Novo Nordisk has identified an IT security incident affecting some internal systems and clinical trial data. Find out what this means for participants and how the company is responding.

In a recent development, Novo Nordisk A/S has uncovered an IT security incident that involved unauthorized access to certain internal systems. This breach has raised concerns about the protection of personal data stored within these systems.
The company has taken this matter seriously, emphasizing its commitment to security and data protection.
They have released a statement to inform clinical trial participants about the incident and its potential implications.
Nature of the Incident
The incident primarily affected a limited amount of information related to patients participating in some of Novo Nordisk’s clinical trials.
It is important to note that the exposed data is not directly linked to any patients by name or other direct identifiers. The information that could identify patients by name or other personal details was not compromised.
Novo Nordisk has clarified that the incident does not enable any third party to identify participants in their clinical trials.
The data that was accessed is pseudonymizedmeaning that knowledge of patient identity would require access to further information, which was not part of the incident.
Categories of Affected Personal Data
The categories of personal data that were potentially exposed include:
- Patient ID (a random alphanumeric string) and information on trial participation
- Sex
- Year of birth
- Biomarkers
- Health/immunogenicity data
- Lifestyle factorssuch as smoking, alcohol use, and BMI
It is important to note that the exposure of data does not necessarily include all the categories listed above.
Response and Security Measures
Following the incident, Novo Nordisk launched an investigation with the assistance of cybersecurity experts. The company has taken multiple security measures to address the situation, including temporarily taking certain internal IT systems offline to protect their environment.
Novo Nordisk is working to bring the affected systems back online in a controlled and safe manner. However, they acknowledge that this process takes time. Despite this, the company assures that their core business operations are not impacted and remain up and running.
The company emphasizes that protecting the security and integrity of their systems, including the personal data of their employees, customers, patients, and stakeholders, remains their highest priority.
Novo Nordisk recommends that patients remain vigilant and report any unusual activity that could be linked to the incident.
