PolicyMedium

IQVIA fined 7 million euros in Italy over health data that could be reidentified

Italy's data protection authority fined IQVIA's Italian arm €7 million, finding that health records gathered from 800 general practitioners were pseudonymised rather than truly anonymised and could be traced back to patients.

IQVIA fined 7 million euros in Italy over health data that could be reidentified

At a glance

  • Italy's GPDP issued a €7 million ($7.8 million) fine against IQVIA's Italian division in September 2026
  • The database aggregated data from 800 general practitioners covering roughly one million patients
  • Regulators found that replacing names with persistent unique codes still allowed patients to be singled out and reidentified
  • IQVIA says it maintains pseudonymisation and encryption safeguards and reserves the right to appeal; remediation is ordered within 120 days

Italy's data protection authority has fined the Italian division of health data analytics company IQVIA €7 million (about $7.8 million) after finding that a database of patient health records it described as anonymised could in fact be traced back to individuals. BleepingComputer reports that the decision was issued in September 2026 by the Garante per la protezione dei dati personali (GPDP) and concerns data drawn from 800 general practitioners covering roughly one million patients.

What happened

According to BleepingComputer, IQVIA's Italian arm aggregated information from those 800 general practitioners into a single database. Patient names had been replaced with unique codes, which the company treated as sufficient to take the dataset outside the scope of personal data protection rules.

The GPDP disagreed. BleepingComputer reports the authority found that the identifiers were persistent enough to track the same individual over time, and that when combined with the detailed health attributes held alongside them — year of birth, sex, diagnoses, prescriptions, vaccinations and location data — patients could be "singled out and, using reasonable means, reidentified." In regulatory terms, that makes the dataset pseudonymised rather than anonymous, and therefore still fully subject to data protection law.

Technical and legal details

The reidentification finding was not the only violation. BleepingComputer reports that the authority also concluded the data was processed without an appropriate legal basis and without notifying the patients concerned, and that no retention periods had been established — with records in the database dating back as far as 2001.

The regulator additionally found that for 3,300 patients the database went well beyond coded identifiers and held names, tax identification numbers, addresses and contact details outright, according to BleepingComputer.

Italian authorities ordered the company to bring its processing into compliance within 120 days of the decision.

Who is affected

The immediate scope is the roughly one million Italian patients whose records sat in the database, and the much smaller group of 3,300 whose directly identifying details were held. But the significance of the case reaches further, to any organisation that treats code-substituted health or behavioural data as anonymous and therefore exempt from consent, notice and retention obligations.

The reasoning applied here is familiar from other European decisions: a stable identifier plus a rich attribute set is a reidentification toolkit, even with names stripped. Health data is especially exposed to this because diagnoses, prescriptions and visit patterns are close to unique at the individual level.

IQVIA told BleepingComputer that "we maintain robust safeguards, including the use of pseudonymization and encryption, to support responsible data use in healthcare." The company said the dataset was not used for its clinical research services and that it "reserves the right to appeal."

What to do

Organisations holding coded health, insurance or telemetry datasets should not assume that removing names clears the anonymity bar. Practical steps that follow from this decision: test datasets for reidentification risk rather than asserting anonymity on the basis of the pseudonymisation method alone; rotate or break the linkability of identifiers where longitudinal tracking is not strictly required; define and enforce retention limits instead of letting records accumulate for two decades; and audit tables for fields — names, tax numbers, addresses — that were never supposed to be there. Where a dataset is genuinely pseudonymised, treat it as personal data end to end, including legal basis, transparency notices and data subject rights.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.