
Italy’s data protection authority has fined IQVIA Solutions Italy €7 million for unlawfully processing health information belonging to one million patients, rejecting the company’s claim that the records were anonymous.
The database contained information collected from approximately 800 general practitioners and was used for research, including studies commissioned by pharmaceutical companies.
The Garante announced the penalty late last week following a decision adopted on September 23, 2026. Its investigation followed inspections conducted in April 2025 and incorporated separate proceedings concerning a personal data breach reported by IQVIA itself.
IQVIA Solutions Italy is part of the multinational IQVIA group, which operates in healthcare data analysis and clinical research. The Italian operation maintained the patient database to support studies examining medical treatment and related health outcomes.
Patient codes did not ensure anonymity
The authority’s findings centered on the ability to distinguish individual patients and connect their medical information over time.
Each patient was assigned a persistent code that allowed successive records to be linked. Alongside that identifier, the database held detailed information including birth year, sex, diagnoses, symptoms, prescriptions, medical tests, vaccinations, and location data.
The Garante concluded that this combination made it possible to single out patients and re-identify them using reasonably available means. Consequently, the records could not be treated as anonymous simply because conventional identifiers had been replaced with codes.
The regulator also determined that IQVIA was responsible as the data controller from the point at which it collected information from doctors, placing responsibility for the processing on the company from that stage.
Separately, investigators established that the database contained direct identifying information for more than 3,300 patients, including names, tax identification codes, addresses, and contact details. For more than 3,000 of those individuals, the identifying information appeared alongside health data.
The detailed decision explains that IQVIA discovered personal information in free-text fields transferred from doctors’ systems through a software add-on. According to the workflow recorded in the decision, pharmaceutical customers received aggregated research reports.
Processing changes required
The authority found that IQVIA processed health data without an appropriate legal basis and failed to adequately inform patients about its use of their information.
The company also lacked defined retention periods, with records dating back to 2001, had not completed a data protection impact assessment, and had failed to implement adequate security measures.
IQVIA must address the regulator’s requirements within 120 days of notification if it intends to continue the processing activity. Alternatively, doctors must independently anonymize the information before supplying it.







Leave a Reply