Security & AI news

Health data and pseudonymisation · By FireAI Security & Research Team · Published

Italy’s data protection authority fines IQVIA €7 million, finding that GP patient data it called anonymous could be re-identified

The Garante says coded records of about one million patients from 800 GPs could single people out. IQVIA reserves the right to appeal; CNIL found the same in May.

A database motif and the PrivateAI mascot, next to the words “Coded is not anonymous.”

Italy’s data protection authority, the Garante, has fined IQVIA Solutions Italy €7 million over a database holding the health information of roughly one million patients collected from 800 general practitioners, BleepingComputer reported on 5 October 2026. The authority rejected the company’s position that the records were anonymous [1]. IQVIA says it reserves the right to appeal [1]. The case shows how records that leave a professional’s office under a code can still identify the people behind them.

Background

Under the GDPR, anonymous data falls outside data protection rules, while pseudonymised data, in which names are replaced by a code but people can still be re-identified by reasonable means, remains personal data. IQVIA is a multinational company that provides healthcare data analysis, technology and clinical research services [1]. According to Il Sole 24 Ore, the dataset was used for studies commissioned by pharmaceutical companies [2].

What the authority found

The Garante wrote that “the code associated with each patient made it possible to track them over time” and that, combined with “a very detailed set of information (year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to single out individual patients and, using reasonable means, reidentify them” [1]. For a subset of 3,300 patients the database also held names, tax identification numbers, addresses and contact details [1].

The authority also found that the data was processed without an appropriate legal basis and without informing patients, and that no retention periods were set, with records dating back to 2001 [1]. Il Sole 24 Ore adds that, according to the authority, no data protection impact assessment was carried out and no adequate security measures were in place, and that the investigation followed inspections in April 2025 [2] [1]. IQVIA has 120 days to bring its processing into line; failing that, the anonymisation must be carried out by the doctors themselves [2].

In a statement to BleepingComputer, IQVIA said it maintains “robust safeguards, including the use of pseudonymization and encryption”, that the dataset “is not used by IQVIA in conduct of clinical research services”, and that it has already taken steps to align with the authority’s guidance [1]. The president of Italy’s federation of medical orders, Filippo Anelli, said the doctors involved bore no responsibility and that “patients were unaware that their data had not been redacted” [2].

The Italian decision follows a €5 million fine imposed by France’s CNIL on IQVIA Operations France on 26 May 2026 and announced on 28 May. The CNIL likewise found that data the company presented as anonymous was “only pseudonymous, as the re-identification of the data subjects was possible using reasonable means” [3].

Implications for professionals

The doctors in this case supplied the data; the authority’s findings are against the company. For any professional bound by secrecy, whether a doctor, a lawyer, a notary or an accountant, the decision illustrates a general point: replacing a name with a code does not make a record anonymous when the remaining details are rich enough to single a person out. Once confidential records are passed to a third party, their protection depends on that party’s practices, which the professional does not control. Patients in Italy whose doctors contributed data were, according to the federation’s president, unaware of how it was handled.

Recommendations

  1. Treat coded or pseudonymised client records as personal data unless re-identification is genuinely impossible by reasonable means.
  2. Before sharing records with a vendor or research partner, ask what legal basis, retention period and security measures apply.
  3. Keep an inventory of the software that sends client files outside the office, including AI tools and data-sharing plug-ins.
  4. Inform clients or patients when their data is passed on, as the authority found was not done here.

Relevance to PrivateAI

PrivateAI 1.0.0 runs its AI model on the Mac with no cloud fallback and no telemetry, and none of its four network uses, a one-time model download, licence checks, update checks and opening a payment page, sends a document, a prompt or a result. It summarises, translates and drafts from contracts, deeds and accounts, and checks every amount, date and reference against the original. PrivateAI does not anonymise or pseudonymise data, does not decide whether data may be shared, and does not control what happens to files a user sends elsewhere. HisnLabs makes no claim that PrivateAI satisfies any legal or professional rule. Purchase is not open yet.

Limitations

The Garante’s decision itself was not reviewed here; this item relies on BleepingComputer’s and Il Sole 24 Ore’s reports, which quote the authority’s announcement and IQVIA’s statement [1] [2]. IQVIA may appeal, and the findings could be revised. The reports do not say whether any patient was in fact re-identified, only that re-identification was possible by reasonable means.

To work on confidential documents with an AI model that stays on the Mac, download PrivateAI and try every feature free for 17 days. PrivateAI is made by HisnLabs.

Sources

  1. BleepingComputer, 5 October 2026: IQVIA fined $7.8 million for failing to properly anonymize health data
  2. Il Sole 24 Ore (English edition), 3 October 2026: Health data of one million patients exposed; Iqvia faces a fine of 7 million
  3. CNIL, 28 May 2026: Health data: fine of 5 million euros against IQVIA