Skip to main content
ComplianceData Protection

IQVIA Fined $7.8 Million for Lax Health Data Anonymization Practices

Softly lit healthcare setting with patient files in foreground and blurred database screen in background.

€7 million ($7.8M) — the fine Italy's Data Protection Authority (GPDP) levied against IQVIA after finding anonymization and processing practices that, the agency said, could have put roughly one million patients at risk of reidentification.

The GPDP’s findings

Italian authorities investigated IQVIA's data-processing practices in April 2025, and, according to the GPDP announcement cited by BleepingComputer, decided last month that the company "did not provide adequate health-data anonymization warranties." The agency concluded the database in question contained the health information of roughly one million patients, assembled by aggregating records from 800 general practitioners.

The GPDP described how a unique code associated with each patient allowed longitudinal tracking and, in combination with a detailed set of attributes, made reidentification feasible. "The code associated with each patient made it possible to track them over time,” the GPDP said. “Combined with a very detailed set of information (year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to single out individual patients and, using reasonable means, reidentify them.”

What the database contained and retention issues

Beyond the coded identifiers, the GPDP highlighted the richness of the records: year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data. The authority also found that IQVIA processed data without an appropriate legal basis and without informing patients, which it said violated the GDPR.

On retention, the GPDP found IQVIA "did not establish or follow any data retention periods," with records in the dataset dating back as far as 2001. For a subset of 3,300 patients, the agency said the database included direct identifiers — names, tax identification numbers, addresses, and contact details.

Regulatory outcome and remedial orders

In addition to the €7 million fine (reported as $7.8M), Italian authorities ordered IQVIA to bring its practices into compliance within 120 days. The GPDP’s decision identifies failures in anonymization guarantees, lawful basis for processing, transparency to data subjects, and retention controls as the basis for both the monetary sanction and the compliance order.

IQVIA’s response

BleepingComputer contacted IQVIA and received a spokesperson statement. IQVIA said it is "committed to the responsible use of data and information and continues to cooperate with the Authority." The company asserted it maintains "robust safeguards, including the use of pseudonymization and encryption, to support responsible data use in healthcare."

IQVIA acknowledged the GPDP decision and "reserves the right to appeal." The firm also said "the dataset to which the Italian Data Protection Authority's decision relates is not used by IQVIA in conduct of clinical research services and does not relate to the conduct of clinical trials on behalf of the sponsors." IQVIA added it has "engaged constructively with the Italian Data Protection Authority throughout this process and have already taken steps to adopt the measures necessary to ensure full alignment with the Authority's guidance."

What this means for technologists, policymakers, and patients

  • Technologists and security teams: The GPDP’s conclusion that pseudonymization plus rich attribute sets permitted reidentification underscores the limits of coding alone when longitudinal or granular location and clinical data are present. Systems that allow long-term linking of records may need stronger technical or organizational safeguards and clearer retention rules.
  • Policymakers and regulators: The decision points to enforcement consequences for processing without an appropriate legal basis or without informing data subjects and shows regulators will pair monetary sanctions with orders to remediate practices within defined deadlines (the GPDP set a 120-day compliance window).
  • Patients and the public: The GPDP flagged a real-world exposure risk affecting roughly one million patients and found a subset of 3,300 records contained direct identifiers, meaning some individuals were held in a dataset that included names, tax IDs, addresses, and contact information.

IQVIA is described in the company’s materials as a multinational that operates in over 100 countries and handles 68 petabytes of data and 1.2 billion patient records; the GPDP decision focuses on practices within its Italian division and a specific dataset assembled from 800 general practitioners. The firm’s stated intent to appeal and the 120-day compliance requirement set clear near-term milestones: legal review by the company and corrective action under a regulator’s clock.

The GPDP’s sanction and order raise a pointed question for organizations handling large, longitudinal health datasets: when does reidentification risk cross the boundary from theoretical to actionable under GDPR criteria? In this case, the regulator determined that combination of coded identifiers, detailed clinical and location attributes, and indefinite retention sufficed to cross that line.

Original reporting: BleepingComputer — IQVIA fined $7.8 million for failing to properly anonymize health data