HomeSecurityIQVIA fined €7 million for improper data processing

IQVIA fined €7 million for improper data processing

The Italian Data Protection Authority (GPDP) has fined IQVIA € 7 million , finding that the company's health data processing practices did not provide sufficient safeguards. According to the decision, around one million patients may have been exposed to the risk of re-identification, despite the fact that their data had been pseudonymised.

IQVIA

The case highlights a particularly critical issue for the digital health sector: removing a name from a database does not automatically mean that an individual cannot be identified. When enough details about a patient are combined, their identity can be revealed even without their full name being recorded.

A database with approximately one million patients

IQVIA is an international leader in health data analytics, technology and clinical research. It says it has a presence in more than 100 countriesand manages vast volumes of health-related information.

See also: CPR Register Denmark: Data leak of 8.8 million people

As part of the investigation, GPDP found that the company's Italian division had created a database containing information on around one million patients, with data collected from around 800 general practitioners.

The investigation by Italian authorities began in April 2025 and examined how IQVIA collected, stored and processed the specific information.

Pseudonymization was not considered sufficient

One of the key findings of the GPDP was how patients' identities were protected. Instead of names, the records used a unique code for each individual.

The Authority, however, considered that this approach did not ensure true anonymization. The code allowed different records to be linked to the same patient over time. At the same time, the database contained a particularly detailed set of information, such as year of birth, gender, diagnoses, symptoms, prescriptions, tests, vaccinations and location data.

The combination of these data, according to the GPDP, could under reasonable circumstances allow the identification of specific individuals. This is a typical example of the risk created when data that appears individually “harmless” is combined with each other.

See also: Wikimedia Foundation reports action by OpenAI agents

IQVIA fined €7 million for improper data processing

Even more sensitive data for 3,300 patients

The case is made even more serious by the fact that for a subset of approximately 3,300 patients , the database also contained directly identifiable information. This included names, tax numbers, addresses and contact information.

At the same time, the GPDP identified records that were kept for a particularly long time, with some data dating back as far as 2001.The lack of clear and enforced retention time limits was another point of concern for the Italian authorities.

The case illustrates why the principle of data minimization and limited data retention are key elements of privacy protection. The more data is stored and the longer it is retained, the greater the potential impact of a breach.

Issues regarding GDPR

The GPDP also found problems with the legal basis of the processing and the information provided to patients. The authorities considered that IQVIA was processing certain information without meeting the required conditions and without sufficient information being provided to the individuals concerned.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

For health data, the GDPR requirements are particularly strict, as it is a special category of personal data. Its proper management requires not only technical measures, but also a clear definition of purpose, legal basis, retention period and rights of the subjects.

IQVIA's answer

In addition to the monetary fine, GPDP gave IQVIA a 120-day to align its practices with the requirements of the law.

See also: Phishing: TA419 targets AI Policy experts

The company said it considers data protection a top priority and uses measures such as pseudonymisation and encryption, while acknowledging the Italian authority's decision, while reserving the right to appeal.

IQVIA also argued that this particular dataset is not used to provide clinical research services and is not linked to the conduct of clinical trials on behalf of sponsors.

IQVIA fined €7 million for improper data processing

The company added that it cooperated with GPDP throughout the process and that it has already begun implementing the required compliance measures.

The case is an important reminder that in the digital health space, pseudonymization should not be treated as absolute anonymization. The value of health data, combined with the increasing ability to correlate different sources of information, makes a multi-layered approach to protection. For organizations managing millions of medical records, GDPR compliance is not just a legal obligation, but a critical factor for patient safety and trust.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS