Italy's data protection authority, the Garante, said it fined IQVIA Solutions Italy 7 million euros. BleepingComputer put that at about $7.8 million. The authority said the company built a database with health details of one million patients from 800 family doctors. IQVIA had called the data anonymous. The Garante disagreed. It said each patient's code let the company follow that person over time. Combined with birth year, sex, diagnoses, prescriptions and location, it said patients could be singled out and identified by reasonable means. The decision is dated 23 September 2026 and followed inspections in April 2025.
The Garante also said IQVIA had no proper legal basis, did not inform patients properly and set no retention limits. Some data dated to 2001. It said the company skipped an impact assessment and had weak security. The database held names, tax codes and addresses for more than 3,300 patients. IQVIA has 120 days to fix its processing if it wants to continue. Doctors stopped sending data in 2023. IQVIA told BleepingComputer it reserves the right to appeal, and says it has begun taking corrective steps. It is not yet clear whether it will appeal, or whether anyone actually identified a patient.
Swapping names for a code does not make data anonymous in the eyes of this regulator. Teams that build, run or buy health-data products should check whether codes plus detailed records could point back to a person.