IQVIA Fined €7 Million for Data Privacy Violations
Article Content
- •IQVIA fined €7 million for privacy violations involving health data.
- •Data of one million patients was improperly anonymized, allowing potential reidentification.
- •The ruling was based on inspections conducted in April 2025 and finalized in September 2026.
The Italian Data Protection Authority has fined IQVIA Solutions Italy S.r.l. €7 million for mishandling health data of one million patients from 800 general practitioners. The investigation revealed that the data, claimed by IQVIA to be anonymous, contained identifiable information including birth year, gender, diagnoses, and location data. This decision followed inspections conducted in April 2025 and was formalized in a ruling dated September 23, 2026. The authority concluded that the data was not properly anonymized and could allow for patient reidentification. The fine is part of a broader scrutiny of data privacy practices in the healthcare sector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Azienda USL Della Romagna in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What specific violations did IQVIA commit?
How many patients were affected by this violation?
What actions did the Italian Data Protection Authority take?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…