IQVIA fined $7.8 million for failing to properly anonymize health data
Italy's data protection authority fined IQVIA €7 million after finding that the company's anonymization practices were inadequate, leaving roughly one million patients at risk of being re-identified from their health data.
Why this matters: Health data is about as personal as data gets. When a company processes it at scale and fails to properly anonymize it, real people face real exposure — not just embarrassment, but potential discrimination, insurance consequences, and loss of medical privacy they never agreed to sacrifice. IQVIA is a major player in pharmaceutical data and health analytics. That makes this a systemic issue, not a one-off. The fine signals that regulators are paying attention to re-identification risk, not just obvious data leaks. Whether €7 million is enough to change how a company this size handles patient data is a separate question worth asking.
Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · AI governance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.