IQVIA Fined $7.8 Million Over Improper Handling of Personal Health Data

Views: 219 views

551/69 Wednesday, October 7, 2026

Italy’s data protection authority, the Garante per la Protezione dei Dati Personali (GPDP), has imposed a €7 million fine, approximately US$7.8 million, on IQVIA over improper data processing practices that may have exposed the health information of around one million patients to the risk of disclosure or re-identification. IQVIA provides healthcare analytics, technology, and clinical research services, and states that it operates in more than 100 countries while managing large volumes of data, including extensive patient information.

The investigation found that IQVIA’s Italian operation had created a database containing the health information of approximately one million patients, collected from around 800 general practitioners. Although the company replaced patients’ names with unique identifiers, the GPDP determined that these identifiers could still be used to track individuals over time. When combined with detailed information such as year of birth, gender, diagnoses, symptoms, prescriptions, medical examinations, vaccinations, and geographic information, the data could allow individual patients to be distinguished and potentially re-identified using reasonably available methods.

The GPDP also found that IQVIA processed the data without an appropriate legal basis and failed to inform the affected patients, in violation of the General Data Protection Regulation (GDPR). In addition, the company had not clearly established or complied with appropriate data retention periods. Investigators found records dating back to 2001 for approximately 3,300 patients. IQVIA’s database also contained names, tax identification numbers, addresses, and contact details. In addition to the financial penalty, the Italian authority ordered the company to bring its data processing practices into compliance with applicable data protection requirements within 120 days.

Source https://www.bleepingcomputer.com/news/security/iqvia-fined-78-million-for-failing-to-properly-anonymize-health-data/