Novo Nordisk disclosed unauthorised access affecting certain internal IT systems, exposing a limited amount of information relating to participants in some clinical trials. Reported fields include patient identifiers, trial participation details, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors.
“Remain Vigilant” Is The Wrong Instruction For This Data
The standard advice after a breach assumes a person can act — watch for fraudulent accounts, check statements, freeze a credit file. The corpus filed at 25-0828 that credit monitoring addresses new credit opened in your name and nothing else.
Biomarkers and immunogenicity data are not fields anybody can monitor. There is no equivalent of a credit freeze for a leaked diagnosis, per 25-1010, and there is no equivalent at all for a laboratory value.
This desk records the instruction without criticising the company for it. There is nothing else to say to an affected participant, which is the finding.
Trial Participation Is Itself The Disclosure
The corpus argued at 25-0603 that a luxury retailer’s customer list is sensitive because membership of the list is the fact, not the fields on it.
The same applies here with more force. Knowing that a named person participated in a trial for a specific condition reveals that they have or were screened for that condition — regardless of what any biomarker says.
And The Corpus Should Note What "Limited" Is Doing
The disclosure describes a limited amount of information. That may be accurate and this desk cannot verify it.
The reachable-taken-published distinction at 25-0717 applies: "limited" describes volume and says nothing about sensitivity, and the field list quoted above is not limited in that second sense. Graded medium.
Compiled from public reporting of company disclosure, listed below. Affected volume is not established. Corrections: corrections@forensicpost.com.