Italy says a million-patient IQVIA database was never truly anonymous

Italy's privacy watchdog fined IQVIA 7M euros, ruling that a health database drawn from one million patients was not genuinely anonymized.

MedRisk Staff
By
2 Min Read

Italy’s data protection authority has fined IQVIA Solutions Italy Srl EUR 7M, rejecting the company’s claim that a health database covering roughly one million patients was anonymous. The Garante said the records, gathered from about 800 family doctors for studies commissioned by drugmakers, could still be traced back to individuals.

A per-patient code let IQVIA follow people over time. Combined with year of birth, sex, diagnosis, symptoms, prescriptions, tests, vaccinations and location data, that detail made it possible to isolate single patients and re-identify them with reasonable means, the regulator found. The database also carried names, tax codes and addresses for more than 3,300 patients, over 3,000 of them tied to health data.

The authority said IQVIA processed health data without a proper legal basis, failed to inform patients adequately, set no retention limits for records reaching back to 2001, skipped a data protection impact assessment and left security controls short. The ruling, published as provision no. 710 of 23 September 2026, gives the firm 120 days to comply or hand anonymization work back to the doctors.

For providers, labs and clinical research organizations, the case is a warning: one longitudinal code plus rich clinical detail can defeat de-identification, and European regulators now treat “anonymous” as a claim to prove rather than assert.

Share This Article