Pharma Runs on Three Pillars – and Medical Affairs Shares the Most Sensitive Data of All
Life Science    24 views

Pharma Runs on Three Pillars – and Medical Affairs Shares the Most Sensitive Data of All

Published on August 5, 2026

The pharma operating model runs on three pillars: R&D discovers and develops the science, medical affairs translates that science into evidence, and Commercial brings the product to market. (In this framing, Regulatory Affairs sits inside R&D – it owns the IND/NDA/BLA dossier and shepherds it to the agency.) Every one of those functions does the same thing all day long: it shares regulated data with people outside the organization. And of the three, medical affairs shares with the widest, least controllable audience – key opinion leaders, advisory boards, investigators, payers, and medical information requesters.

That’s exactly the data attackers want most. Healthcare has been the costliest industry to breach for fourteen consecutive years, at an average of $7.42 million per incident, and U.S. breach costs hit a record $10.22 million in 2025 – up 9.2% year over year (IBM, Cost of a Data Breach Report 2025). Thirty percent of breaches now involve a third party, double the prior year (Verizon, DBIR 2025). It takes 279 days, on average, to spot and contain a healthcare breach.

Here’s the uncomfortable part: most of this data still moves by email attachment and consumer file-sharing links. Once it leaves, there is no revoke, no expiry, no audit – and no idea who forwarded it where.

What Medical Affairs Actually Shares – and With Whom

Medical affairs sits between the lab and the market, which means its daily work is external by design. A typical medical affairs strategy touches all of these flows:

Medical science liaisons (MSLs) share publication reprints, congress data, and scientific decks with KOLs and treating physicians – often from a laptop in a hospital hallway. Effective KOL engagement depends on getting the right data to the right expert quickly, which is precisely why it so often bypasses controls.

Advisory boards require pre-read distribution to a dozen or more external experts: draft data, unpublished analyses, strategic questions the company would never want a competitor to see. Advisory board document distribution is a textbook case of regulated content leaving the tenant.

Medical information teams respond to unsolicited HCP requests with standard response letters and, sometimes, unpublished data on off-label use – content that is both commercially sensitive and subject to strict compliance boundaries.

Publications, RWE/HEOR, and medical education teams exchange manuscripts with external authors, real-world evidence packages with payers, and grant documentation with institutions.

Investigator-initiated studies (IIS) move protocols, safety information, and study data between the sponsor and independent investigators for years at a stretch.

Every flow above involves protected health information, unpublished clinical data, or pre-approval scientific exchange. Every flow is an audit question waiting to be asked – by a regulator, by legal, or by an incident response team.

The Three Ways Medical Affairs Moves Regulated Data

Across all of those workflows, there are really only three transport mechanisms in use today – and only one of them is governed.

Email attachments. Gone the moment you hit send. No revoke, no expiry, no audit trail, no watermark. A pre-read forwarded from a KOL’s academic inbox to a personal one is invisible to you forever.

Consumer file-sharing and shared drives. Anonymous links, link sprawl, and shadow copies you can’t see, let alone control. “Anyone with the link” is not an access policy; it’s the absence of one.

A governed data room. Named-user permissions, dynamic watermarking, time-based expiry, instant revoke, and a complete audit trail – for internal teams and external partners alike. This is the model virtual data rooms proved in M&A, applied to the continuous, always-on sharing that defines medical affairs.

The catch with traditional standalone VDRs is that they were priced and designed for episodic deals, not for a function that shares documents every single day across dozens of concurrent relationships. Moving medical affairs content into a third-party VDR also means moving it out of the Microsoft 365 tenant where your sensitivity labels, DLP policies, and retention rules already live.

A Governed Foundation Inside Microsoft 365

Govern 365 takes the other path: it builds the data room inside your own Microsoft 365 tenant, as the governed foundation under all three pillars. For medical affairs specifically, that looks like:

  • A room per relationship. Each advisory board, each KOL engagement, each IIS gets its own governed workspace – isolated from every other, so an advisor for one program never glimpses another’s documents.
  • Granular, need-to-know permissions with no guest sprawl. External experts see exactly the documents intended for them, nothing else in your tenant.
  • Dynamic watermarking on view and download, so every page carries the recipient’s identity – a quiet but powerful deterrent for pre-publication data.
  • Time-based expiry and instant revoke. When the advisory board ends or the contract lapses, access ends with it – including for copies already downloaded when paired with protection policies.
  • A complete, exportable audit trail built on Microsoft Purview: who viewed what, when, from where. When compliance asks, you answer in minutes.
  • Your compliance stack still applies. Because content never leaves Microsoft 365, Purview sensitivity labels, DLP, retention, and Entra conditional access keep working. This is also what makes genuinely HIPAA compliant file sharing achievable without a parallel system.

The same tenant-native model already anchors Govern 365’s life sciences data room for clinical and partnering workflows and the regulatory submission data room used by regulatory affairs teams to assemble and share dossier content upstream of eCTD. Medical affairs is the third leg of the same stool – one governed foundation under R&D, Medical Affairs, and Commercial alike.

What This Means for Your Medical Affairs Strategy

If you lead a medical affairs organization, the question is not whether your teams share regulated data externally – they do, constantly, and that is the job. The question is whether your medical affairs strategy treats sharing as a governed capability or an ungoverned habit.

A practical way to start: pick your next advisory board. Instead of emailing the pre-read, stand up a governed room, invite the advisors as named users, watermark the documents, set expiry for the day after the meeting, and export the audit log when it closes. Compare that record to what you could produce for your last board. That delta is your current risk.

Most medical affairs software addresses content creation and approval – the MLR workflow. The gap is in distribution: the moment approved content leaves for the outside world. That is the layer a governed data room fills, and because Govern 365 runs on the Microsoft 365 you already own, it typically deploys in weeks at a flat rate – not the per-page pricing of deal-era VDRs.

Ask one question of your organization this week: can you prove who saw it, and can you pull it back? If the answer is no, the foundation under your three pillars has a crack in it – and medical affairs is standing on the widest span.

Frequently Asked Questions

What is medical affairs in pharma?

Medical affairs is the function that translates clinical science into evidence and communicates it to the medical community. It typically includes medical science liaisons (MSLs), medical information, publications and medical communications, RWE/HEOR, medical education and grants, and investigator-initiated studies. In the three-pillar model of pharma, medical affairs stands as a peer of R&D and Commercial.

Why is medical affairs data sharing considered high-risk?

Medical affairs routinely sends unpublished clinical data, pre-approval scientific content, and patient-level information to external parties – KOLs, advisory boards, payers, and investigators. Healthcare breaches cost an average of $7.42M, 30% of breaches now involve a third party, and email attachments offer no revoke, expiry, or audit once sent.

What is a medical affairs data room?

A medical affairs data room is a governed workspace for sharing regulated content with external medical stakeholders. It applies named-user permissions, dynamic watermarking, time-based expiry, and full audit logging to workflows like advisory board pre-reads, KOL engagement, and IIS document exchange – controls email and file-share links can’t provide.

How does Govern 365 differ from standalone medical affairs software?

Most medical affairs software manages content creation and MLR approval. Govern 365 governs the distribution layer – the moment content leaves for external audiences – and does it inside your own Microsoft 365 tenant, so Purview, Entra, and your existing compliance policies continue to apply. Standalone VDRs move content out of your tenant and price by the page.

Is sharing through Govern 365 HIPAA compliant?

Govern 365 supports HIPAA compliant file sharing by keeping PHI inside your Microsoft 365 tenant under your BAA with Microsoft, with need-to-know permissions, watermarking, expiry, revoke, and a complete exportable audit trail. See our detailed guide to HIPAA-compliant file sharing for the 2026 Security Rule context.

How should advisory board documents be distributed securely?

Best practice is a dedicated, time-boxed room per advisory board: invite advisors as named users, watermark every document, set access to expire after the meeting, and export the audit log at close-out. This produces a defensible record of exactly who accessed which pre-read materials, and prevents forwarding to unintended recipients.

Can MSLs use a data room in the field?

Yes. Because Govern 365 runs on Microsoft 365, MSLs share governed links from the same Teams and SharePoint environment they already use – on any device. The recipient experience is a simple, branded portal; the sponsor keeps watermarks, expiry, and a per-document view log behind it.

Related Reading

Niraj Tenany

President, CEO and Co-founder, Netwoven | Product Owner, Govern 365

38 years of Enterprise Technology experience. Worked on early version of SharePoint at Microsoft in 1999. Also leads the AI and Security practice.

Author of Secure by Design: How Modern Organizations Collaborate Without Compromise, the executive playbook for delivering VDR-grade outcomes inside Microsoft 365.

I wrote this book after watching enterprises use a category of software called Virtual Data Rooms (VDR) for M&A types of transactions only, whereas the broader category of secure collaboration needed organizations to think about Virtual Data Rooms in a broader context to be able to secure their crown jewels from all across the organizations. This book frames VDR from a software category to VDR as an outcome.

Get the book →

Leave a comment

Your email address will not be published. Required fields are marked *

4000 Pimlico Drive, Suite 114-103 Pleasanton, CA 94588
Linkedin Twitter Facebook Youtube
 
Microsoft
Govern 365 - Member of Microsoft Intelligent Security Association
9 minutes
Request a Demo