Security2 publishers2 min readPublished
Italy's privacy regulator fines IQVIA 7 million euros over re-identifiable patient codes
Italy's privacy regulator fined IQVIA 7 million euros after finding coded records on about one million patients could be traced back to individuals. Teams that pool health records under one persistent patient key now have a regulator's written reasoning for why removing names fell short.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- IQVIA's Italian division built the database from records supplied by 800 general practitioners, with a unique code in place of each patient's name.
- For a subset of 3,300 patients, the records also held names, tax identification numbers, addresses and contact details.
- The regulator found IQVIA processed the data without an appropriate legal basis and without informing patients, in breach of the GDPR.
- The GPDP ordered IQVIA to bring its practices into compliance within 120 days.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction IQVIA lists pseudonymization among its core safeguards, and the GPDP found this pseudonymized dataset re-identifiable by reasonable means; any appeal has to contest that reading.
- decision Teams pooling longitudinal health data have to measure re-identification on everything left after names come out, including birth year, sex, location and prescription history, before calling it anonymous.
- cost At about 7 euros per patient, the fine covers the legal-basis, notice, retention and named-record findings as well as the code, so it does not set a price for a weak pseudonym on its own.
The patient code never changed. Each new record joined the patient's earlier ones, and the GPDP found the records could be used to track and de-anonymize people over time [3]. "The code associated with each patient made it possible to track them over time," the authority said in its announcement [4]. It described the exposure as a risk to roughly one million patients [1].
The GPDP's reasoning paired the code with the fields stored beside it: year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data [5]. Combined, the authority said, "it made it possible to single out individual patients and, using reasonable means, reidentify them" [5].
Retention made each track longer. IQVIA set or followed no data retention periods, the GPDP found, and its records went back as far as 2001 [7]. The oldest were at least 24 years old when the investigation opened in April 2025 [11][16].
IQVIA's spokesperson told BleepingComputer that "we maintain robust safeguards, including the use of pseudonymization and encryption, to support responsible data use in healthcare" [12]. The company "reserves the right to appeal," the statement said [13]. It also said it has "already taken steps to adopt the measures necessary to ensure full alignment with the Authority's guidance" [15]. On scope, the spokesperson said the dataset "is not used by IQVIA in conduct of clinical research services and does not relate to the conduct of clinical trials on behalf of the sponsors" [14].
The case is one authority's decision about one database [11][2]. As reported, the GPDP found that this code, combined with these fields, did not meet the anonymization IQVIA claimed for it [11][5]. The report does not describe other European regulators adopting the same reading. It is one enforcement decision against one dataset built a particular way.
The decision covers IQVIA's Italian division [2]. Its roughly one million patients are about 0.08 percent of the 1.2 billion patient records the company says it handles in more than 100 countries [10][18].
What to watch
- Whether IQVIA files the appeal it says it reserves, which would put the GPDP's reasonable-means reading of a coded dataset in front of a court.
- What IQVIA changes in the Italian database inside the 120-day window, in particular retention limits on records reaching back to 2001 and the persistent patient code.
- Whether other EU data protection authorities apply the same reasoning to pooled primary-care datasets keyed on a stable patient code.