Compliance · · 4 min read
Italy orders IQVIA to pay €7m over patient database
Italy’s privacy regulator says IQVIA treated identifiable health information as anonymous after collecting records from about one million patients.
Italy’s data protection authority has ordered IQVIA Solutions Italy to pay €7 million over a database containing health information from about one million patients. The Garante adopted the decision on September 23, 2026, and published it on October 2, according to reporting by ppc.land.
The Milan-based subsidiary of IQVIA Holdings had described the material as de-identified. The regulator disagreed, finding that patients retained a persistent code alongside diagnoses, prescriptions, examinations and location information. In the Garante’s view, that combination meant people could still be distinguished and tracked over time, so the records remained personal data.
IQVIA has 120 days to establish a lawful basis for continuing to use the information and provide the required information to patients. If it cannot do so, the company must transfer the anonymisation process to the doctors supplying the records. The decision can still be challenged in court.
How the database was built
The case concerns IQVIA’s Longitudinal Patient Data database, known as LPD. It was developed through Health Search, a project associated with the Italian Society of General Practitioners and Primary Care, or SIMG. The initiative aimed to improve the use of coded clinical records, create a nationwide network of participating doctors and support research into primary care.
Participating practices used the same practice-management software. An add-on commissioned by IQVIA extracted information from that software and sent it onward. Doctors received the software subscription without charge, while IQVIA paid the vendor. Their agreements required them to supply accurate data on an ongoing basis for statistical, epidemiological and market research carried out for public and private organisations.
The information initially entered a temporary staging database. From there, one stream was sent to SIMG twice a year for scientific work. Another was converted into IQVIA’s internal format, subjected to additional safeguards and placed in the LPD data warehouse. Pharmaceutical companies used the warehouse for retrospective observational studies, with the resulting work delivered as aggregated reports.
The database included demographic details, prescriptions, diagnoses, examinations and visit counts. IQVIA told inspectors that it covered more than one million patients treated by about 800 general practitioners. A European Medicines Agency catalogue instead describes a Health Search/IQVIA database involving approximately 1,000 doctors, making the scale depend on which source is used.
Why the patient code mattered
At the heart of the regulator’s reasoning was the Pat ID, a unique identifier generated by the software add-on. IQVIA said it was a randomly created UUID that doctors could not view in their applications. The database was password-protected, and dates of birth were generally replaced with the first day of the relevant month.
Those measures did not satisfy the Garante because the identifier was designed to remain stable. It allowed records belonging to the same person to be connected across years, preserving the longitudinal value that made the database useful for research and commercial studies. IQVIA told inspectors that the code could change if a patient moved to another doctor or if a practice replaced its computer, but maintained that the dataset remained valuable despite those events.
The decision describes a presentation showing one patient appearing 34 times in the prescriptions table. That example demonstrated how the information could be assembled into an individual clinical history, even without a name attached to the records.
The authority also noted differing descriptions of the safeguards applied to the data. In one account, IQVIA referred to reducing age information to the month of birth and removing the city. In a later submission, it said the add-on sent only the month and year of birth, did not send a patient’s address and reduced the doctor’s address to the province.
Responsibility for the data pipeline
The Garante held IQVIA responsible from the point at which information left the doctors’ computers. The company had commissioned the extraction software and supplied the instructions governing the transfer, meaning it could not avoid responsibility by treating the output as anonymous.
The database originated before IQVIA’s involvement. SIMG and the Health Search association conceived the project, then transferred an early version to a company in the French Cegedim group. The assets later moved through IMS Health entities before reaching the company now known as IQVIA Solutions Italy. The published decision records conflicting accounts of when IQVIA became involved: one company statement said 2015, while another placed the takeover of the database in 2017. The Garante’s assessment treated the processing as beginning in 2015.
The regulator’s action followed inspections carried out in April 2025, although the decision itself redacts the inspection dates. A separate proceeding, opened after IQVIA reported a personal-data breach, was later combined with the case. Doctors stopped sending new information in 2023, but the database continued to support existing and new studies on a reduced basis, according to the Garante’s account.
The ruling therefore reaches beyond one medical database. It warns organisations that removing names is not necessarily enough when records retain stable identifiers and detailed health histories. Companies that design and operate data-collection systems may remain accountable for how information is classified and used, even when the records are presented as anonymised.