IQVIA fined $7.8 million for failing to properly anonymize health data

Italian authorities have slammed multinational healthcare analytics firm IQVIA with a hefty $7.8 million fine for its failure to properly anonymize sensitive patient data, potentially putting around one million individuals at risk of identification and re-identification.

IQVIA, which boasts operations in over 100 countries and handles an astonishing 68 petabytes of health-related data – roughly equivalent to 1.2 billion patient records – was found to have created a database containing the aggregated information of nearly one million patients from Italian general practitioners’ offices. While the company claimed to have anonymized this data using unique codes instead of actual names, investigators discovered that these codes could be used to track and de-anonymize individuals over time.

According to Italy’s Data Protection Authority (GPDP), IQVIA’s database included a wealth of detailed information on each patient, including year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data. This combination of factors made it possible for the GPDP to single out specific patients and re-identify them using “reasonable means”.

Furthermore, IQVIA was found to have processed this sensitive data without a legitimate legal basis or patient consent – clear contraventions of the General Data Protection Regulation (GDPR). The company also failed to establish or adhere to data retention periods, with records stretching back as far as 2001. In some cases, even more personally identifiable information such as names, tax identification numbers, addresses, and contact details were included.

This debacle serves as a stark reminder of the importance of proper anonymization techniques in protecting sensitive personal health data. While pseudonymization – using unique codes to conceal identities – may seem like a foolproof method, it can still be vulnerable to re-identification if other identifying factors are present.

The Italian authorities have given IQVIA 120 days to bring its practices into compliance with the GDPR. In response to the fine, an IQVIA spokesperson claimed that protecting data is a “core priority” for the company and emphasized their use of robust safeguards like pseudonymization and encryption.

However, as the GPDP’s finding illustrates all too clearly, even the most rigorous measures can fall short if not properly implemented or maintained. For individuals concerned about the security of their health-related data, it’s essential to remain vigilant and demand transparency from healthcare providers and organizations that handle sensitive patient information.

In light of this incident, it’s crucial for both patients and healthcare professionals to prioritize proper anonymization techniques, ensuring that even with the best intentions, sensitive data doesn’t become a liability. By understanding the limitations of pseudonymization and taking proactive steps to protect patient confidentiality, we can create safer digital ecosystems where personal health data is safeguarded.


Source: Bleeping Computer — 2026-10-05