Italy Fines IQVIA €7 Million Over Patient Data Anonymization Failures

Italy’s data protection authority, the Garante per la protezione dei dati personali, fined IQVIA Solutions Italy €7 million—roughly $7.8 million—on September 23, 2026, over poor data-processing practices. The Italian regulator stated that the company failed to properly anonymize a database of roughly one million patients, exposing them to potential de-anonymization.

The Anatomy of an Anonymization Failure

The investigation focused on IQVIA’s Longitudinal Patient Data (LPD) database. This repository aggregated health information pulled directly from about 800 general practitioners affiliated with the scientific association SIMG, as bleepingcomputer.com reported.

The data collection pipeline relied on a specialized software add-on. Installed on practice management systems, this add-on stripped away direct identifiers like names and addresses, adjusted birth dates to the first day of the month, and assigned each patient a random, fixed Pat ID.

IQVIA utilized this setup for pharmaceutical company-sponsored observational studies. However, the Italian Garante found these safeguards fell short of legal standards.

The regulator determined that the constant Pat ID allowed researchers to track individuals over time. When combined with granular attributes—such as year of birth, sex, specific diagnoses, symptoms, prescriptions, exams, vaccinations, and location-related metrics—the dataset crossed the line from anonymous back to personal data.

As captaincompliance.com noted, a dataset can have names and tax IDs removed and still remain personal data if individuals can reasonably be singled out or reidentified. The Garante discovered that the richness of the clinical records made single-patient isolation entirely feasible using reasonable means.

One million patients face exposure after anonymization fell short #Shorts

Regulatory Violations and Wider Compliance Failures

Beyond the technical flaws of pseudonymization, the Garante cited multiple statutory breaches under the General Data Protection Regulation. IQVIA processed sensitive health data without an appropriate legal basis and failed to properly inform patients, relying solely on the privacy notices issued by their individual general practitioners.

The company also allegedly neglected to establish or follow strict data retention periods. Investigators found records stretching all the way back to 2001.

The investigation uncovered an explicit data breach within a subset of the LPD database. Free-text fields had been mistakenly extracted, leaving the unmasked names, tax identification numbers, addresses, and contact details of 3,370 patients—alongside health data for 3,080 of them—exposed and passed on to SIMG.

The Garante ordered IQVIA Solutions Italy to bring its entire data-processing architecture into regulatory compliance within 120 days.

IQVIA Claims Data Was Effectively Anonymous

IQVIA maintained that it acted merely as a technological and financial partner, arguing that SIMG, the practitioners, and the software developer determined the core purposes and means of the processing. Citing the Court of Justice of the European Union’s SRB judgment, the company asserted that the data was effectively anonymous from its perspective because it lacked access to the linkage key and faced a low risk score for re-identification.

The firm also argued that Data Protection Impact Assessment obligations did not apply because the processing operations began before 2018.

The Garante rejected these arguments, concluding that IQVIA played an active, determining role as the controller across the entire processing chain. In a statement provided to bleepingcomputer.com, an IQVIA spokesperson acknowledged the decision, stating: IQVIA is committed to the responsible use of data and information and continues to cooperate with the Authority. Protecting data is a core priority for IQVIA, and we maintain robust safeguards, including the use of pseudonymization and encryption, to support responsible data use in healthcare.

The company confirmed it reserves the right to appeal the decision. It also stated that the disputed dataset is not used to conduct clinical research services or clinical trials on behalf of sponsors, and that it has already engaged constructively with Italian regulators to adopt necessary alignment measures.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Premier League clubs seek new shirt sponsors after gambling ban

Supreme Court signals skepticism of state climate change lawsuits