IQVIA fined $7.8 million by Italian regulator over health data anonymization failures

Data protection authority says unique patient codes allowed re-identification, violating GDPR

By LineZotpaper
Published
Read Time2 min
Italy's Data Protection Authority (GPDP) has fined health data analytics firm IQVIA €7 million ($7.8 million) for inadequate anonymization practices that put roughly one million patients at risk of re-identification. The regulator found that the company used unique codes instead of names in its database, but these codes could be combined with detailed health and location data to track and identify individuals over time.

The GPDP investigation, which began in April 2025, concluded that IQVIA's Italian division had created a database aggregating health information from 800 general practitioners. While the company argued the data was pseudonymized, the regulator determined that the approach did not meet GDPR requirements for anonymization.

"The code associated with each patient made it possible to track them over time," the GPDP said in its announcement. "Combined with a very detailed set of information (year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to single out individual patients and, using reasonable means, reidentify them."

In addition to the anonymization issue, the authority found that IQVIA processed data without an appropriate legal basis and failed to inform patients. The company also did not follow any data retention schedule, with records dating back to 2001. For a subset of 3,300 patients, IQVIA had stored names, tax identification numbers, addresses, and contact details.

IQVIA said in a statement to BleepingComputer that it is "committed to the responsible use of data and information" and continues to cooperate with the authority. The company acknowledged the decision and reserves the right to appeal. It noted that the dataset in question is not used in clinical research services or clinical trials.

The GPDP has ordered IQVIA to bring its practices into compliance within 120 days.

§

Analysis

Why This Matters

  • The fine underscores that pseudonymization alone may not satisfy GDPR requirements for health data, setting a significant precedent for data analytics firms.
  • The case exposes the privacy risks faced by millions of patients whose data, collected through general practitioners, could be re-identified and linked to sensitive medical histories.
  • As health data becomes increasingly valuable for research and commercial analytics, regulators are signaling that companies must implement stronger anonymization and transparency measures.

Background

IQVIA is a multinational company that provides healthcare data analysis, technology, and clinical research services, operating in over 100 countries. The Italian Data Protection Authority (GPDP) initiated its investigation in April 2025 after concerns about how the company processed health data from general practitioners. The database at issue contained records dating back to 2001 and used pseudonymization through unique patient codes rather than full anonymization.

Key Perspectives

[Regulator (GPDP)]: The unique codes combined with detailed patient information made re-identification possible, violating GDPR requirements for anonymization, legal basis, data retention, and patient consent. [IQVIA]: The company maintains its commitment to responsible data use and robust safeguards including pseudonymization and encryption. It disagrees with the decision, reserves the right to appeal, and has already taken steps to align with the regulator's guidance. IQVIA also emphasizes that the dataset is not used in its clinical research services or trials. [Critics/Skeptics]: Privacy advocates may argue that the fine, while substantial, is a fraction of IQVIA's revenues and that the real harm to patients from potential re-identification remains unaddressed. The case also raises broader questions about how effectively GDPR enforcement deters companies from collecting health data without robust safeguards.

What to Watch

  • Whether IQVIA appeals the fine and how Italian courts interpret the adequacy of pseudonymization under GDPR.
  • The outcome of the 120-day compliance deadline, including any follow-up audits by GPDP.
  • Potential spillover: other European data protection authorities may open similar investigations into IQVIA's practices across the continent.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.