Summary

This week's digest covers a period of acute pressure on healthcare data security, with ransomware now quantifiably linked to patient mortality and multiple large-scale breaches affecting millions of individuals across the US life sciences sector. Simultaneously, regulators on both sides of the Atlantic are tightening the rules on AI in clinical development, genetic data privacy is gaining statutory footing in US state law, and the EU-US Data Privacy Framework faces fresh legal scrutiny. Biotech and healthtech compliance teams face a convergence of cyber, regulatory and cross-border data transfer obligations that demands immediate attention.

Contact us

1. Healthcare Cybersecurity: Ransomware Is Now a Patient-Safety Crisis

Ransomware (a form of malicious software that encrypts an organisation's systems and demands payment for their release) is no longer solely an IT or data-protection matter: peer-reviewed evidence now frames it as a direct clinical risk with measurable mortality consequences. Four incidents this week reinforce the scale of exposure facing healthcare and life sciences organisations.

Ransomware Raises In-Hospital Mortality by Up to 38 Per Cent

A February 2026 study published in the American Economic Journal: Economic Policy found that in-hospital mortality for patients already admitted at the onset of a ransomware attack rises by 34 to 38 per cent. The Halcyon Ransomware Research Center estimates 42 to 67 preventable deaths over five years across the US healthcare sector. Black Hat and HIMSS have announced a joint Healthcare Cybersecurity Summit for 2026 in direct response, signalling that the security and health-IT communities are formally uniting to address the threat.

Read more

Amgen Reports Material Cyber Breach Involving Patient Data and R&D Materials

Amgen Inc. disclosed in July 2026 that hackers had gained unauthorised access to cloud storage systems operated by a third-party provider, exfiltrating protected health information alongside confidential business information, intellectual property and R&D materials. Amgen notified the US Securities and Exchange Commission (SEC), reflecting the growing intersection of cybersecurity, HIPAA clinical trials obligations and securities disclosure rules. The use of a third-party cloud host highlights the importance of robust data processing agreements and vendor due diligence for any sponsor holding participant data.

Read more

CareCloud Cyberattack Affects More Than 345,000 Patients

CareCloud Inc., a New Jersey-based provider of electronic health record software, identified unauthorised access to one of its EHR environments on 16 March 2026, with the threat actor claiming to have exfiltrated database records during a window of 10 to 16 March 2026. CareCloud confirmed the specific data types involved on 24 June 2026 and began issuing breach notifications thereafter. The timeline illustrates the persistent gap between initial intrusion and notification, an issue directly relevant to HIPAA clinical trials breach-response obligations and to any EU-facing clinical trial data protection programme.

Read more

MCBS Ransomware Attack Exposes 1.26 Million Individuals

MCBS, a healthcare billing and practice-management vendor, suffered a ransomware attack attributed to the PEAR group between 22 and 26 September 2025, with the threat actors claiming to have exfiltrated 3.3 terabytes of data. The breach was disclosed to the US Department of Health and Human Services in June 2026 after an investigation concluded on 28 May 2026, affecting 1,261,464 individuals across seven covered healthcare entities in Georgia. The nine-month gap between the attack and disclosure underscores the need for sponsors and CROs operating under HIPAA clinical trials frameworks to mandate contractual notification timelines with all billing and technology sub-processors.

Read more

Craneware Breach Puts 2,000 Hospitals at Risk

Craneware, a UK-based financial management software vendor serving US healthcare providers, announced that hackers had gained unauthorised access to its data environment and stolen a significant volume of files, including employee data and customer and partner records. Craneware's partnerships include Microsoft and the National Rural Health Association, and its customer base extends to approximately 2,000 US hospitals. The incident illustrates how a single vendor breach can cascade across an entire healthcare supply chain, reinforcing the case for comprehensive vendor GDPR clinical trials assessments and equivalent HIPAA due-diligence processes wherever UK or EU vendors process US patient data.

Read more

2. Genetic Data Privacy: US State Law and Enforcement Expand Rapidly

Genetic data, meaning biological information derived from an individual's DNA that can reveal predispositions to disease or hereditary conditions, is attracting dedicated statutory protection at US state level at an accelerating pace. Two developments this week illustrate both new obligations and the enforcement consequences of non-compliance.

South Dakota Genetic Data Privacy Law Takes Effect

South Dakota Attorney General Marty Jackley announced that Senate Bill 49, the state's new genetic data privacy statute, took effect on 1 July 2026 following legislative approval and the governor's signature. The law requires organisations handling genetic data to review privacy notices and governance practices, adding South Dakota to a growing list of US states with targeted genetic data protections. For life sciences sponsors and biobanks processing genetic data in clinical trials, this development compounds existing obligations under GDPR Article 9 (which classifies genetic data as a special category requiring explicit legal basis), and reinforces the relevance of maintaining defensible genetic data clinical trials governance frameworks across all jurisdictions of operation.

Read more

42-State Coalition Settles with 23andMe for $18 Million Over Genetic Data Breach

A coalition of 42 state attorneys general, including Arizona, reached an $18 million settlement with 23andMe over its 2023 data breach in which hackers obtained genetic ancestry information for nearly 7 million customers, approximately 143,000 of whom were Arizona residents, and attempted to sell the data on the dark web. The company initially denied the breach and subsequently drew criticism for attributing fault to affected consumers' password practices. The scale of the settlement and the breadth of the multi-state enforcement action signal that regulators view genetic data clinical trials and consumer genetic platforms as high-priority enforcement targets, and that inadequate breach response amplifies both reputational and financial liability.

Read more

3. AI in Clinical Development: A Binding Framework Takes Shape

Regulators and industry have moved decisively from exploratory guidance to enforceable expectations for AI in drug development. Sponsors and CROs should treat the FDA-EMA framework as the new baseline for clinical trial data protection programmes that incorporate AI tools.

FDA and EMA Establish Joint AI Framework for Drug Development

The FDA's January 2025 draft guidance introduced a seven-step, risk-based AI credibility framework for use in drug development, and by January 2026 both the FDA and the European Medicines Agency (EMA) had jointly issued "Guiding Principles for Good AI Practice in Drug Development." Major pharmaceutical sponsors including Novartis and Eli Lilly are understood to be adapting their internal frameworks in response. For clinical trial data protection teams, the framework carries implications for DPIA (Data Protection Impact Assessment, a structured process for identifying and mitigating privacy risks) obligations wherever AI tools process participant data, as well as for audit-trail requirements under ICH GCP data protection standards.

Read more

AI Scribes in Medical Training: Educational Asset or Cognitive Risk?

Medical schools and training programmes remain divided on whether AI scribes (automated documentation tools that transcribe and summarise clinical encounters in real time) should be permitted for trainees. Some institutions have restricted their use to protect the development of clinical reasoning, while others are integrating them with guardrails. Educators broadly agree that the evidence base for either position remains limited, and the absence of agreed standards has direct implications for data protection in clinical trials where trainee clinicians are site investigators handling participant records.

Read more

4. EU AI Regulation: Germany Operationalises the EU AI Act

Germany's new implementation law for the EU AI Act is now in force, marking the first major member-state operationalisation of the regulation and setting a precedent for how national authorities will structure oversight. Organisations developing or deploying AI in clinical research in Germany should review their compliance posture against the KI-MIG without delay.

Germany's KI-MIG Centralises AI Market Surveillance

The KI-Marktüberwachungs- und Innovationsförderungs-Gesetz (KI-MIG, Germany's national law implementing the EU AI Act's market surveillance and innovation-support provisions) entered into force on 29 July 2026. The law centralises AI oversight primarily in the Federal Network Agency (Bundesnetzagentur, known as BNetzA) and creates support tools including a service desk and regulatory sandbox to assist developers and deployers. For life sciences companies operating high-risk AI systems in Germany (for example, AI-assisted diagnostic or clinical decision-support tools), the KI-MIG establishes the concrete national authority against which conformity and incident-reporting obligations must now be discharged.

Read more

5. EU-US Data Transfers: The Data Privacy Framework Under Pressure

The EU-US Data Privacy Framework (DPF), the adequacy arrangement adopted in July 2023 that permits personal data transfers from the EU to certified US organisations without additional safeguards, is facing a formal reassessment triggered by a US Supreme Court ruling. Organisations relying on the DPF as their transfer mechanism for cross-border data transfer clinical trials should monitor this situation closely and review contingency plans.

EDPB Requests Commission Review of DPF Following US Supreme Court Ruling

The European Data Protection Board (EDPB), the independent body composed of EU member-state supervisory authorities responsible for ensuring consistent application of the GDPR, has formally written to the European Commission requesting that it "closely assess" how the US Supreme Court's Trump v. Slaughter decision on independent agency authority may affect the Federal Trade Commission's capacity to enforce DPF commitments against US companies. If the FTC's independence or enforcement powers are found to be materially diminished, the legal foundations of the DPF's adequacy determination could be called into question. Sponsors and CROs relying on the DPF for transatlantic transfers of clinical trial participant data should revisit whether standard contractual clauses (SCCs) or binding corporate rules provide a more resilient fallback, and should consider conducting or updating a transfer impact assessment for any affected data flows.

Read more

Contact us

FAQs

Our frequently questions

Why is ransomware now considered a patient safety risk in healthcare?

Ransomware can disrupt access to clinical systems, patient records, diagnostics and treatment workflows. A February 2026 study found that in hospital mortality among patients already admitted when a ransomware attack begins may increase by 34 to 38 per cent. This shows that healthcare cyberattacks can create direct clinical harm, not only financial loss or data protection risks.

What do recent healthcare data breaches reveal about third party vendor risk?

Incidents involving Amgen, CareCloud, MCBS and Craneware show that healthcare organisations can be exposed through cloud providers, billing companies, electronic health record platforms and other technology partners. Sponsors, CROs and healthcare providers should conduct robust vendor due diligence, include clear breach notification deadlines in contracts and regularly assess how third parties protect patient and clinical trial data.

How are US genetic data privacy requirements changing?

More US states are introducing laws that specifically regulate the collection, use and protection of genetic data. South Dakota’s genetic data privacy law took effect on 1 July 2026, requiring organisations to review their privacy notices and governance practices. Life sciences companies and biobanks must therefore consider state privacy laws alongside GDPR requirements and other applicable health data rules.

What does the 23andMe settlement mean for organisations processing genetic data?

The $18 million settlement involving 42 state attorneys general demonstrates that genetic data breaches can result in significant regulatory, financial and reputational consequences. The case also shows that a poor breach response, including delayed acknowledgement or attempts to shift responsibility to users, may increase regulatory scrutiny and damage public trust.

What should life sciences organisations know about the FDA and EMA AI framework?

The FDA and EMA have established joint principles for the responsible use of artificial intelligence in drug development. Organisations using AI in clinical research should apply a risk based approach, document how systems are validated and maintain appropriate audit trails. They should also assess whether a Data Protection Impact Assessment is required when AI tools process clinical trial participant data.

How could current EU regulatory developments affect clinical trial data and AI systems?

Germany’s KI MIG law establishes the Federal Network Agency as a central authority for AI market surveillance and creates support services such as a regulatory sandbox. At the same time, the European Data Protection Board has asked the European Commission to review the EU US Data Privacy Framework following a US Supreme Court ruling. Sponsors and CROs should review their AI compliance responsibilities in Germany and maintain alternative safeguards, such as standard contractual clauses, for transatlantic clinical trial data transfers.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
Abstract graphic showing a digital EU flag alongside a US state outline representing new AI regulation milestones in Europe and Rhode Island in July 2026
July 29, 2026
Healthtech
Regulations & Guidelines
DPIA
Biotech & Healthtech
Health Data Warehouse

EU Digital Omnibus Simplifies AI Act Obligations; Rhode Island Enacts AI Healthcare Laws

Regulation (EU) 2026/1744 streamlines EU AI Act compliance, while Rhode Island enacts three AI healthcare laws. Key updates for biotech and healthtech teams.

Diagram illustrating the EDPB three-criteria anonymisation test applied to clinical trial datasets under GDPR, with icons for record isolation, linkage and inference
July 13, 2026
DPIA
AI
Testimonial
EU Privacy Law
Regulations & Guidelines

EDPB Anonymisation Guidelines 2026 and Clinical Trial Data: What Life Sciences Organisations Must Know

EDPB Guidelines 02/2026 on anonymisation set new standards for clinical trial data. Learn the three-criteria test, enforcement lessons and compliance steps. iliomad.

Abstract digital network connecting a hospital, a regulatory building and a courtroom, representing AI governance, health data privacy and transatlantic data transfer risks in 2026
July 8, 2026
Healthtech
Regulations & Guidelines
DPIA
Regulation
LLMS

AI Triage, Biopharma Workbenches and Crumbling Data Bridges: iliomad Weekly Digest

NHS AI triage, Anthropic Claude Science, medical AI privacy risks, MHRA GxP guidance, EDPS ADM checklist and the EU-US data transfer threat explained.