Bleepingcomputer IQVIA Fined €7 Million for Data Anonymization Failures
Article Content
- •IQVIA fined €7 million for failing to anonymize health data properly.
- •The breach involved sensitive data from one million patients linked to 800 doctors.
- •IQVIA must comply with regulatory requirements within 120 days to avoid further penalties.
Italy's Data Protection Authority has fined IQVIA €7 million ($7.8 million) for inadequate health data anonymization practices that jeopardized the privacy of approximately one million patients. The investigation, initiated in April 2025, revealed that IQVIA had created a database aggregating sensitive health information from 800 general practitioners without proper anonymization, allowing for potential re-identification of individuals. The data included detailed health records, such as diagnoses and prescriptions, and some records contained identifiable information for over 3,300 patients. The company failed to establish legal grounds for processing the data and did not inform patients, violating GDPR regulations. IQVIA has 120 days to comply with the Authority's requirements or face further penalties. The fine reflects the serious nature of the breach and the number of patients affected.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Iqvia in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What specific data was compromised?
How long does IQVIA have to comply?
What are the potential consequences for IQVIA?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…