Italy’s Data Protection Authority fined IQVIA Solutions Italy Srl €7 million for unlawfully processing health information concerning approximately one million patients of 800 general practitioners. The authority found that data described as anonymous allowed patients to be tracked and potentially re-identified, while the database contained explicit identifying information for more than 3,300 patients. The investigation followed inspections in April 2025 and included proceedings concerning a personal data breach reported by IQVIA.
The authority found that IQVIA lacked an appropriate legal basis, adequate patient information, defined retention periods, a data protection impact assessment, and adequate security measures. IQVIA must bring its processing into compliance within 120 days if it wishes to continue; alternatively, physicians must independently anonymize the data under the authority’s safeguards. The ruling underscores the need for healthcare data processors to validate anonymization against tracking and re-identification risks rather than rely on claims that a dataset is anonymous.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
The authority adopted provision no. 710, imposing a €7 million fine after finding that supposedly anonymous patient data could enable re-identification and that the database contained explicit identifiers for more than 3,300 patients. It found deficiencies in legal basis, patient information, retention, impact assessment and security, and ordered compliance within 120 days if processing continued, or independent anonymization by physicians under specified safeguards.
Inspections carried out in April 2025 were followed by an investigation into IQVIA's processing of patient health information.
Physicians stopped transmitting data to IQVIA starting in 2023. The Italian Data Protection Authority later considered this cessation when determining its fine.
IQVIA notified a personal data breach to the Italian Data Protection Authority. Proceedings concerning that breach were included in the authority's investigation.
IQVIA Solutions Italy Srl created a database containing health information concerning one million patients of 800 general practitioners. It used the database for studies commissioned by pharmaceutical companies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.