
Italy fines healthcare analytics firm Iqvia 7 million euros over unmasked patient data
Italy's privacy watchdog penalized Iqvia Solutions Italy for compiling unmasked health records of over one million patients gathered from 800 doctors, setting a 120-day compliance deadline.
Investigation and regulatory findings
The Italian data protection authority, the Garante per la protezione dei dati personali, fined Iqvia Solutions Italy S.r.l. 7 million euros on 2 October 2026 for violations concerning the processing of personal health data. The regulatory action followed an inspection inquiry opened in April 2025, which was later merged with a data breach notification submitted by the company itself. The watchdog established that Iqvia created a database containing health information belonging to more than one million patients collected from 800 general practitioners across Italy, with records dating back to 2001. The authority determined that Iqvia acted as the data controller starting from the initial data collection at medical practices. The regulator concluded that the enterprise processed sensitive health data without an appropriate legal basis and failed to provide adequate information to the affected individuals.
- Earliest health records stored in Iqvia database
- General practitioners cease sending patient records to Iqvia
- Privacy authority conducts inspection audits
- Italian data protection authority imposes 7 million euro fine
Re-identification risks and unmasked records
The watchdog rejected claims that the stored information had undergone effective anonymization. Each patient had an associated tracking code that permitted continuous observation over time, which, when combined with detailed medical and demographic profiles including year of birth, sex, diagnoses, symptoms, prescriptions, medical examinations, vaccinations, and geographic location, allowed individual identification through reasonable means. Furthermore, investigators found that direct identifying information for more than 3,300 patients entered the repository in plain text, including full names, tax identification codes, home addresses, and contact details. In more than 3,000 of these cases, the personal identifiers directly accompanied sensitive medical records. The authority noted that Iqvia failed to establish maximum retention limits for records gathered since 2001, neglected to perform a required data protection impact assessment, and maintained inadequate technical security safeguards.
Corporate response and data safeguards
Iqvia stated that it took note of the decision while reserving its right to appeal the penalty. The healthcare analytics firm maintained that the dataset referenced in the decision is not used for clinical research services or clinical trials conducted for commercial sponsors. The company also asserted that it collaborated constructively throughout the proceedings and had already adopted measures to ensure full alignment with supervisory instructions.
Iqvia is committed to a responsible use of data and information and continues to collaborate with the Authority. Data protection represents an absolute priority for Iqvia and is protected by robust security measures, including the use of pseudonymisation and encryption, to support responsible data use in healthcare.
Compliance timeline and doctor liability
Under the terms of the decision, Iqvia has 120 days to bring its data processing operations into full compliance if it intends to continue working with the repository. If the firm cannot meet the requirements, anonymization must be handled directly and independently by general practitioners under technical guidelines outlined by the regulator. In setting the 7 million euro fine, the authority evaluated the total volume of patients affected, the sensitive nature of the health records, and the constructive assistance provided by the company during the inquiry. The regulator also took into account that general practitioners had ceased sending medical data to Iqvia in 2023. The watchdog confirmed that family doctors bear no legal responsibility for the data handling practices established by the analytics company.


