Skip to content
See the World Through ScienceA project of ALLATRA

Italy Fines IQVIA 7 Million Euros Over Patient Records It Found Were Not Anonymous

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Visitors walk past the Italian data protection authority's exhibition stand, where a tall green banner carries the authority's name, logo and web address beside rows of small icons.
Visitors pass the Italian privacy regulator's own exhibition stand, its web address printed down the banner (illustrative)."Garante per la protezione dei dati personali" by FPA S.r.l, via flickr, BY-NC · CC-BY-NC-2.0

Italy's data protection authority, the Garante, has fined IQVIA Solutions Italy 7 million euros over a database of health records from a million patients, after finding that the records were not anonymous.

The Garante said in its announcement that the company, part of a multinational group that analyzes health data and runs clinical research, built the database from the files of 800 family doctors and used it for studies commissioned in part by pharmaceutical companies. IQVIA has 120 days to bring the processing into line if it wants to continue. Otherwise the doctors themselves must anonymize the records, under safeguards the Garante set out.

The company maintained the data was anonymous. The Garante found it was not. Each patient carried a code that allowed them to be followed over time. Set beside year of birth, sex, diagnoses, symptoms, prescriptions, test results, vaccinations and location data, that code made it possible to isolate individual patients and re-identify them by reasonable means. The Garante is the authority that decides the question, not a party to it, so the finding is the decision itself. IQVIA's position is on the record only as the authority describes it; the announcement carries no response from the company.

The authority also found that IQVIA processed health data with no adequate legal basis and did not properly inform patients. It set no retention limit, leaving records that reached back to 2001, did not carry out the required risk assessment, and had not put adequate security in place. Identifying details of more than 3,300 patients, including names, tax codes and addresses, had also ended up in the database, most alongside health data.

The decision was adopted Sept. 23, 2026, and made public Oct. 2, 2026. It closes an investigation opened after inspections at the company in April 2025, which the authority merged with a case over a data breach IQVIA had reported itself. In setting the amount, the authority said it weighed the number of patients, the kind of data, the fact that doctors had stopped sending it, and the company's cooperation.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Italy Fines IQVIA 7 Million Euros Over Patient Records It Found Were Not Anonymous

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.