Skip to content
IQVIA Fined €7 Million for Data Anonymization Failures

IQVIA Fined €7 Million for Data Anonymization Failures

First seen 5 Oct 2026, 20:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 21:26 UTC
  • •IQVIA fined €7 million for failing to anonymize health data properly.
  • •The breach involved sensitive data from one million patients linked to 800 doctors.
  • •IQVIA must comply with regulatory requirements within 120 days to avoid further penalties.

Italy's Data Protection Authority has fined IQVIA €7 million ($7.8 million) for inadequate health data anonymization practices that jeopardized the privacy of approximately one million patients. The investigation, initiated in April 2025, revealed that IQVIA had created a database aggregating sensitive health information from 800 general practitioners without proper anonymization, allowing for potential re-identification of individuals. The data included detailed health records, such as diagnoses and prescriptions, and some records contained identifiable information for over 3,300 patients. The company failed to establish legal grounds for processing the data and did not inform patients, violating GDPR regulations. IQVIA has 120 days to comply with the Authority's requirements or face further penalties. The fine reflects the serious nature of the breach and the number of patients affected.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-04-01
Investigation initiated
Italy's Data Protection Authority began investigating IQVIA's data practices after inspections.
Bleepingcomputer
2026-09-23
Fine imposed
The Italian Data Protection Authority fined IQVIA €7 million for data protection breaches.
Databreaches

More articles in this cluster (2)

Following this threat?

Track Iqvia in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What specific data was compromised?
The compromised data included health information such as diagnoses, prescriptions, and identifiable details for over 3,300 patients.
How long does IQVIA have to comply?
IQVIA has 120 days to adapt its data processing practices to meet the Authority's requirements.
What are the potential consequences for IQVIA?
Failure to comply with the Authority's requirements may result in further penalties or restrictions on their operations.