Italian Data Protection Authority Fines IQVIA $7.8 Million for Poor Data Handling Practices
In a move that highlights the critical importance of robust data protection practices, Italy’s Data Protection Authority (GPDP) has fined multinational healthcare company IQVIA €7 million ($7.8M) for failing to properly anonymize sensitive health information. The fine is the latest in a string of penalties levied against companies found to be lax in their handling of personal and medical data.
The investigation, which began in April 2025, focused on IQVIA’s Italian division and its practices in aggregating and processing data from general practitioners’ records. The company claimed to have anonymized the data by using a unique code instead of patients’ names, but the GPDP found this measure insufficient to prevent re-identification. By combining the code with detailed patient information such as year of birth, diagnoses, and location data, it became possible for researchers or other parties to single out individual patients and de-anonymize their records.
The GPDP’s findings also revealed that IQVIA processed sensitive health data without an appropriate legal basis and failed to inform patients about the processing of their data. Moreover, the company did not establish or follow any data retention periods, with some records dating back as far as 2001. In a particularly disturbing discovery, the agency found that for a subset of 3,300 patients in IQVIA’s database, the company had included sensitive personal details such as names, tax identification numbers, addresses, and contact information.
The scale of this breach is significant, with approximately one million patients potentially at risk of data exposure. The fine levied against IQVIA sends a clear message to companies handling sensitive health data: protecting patient confidentiality and adhering to robust data protection practices must be their top priority.
This incident serves as a reminder that even large corporations can fall victim to lax data handling practices, highlighting the need for continuous vigilance and improvement. As more organizations adopt digital solutions and expand their reach into sensitive industries such as healthcare, they must also invest in robust security measures and ensure compliance with relevant regulations like the GDPR.
For individuals, this incident underscores the importance of being aware of how their personal and medical data is handled. Patients should verify that their healthcare providers are taking adequate steps to protect their confidentiality and seek clarity on any data processing practices or transfers.
As companies continue to grapple with the complexities of handling sensitive health information, it’s crucial for them to prioritize robust security measures, regular audits, and employee training. Only by doing so can they ensure that patients’ trust is maintained and that sensitive data remains protected from unauthorized access or misuse.
Source: Bleeping Computer — 2026-10-05