Novo Nordisk discloses clinical trial data breach, attackers copy pseudonymised patient health data and healthcare professional contact details
Clinical trial participants for Novo Nordisk $NVO are told to stay vigilant: the Ozempic maker says attackers copied pseudonymised patient data, including biomarkers, health details, year of birth and lifestyle factors. Doctors' names and contact details were also exposed.
People who took part in some of Novo Nordisk's clinical trials are being told to stay alert after the Danish drugmaker disclosed a cybersecurity breach. Novo Nordisk $NVO, the company behind the weight-loss and diabetes treatments Ozempic and Wegovy, says attackers copied information from its internal IT systems, including data tied to certain trial participants. The exposed records, according to the company, include patient ID numbers, details about trial participation, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors such as smoking status, alcohol use and body mass index. Novo Nordisk says the patient data was pseudonymised and that no directly identifying details, such as names, were taken. Separately, the breach also exposed names, registration numbers, email addresses, phone numbers and office locations belonging to healthcare professionals. The company says it has launched an investigation with external cybersecurity experts, contacted the relevant authorities, and temporarily took some internal systems offline to contain the incident while it restores services. Even without names attached, the combination of detailed health markers and trial information raises real privacy concerns. Pseudonymised does not mean anonymous, and regulators under the GDPR treat such health data as sensitive. For trial participants, the practical advice is the standard guidance after any breach involving personal data: be cautious with unexpected emails or calls referencing medical information, and verify any contact that claims to come from the company or a clinic.