What happened

Italy's data protection authority, the Garante per la protezione dei dati personali, has fined the healthcare data company IQVIA 7 million euros, roughly 7.8 million US dollars, over the way it handled patient information. The decision was published late last week and followed an investigation opened in April 2025.

The regulator found that IQVIA's Italian division had built a database covering about one million patients by aggregating records from 800 general practitioners. Patient names were replaced with a unique code, but the authority concluded that the code still allowed individuals to be tracked over time. Combined with the level of detail held, which included year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data, it was possible to single out individual patients and re-identify them using reasonable means.

The GPDP also found the data was processed without an appropriate legal basis and without informing patients, which breaches the GDPR. No retention periods were established or followed, and records dating back to 2001 were still held. For a subset of about 3,300 patients, the database also contained names, tax identification numbers, addresses and contact details.

Alongside the fine, IQVIA has been ordered to bring its practices into line within 120 days. In a statement, the company said it maintains robust safeguards including pseudonymization and encryption, that it has already taken steps to align with the authority's guidance, and that it reserves the right to appeal.

Why this is a GRC story

Pseudonymisation is not anonymisation, and the gap is now measurable. A coded identifier feels like protection, yet if the same code follows the same person across years of records it becomes a tracking key. This decision is a practical test of how a regulator assesses re-identification risk, and it lines up with long standing guidance that what matters is the data that could reasonably be linked back to a record.

Purpose, notice and retention failed together. Three separate obligations broke inside the same programme, and none of them needed exotic technology to fix. A lawful basis, a privacy notice to patients, and a defined retention period are the basics a privacy impact assessment should surface before a dataset is built, not after a regulator arrives.

Health analytics carries an asymmetric downside. The commercial value of the dataset sits in its detail. That same detail is what makes re-identification possible and what makes the harm hard to undo, because a patient cannot change a diagnosis the way they can change a password.

What to watch

Watch whether IQVIA appeals, and how the authority treats the 120 day remediation order if the company does. Watch, too, for similar scrutiny of other analytics vendors that sit between clinics and commercial research, because the reasoning travels easily to any secondary use of health data.

If the reasoning holds, the working checklist for health data reuse becomes short: prove the dataset cannot be re-identified, name the lawful basis in writing, tell the people whose data you hold, and delete on a schedule you can evidence.

Attribution: Analysis based on BleepingComputer and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News