Skip to content
IQVIA Fined €7 Million for Data Privacy Violations

IQVIA Fined €7 Million for Data Privacy Violations

First seen 5 Oct 2026, 20:27 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 21:26 UTC
  • •IQVIA fined €7 million for privacy violations involving health data.
  • •Data of one million patients was improperly anonymized, allowing potential reidentification.
  • •The ruling was based on inspections conducted in April 2025 and finalized in September 2026.

The Italian Data Protection Authority has fined IQVIA Solutions Italy S.r.l. €7 million for mishandling health data of one million patients from 800 general practitioners. The investigation revealed that the data, claimed by IQVIA to be anonymous, contained identifiable information including birth year, gender, diagnoses, and location data. This decision followed inspections conducted in April 2025 and was formalized in a ruling dated September 23, 2026. The authority concluded that the data was not properly anonymized and could allow for patient reidentification. The fine is part of a broader scrutiny of data privacy practices in the healthcare sector.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-04-01
Inspections conducted
The Italian Data Protection Authority conducted inspections on IQVIA regarding data privacy practices.
Garante Privacy
2026-09-23
Ruling issued
The Italian Data Protection Authority issued a ruling fining IQVIA €7 million for data privacy violations.
Garante Privacy
2026-10-05
Public announcement of fine
The fine against IQVIA was publicly announced, detailing the misuse of patient data.
GPDP

More articles in this cluster (2)

Following this threat?

Track Azienda USL Della Romagna in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What specific violations did IQVIA commit?
IQVIA failed to properly anonymize health data, allowing for potential reidentification of patients.
How many patients were affected by this violation?
The violation involved health data from one million patients across 800 general practitioners.
What actions did the Italian Data Protection Authority take?
The authority conducted inspections and issued a €7 million fine to IQVIA for data privacy violations.