Breaking
Cyber CrimeDeveloping Story

Italy fines IQVIA $7.8M over health data

Italy's privacy regulator fined IQVIA €7M for pseudonymization failures it says risked re-identifying roughly one million patients.

··1 hour ago·6 min read
person sitting while using laptop computer and green stethoscope near
Photo by National Cancer Institute on Unsplash

A pseudonymized health database holding records on about one million Italians has landed IQVIA with a €7 million penalty from the country's privacy watchdog. The Garante per la protezione dei dati personali (GPDP) says the company's promise of anonymization did not hold up against the data it had collected — and that the records carried enough detail to bring individuals back into view.

The fine, announced by the authority, is one of the regulator's larger actions against a health-data processor. It targets not a single breach but a set of data-handling practices that the GPDP says violated the General Data Protection Regulation on several fronts at once.

A database built from 800 doctors

According to the GPDP, IQVIA's Italian division assembled a database of health information on roughly one million patients by aggregating records from 800 general practitioners.

IQVIA is a multinational company that provides healthcare data analysis, technology, and clinical research services. The company states on its website that it operates in more than 100 countries and handles 68 petabytes of data and 1.2 billion patient records.

That scale is central to the case. The regulator's concern is not that the records carried patients' names, but that the substitute — a code — was not enough to break the link back to a real person.

Why a code wasn't enough

The GPDP's analysis concluded that the unique code assigned to each patient functioned as a persistent identifier rather than a true anonymization measure. Because the same code stayed with a patient across records and over time, it allowed that person's history to be followed.

"The code associated with each patient made it possible to track them over time," explained GPDP in an announcement published late last week.

The regulator went further, describing how the surrounding data turned a coded record into a re-identifiable one.

"Combined with a very detailed set of information (year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to single out individual patients and, using reasonable means, reidentify them."

— GPDP, Italy's data protection authority

That combination — a stable code plus granular clinical and location detail — is the crux of the finding. Each element on its own may look innocuous; together, the GPDP says, they shrink the pool of possible matches until an individual can be singled out.

The legal basis problem

Beyond the anonymization question, the authority found that IQVIA processed the data without an appropriate legal basis and without informing patients. Under the GDPR, both are independent violations, and the GPDP cited them alongside the re-identification risk.

The authority also said IQVIA had not established or followed any data retention periods. Records in the database dated back as far as 2001, according to the GPDP's findings — a span that the absence of a retention policy left unaddressed.

Names and tax IDs for 3,300 patients

For a subset of the database, the regulator found the pseudonymization was absent altogether. The GPDP says IQVIA included names, tax identification numbers, addresses, and contact details for 3,300 patients.

That subset sits at the opposite end of the spectrum from the coded records: direct identifiers layered on top of clinical data, in a database the company had characterized as anonymized.

What IQVIA must do now

Alongside the €7 million penalty, Italian authorities ordered the company to bring its practices into compliance within 120 days. The compliance order means the case does not close with the fine alone; IQVIA faces a defined window to change how the data is handled.

The GPDP published its announcement late last week, setting out the findings that underpin both the financial penalty and the corrective order.

IQVIA's response

BleepingComputer contacted the firm about the fine. A spokesperson provided a statement in which the company acknowledged the decision while reserving its options.

"IQVIA is committed to the responsible use of data and information and continues to cooperate with the Authority. Protecting data is a core priority for IQVIA, and we maintain robust safeguards, including the use of pseudonymization and encryption, to support responsible data use in healthcare.

IQVIA acknowledges the decision adopted by the Italian Data Protection Authority and reserves the right to appeal. The dataset to which the Italian Data Protection Authority's decision relates is not used by IQVIA in conduct of clinical research services and does not relate to the conduct of clinical trials on behalf of the sponsors.

We have engaged constructively with the Italian Data Protection Authority throughout this process and have already taken steps to adopt the measures necessary to ensure full alignment with the Authority's guidance."

— An IQVIA spokesperson

The statement draws a boundary around the dataset at issue, stating that it is not used in the company's clinical research services and does not relate to clinical trials conducted on behalf of sponsors. It also notes that IQVIA has begun adopting measures to align with the authority's guidance.

The numbers behind the case

  • €7 million ($7.8 million) — the fine imposed on IQVIA by Italy's GPDP
  • Roughly one million patients — whose health information the GPDP says was in the database
  • 800 general practitioners — the sources whose records were aggregated
  • 3,300 patients — the subset whose names, tax identification numbers, addresses, and contact details were included
  • 2001 — the earliest date of records found in the database
  • 120 days — the compliance window the authority ordered
  • 68 petabytes of data and 1.2 billion patient records — the scale IQVIA claims on its website

The authority's investigation into IQVIA's data-processing practices dates to April 2025, and the decision followed last month, according to the GPDP's account.

The re-identification math

The GPDP's finding rests on a familiar tension in health-data work: stripping names is not the same as making a record anonymous. A coded identifier that persists across time is, in effect, a key — and the more attributes attached to that key, the fewer people any given record could describe.

Year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, and location data are the kind of fields that make a record clinically useful. They are also the kind of fields that narrow a search. The GPDP's position is that this combination, paired with the persistent code, made re-identification possible using reasonable means — the standard the GDPR applies when judging whether data is genuinely anonymous.

The regulator's language emphasizes both parts of that test: singling out individual patients, and then reidentifying them. Neither requires a breach in the conventional sense. The database itself, as constructed, was the problem.

Why the fine lands where it does

Three separate failures appear to stack in the GPDP's reasoning. First, the anonymization warranties IQVIA provided were judged inadequate despite the company's claims. Second, the processing lacked a legal basis and patients were not informed. Third, no retention periods were set or followed, leaving records from as far back as 2001 in place.

Any one of those could draw regulatory attention. Together, they form the basis for the €7 million penalty and the accompanying order to fix the practices within 120 days.

The case also illustrates how regulators are treating pseudonymization claims specifically. IQVIA's statement notes that it uses pseudonymization and encryption as safeguards. The GPDP's decision suggests that in this instance, the authority did not accept those safeguards as sufficient to make the data anonymous — a distinction that matters because pseudonymized data remains personal data under the GDPR, carrying obligations that anonymous data does not.

What this means for data handlers

For any organization aggregating health records at scale, the GPDP's action against IQVIA offers a concrete example of where anonymization claims can fail: a persistent code, rich clinical attributes, and location data, all in one dataset, with no retention limit and no notice to the people involved.

The fine is significant in size but the compliance order may prove more consequential for how the company operates in Italy. A 120-day clock to align with the authority's guidance puts the burden on IQVIA to demonstrate that its practices — not just its stated safeguards — meet the standard the regulator applied.

IQVIA has said it reserves the right to appeal, so the findings are not necessarily final. But the decision as published reflects the GPDP's view that a code alone does not anonymize, and that the surrounding detail is what determines whether a patient can be found again in the data. For companies handling similar troves, that is the part worth reading closely.

#iqvia#gdpr#health data#data privacy#anonymization#italy

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories