IQVIA fined $7.8 million for failing to properly anonymize health data

Italy’s Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization.

IQVIA is a multinational company that provides healthcare data analysis, technology, and clinical research services. The company claims on its website that it operates in over 100 countries and handles 68 petabytes of data and 1.2 billion patient records.

Italian authorities investigated IQVIA’s data-processing practices in April 2025, and last month decided that the company did not provide adequate health-data anonymization warranties, despite its claims.

GPDP has found that IQVIA’s Italian division had created a database containing the health information of roughly one million patients by aggregating data from 800 general practitioners.

While the company used a unique code instead of patients’ names in those records, the data protection agency found they could be used to track and de-anonymize patients over time.

“The code associated with each patient made it possible to track them over time,” explained GPDP in an announcement published late last week.

“Combined with a very detailed set of information (year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to single out individual patients and, using reasonable means, reidentify them.”

In addition, IQVIA processed data without an appropriate legal basis and without informing patients, which violates the GDPR (General Data Protection Regulation).

Finally, IQVIA allegedly did not establish or follow any data retention periods, with the GPDP finding records dating back as far as 2001.

For a subset of 3,300 patients in IQVIA’s database, the company also included names, tax identification numbers, addresses, and contact details.

In addition to the $7.8 million fine, Italian authorities also ordered the company to bring its practices into compliance within 120 days.

BleepingComputer has contacted the firm with questions about the fine, and a spokesperson sent us the following statement:

“IQVIA is committed to the responsible use of data and information and continues to cooperate with the Authority. Protecting data is a core priority for IQVIA, and we maintain robust safeguards, including the use of pseudonymization and encryption, to support responsible data use in healthcare.

IQVIA acknowledges the decision adopted by the Italian Data Protection Authority and reserves the right to appeal. The dataset to which the Italian Data Protection Authority’s decision relates is not used by IQVIA in conduct of clinical research services and does not relate to the conduct of clinical trials on behalf of the sponsors.

We have engaged constructively with the Italian Data Protection Authority throughout this process and have already taken steps to adopt the measures necessary to ensure full alignment with the Authority’s guidance.”

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

French hospital fined €500,000 after breach exposes data of 727,000

Google fined €403 million over location data privacy violations

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Aesto Health says data breach affects over 9.5 million patients

Anthropic asks Claude users to share voice data for AI model training

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

Citrix patches NetScaler SAML zero-day exploited in attacks

Free Identity Governance for up to 150 Users: Try Our Community Edition

73% of orgs feel prepared for attacks. 82% had a browser incident last year anyway.

Free Identity Governance for up to 150 Users: Try Our Community Edition

Overdue a password health-check? Audit your Active Directory for free

Your access review passed cleanly, but it never saw the agents swimming under the surface. See how Token Security fishes out every one of them.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.