Inotiv at 25-0819b in August, BioPharma Services at 25-1127c in November. Both are contract research organisations, and both hold work performed for other companies.
The Rule At 25-1219b Applies Again
That file stated it plainly: the organisation holding the largest population in any sector is generally the one with no relationship to any of them.
A pharmaceutical company runs some trials itself and outsources many. A CRO holds studies for dozens of sponsors, with participant records, protocols, results and timing — assembled because outsourcing clinical operations is the industry standard, not an exception.
The participant consented to a trial run by a named sponsor. They will not know the CRO’s name and did not select it. It is the structure at 25-0801 and 25-1214b with study data attached.
And The Material Is Commercially Explosive
Unpublished trial results are market-moving information about listed companies. A CRO holds them for competitors simultaneously.
This corpus filed at 25-1124b that corporate data with no data subject triggers no notification anywhere, and recorded the same category for litigation strategy at 25-0916 and manufacturing process data at 25-1204.
Clinical results are the highest-value instance of it, and there is no register that would record their exposure.
What Would Help, And Does Not Exist
Sponsor-side visibility into research partners’ security, of the kind DORA at 25-0117 established for critical ICT providers in EU financial services.
Pharmaceutical regulation is exhaustive on data integrity, trial conduct and record retention. It is not, as far as this desk can establish, comparably concerned with whether a CRO’s network is defensible. Graded medium: this is a structural reading of two incidents.
It reasons about sector structure from the incidents recorded in this database. Sources support the underlying cases. Corrections: corrections@forensicpost.com.
- Major drug research company confirms cyberattack compromised employee and partner dataCybersecurity Dive
- BioPharma Services data breachBreachsense