Italy fines IQVIA €7 million over health data anonymization failures
The company has 120 days to change its handling of health data after regulators said its coding system could still reidentify patients.
Italy’s data protection authority has fined IQVIA €7 million ($7.8 million) and given it 120 days to fix its handling of health data after finding that its anonymization safeguards were not strong enough. Regulators say the company’s Italian unit built a database from 800 general practitioners covering about one million patients, and that the coded records could still be linked back to individuals using a mix of demographic, medical and location details. The agency also said IQVIA processed data without a proper legal basis, failed to notify patients, and kept records going back to 2001 without clear retention rules. In a subset of 3,300 patients, the database also included direct identifiers such as names, tax numbers, addresses and contact details. IQVIA says it is cooperating with the authority, has already taken steps to align with its guidance, and may appeal.
Why it matters
The case raises the bar for how health data can be coded and stored in Italy. For companies handling patient records, it shows that anonymization has to be strong enough to block reidentification over time, and that legal basis, notice and retention rules are now part of the same compliance test.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer