IQVIA hit with EUR 7M fine over health data anonymization

IQVIA hit with EUR 7M fine over health data anonymization

Italy's Data Protection Authority (GPDP), the national regulator that enforces the EU's data protection rules in the country, has fined IQVIA €7 million ($7.8M). The authority says the company's handling of health records could have exposed around one million patients to identification, even though the data was supposed to be anonymous.

IQVIA is a multinational provider of healthcare data analysis, technology and clinical research services. On its website, the company says it operates in more than 100 countries and handles 68 petabytes of data and 1.2 billion patient records.

The GPDP began examining IQVIA's data-processing practices in April 2025. Last month it concluded that the company had not provided adequate guarantees that the health data it held was anonymized, despite its claims.

A database built from 800 doctors' records

According to the regulator, IQVIA's Italian division assembled a database with health information on roughly one million patients. The data came from 800 general practitioners.

Patient names were replaced with a unique code. The GPDP found that this did not stop patients from being tracked and identified over time.

"The code associated with each patient made it possible to track them over time," the authority said in an announcement published late last week.

The problem was the level of detail attached to each code. "Combined with a very detailed set of information (year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to single out individual patients and, using reasonable means, reidentify them," the GPDP explained.

For 3,300 patients, the records went further. They included names, tax identification numbers, addresses and contact details.

Multiple GDPR violations

Weak anonymization was not the only finding. The GPDP said IQVIA processed the data without an appropriate legal basis and without informing the patients involved. Both are violations of the GDPR (General Data Protection Regulation), the EU law that governs how personal data is collected and used.

The company also allegedly failed to set or follow any data retention periods. The regulator found records going back as far as 2001.

On top of the fine, the GPDP ordered IQVIA to bring its practices into compliance within 120 days.

IQVIA says it may appeal

In a statement to BleepingComputer, an IQVIA spokesperson said the company "is committed to the responsible use of data and information and continues to cooperate with the Authority." The spokesperson added that protecting data is a core priority and that the company uses safeguards "including the use of pseudonymization and encryption."

IQVIA acknowledged the decision but "reserves the right to appeal." According to the company, the dataset covered by the ruling is not used in its clinical research services and has nothing to do with clinical trials run on behalf of sponsors.

"We have engaged constructively with the Italian Data Protection Authority throughout this process and have already taken steps to adopt the measures necessary to ensure full alignment with the Authority's guidance," the statement said.

Our Take

The case shows the gap between pseudonymization and anonymization. Swapping a name for a code is pseudonymization, and IQVIA itself describes its safeguards that way. The GPDP's reasoning shows why that is not enough when a stable identifier sits next to birth year, sex, diagnoses, prescriptions and location data. Taken together, those details can point to a single person.

For organizations that collect or share health data, this suggests regulators are judging "anonymous" datasets by what could realistically be done with them, not by the labels companies put on them. The missing retention limits, with records going back to 2001, also show that keeping data indefinitely is a risk in its own right. Every extra year of stored records makes a dataset more valuable to attackers, as recent health sector breaches have shown.

Healthcare data is getting attention from privacy regulators and from lawmakers, including the healthcare cybersecurity bill now moving through the US Congress. Large national datasets also remain attractive targets, as the Danish CPR register breach showed.

It is worth watching whether IQVIA files an appeal and what changes it makes within the 120-day deadline. Another question is whether other European regulators look more closely at similar datasets that rely on coded identifiers.