Italy’s privacy regulator has fined healthcare data company IQVIA €7 million after concluding that a database containing information on around one million patients was not properly anonymized.

 

 

IQVIA Solutions Italy built the database using information collected from approximately 800 general practitioners. The data was used for healthcare studies, including research commissioned by pharmaceutical companies.

Patients’ names were replaced with unique codes, which IQVIA considered sufficient to make the information anonymous. Italy’s Data Protection Authority disagreed, finding that each code remained associated with the same person and could therefore be used to follow an individual’s medical history over time.

The risk increased because the database contained extensive information about each patient. Records could include year of birth, sex, diagnoses, symptoms, prescriptions, medical tests, vaccinations and location information.

Regulators concluded that combining these details could make it possible to isolate individual patients and potentially reidentify them using reasonable means. As a result, the information remained personal health data protected by European privacy law rather than truly anonymous information outside the GDPR.

The investigation also uncovered directly identifying information belonging to more than 3,300 patients, including names, Italian tax identification numbers, addresses and contact details. More than 3,000 of those records were accompanied by health information.

Authorities identified several other privacy problems. IQVIA allegedly processed health information without an appropriate legal basis, failed to adequately inform patients and had not established proper retention periods. Some records dated back to 2001.

The regulator also found that IQVIA had not completed the required data protection impact assessment and had failed to implement sufficient security measures.

IQVIA must bring its processing practices into compliance within 120 days if it intends to continue the activity. Alternatively, doctors supplying the information would have to independently anonymize patient data under safeguards established by the regulator.

IQVIA said protecting data remains a priority and pointed to safeguards including pseudonymization and encryption. The company is continuing to cooperate with the regulator but has reserved the right to appeal the decision.

The company also stressed that the database involved in the case is not used for its clinical research services or clinical trials conducted for sponsors.

Leave a Reply