The challenge
Oxford-based Brainomix has gone from strength to strength over recent years. Following a funding round in 2021, it doubled its headcount in 2022 and established itself as the de-facto European leader in AI-powered brain imaging technology, with a presence in 30 countries. These operations require Brainomix to securely collect, store and share patient data between clinicians and hospitals, while complying with varying and complex data protection regulations. Compliance is business-critical for Brainomix, since the healthcare organisations it partners with have a heightened responsibility to safeguard patient and employee data.
Now, as the company was preparing for large-scale expansion, its data protection duties – and the pressure on its in-house regulatory team to handle these tasks – have grown manifold.
Brainomix was not only expanding its geographic footprint by launching operations in the US, it was also beginning to broaden its scientific remit to develop AI solutions for lung disease treatment. This involves leveraging data for new services and R&D purposes governed by strict and fast-evolving regulations such as HIPAA and GDPR in the EU and UK. It also requires Brainomix to create new frameworks – for example, where US employees would access UK data, the right inter-company agreements need to be in place. The new data protection regime would also need to be conscious of various US state-based differences that influence how specific hospitals can partner with technology providers.
To navigate the challenge of increasing data volumes, geographically varying regulatory complexities and huge risk for reputational damage, the company’s CFO, decided to enlist Norm’s data protection services.