their datasets?

When digital health companies merge — such as the planned acquisition of Headspace by Sword Health — the combination of distinct health datasets (e.g. physical therapy records and mental health data) under a single data controller significantly expands the scope of processing. Under GDPR Article 35, this enlarged processing scope, particularly where sensitive health data may be used to power AI-driven recommendations, requires a Data Protection Impact Assessment (DPIA) to identify and mitigate the new privacy risks. Organisations should conduct the DPIA prior to completing the transaction and before any data integration takes place, and update their records of processing activities accordingly.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
Illustration of the CNIL MR-001 framework applied to a clinical trial data compliance workflow in France, showing patient data flow and security controls
September 7, 2026
GDPR
Regulation
Guideline
Regulations & Guidelines

MR-001 CNIL: what clinical trial sponsors must know about French health data compliance

Understand MR-001 CNIL obligations for clinical trial sponsors in France, from Article 32 security requirements to breach notification and cross-border data transfers.

A clinical trial coordinator reviewing an informed consent form alongside a data governance checklist, representing ICF boilerplate review and open-access database disclosure compliance
September 4, 2026
Guideline
EU Privacy Law
Regulations & Guidelines
Clinical Trials
United-Kingdom

ICF Boilerplate and Open-Access Database Disclosures: What Clinical Trial Sponsors Must Know

Learn how US site ICF boilerplate on commercial products and open-access genetic databases affects sponsor data governance, Common Rule compliance and GDPR obligations.

Diagram showing GDPR data flow between a clinical trial sponsor, a CRO acting as data processor, and cloud infrastructure, with a data breach alert icon overlaid
August 17, 2026
Regulations & Guidelines
GDPR
Clinical Trials
Regulation
Data Breach & Cybersecurity

CRO data protection: managing third-party and cloud infrastructure risk in clinical research

Understand CRO data protection obligations under GDPR and EU CTR 536/2014. Learn how to manage third-party vendor risk, cloud infrastructure breaches and DPA requirements.