Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million (approximately $7.8 million) for inadequate data-processing practices that potentially exposed the personal information of about one million patients, according to a recent report by Bleeping Computer.
The investigation by Italian authorities revealed that IQVIA's Italian division created a database containing health information from approximately one million patients, aggregated from 800 general practitioners. While the company used unique codes instead of names, the GPDP found these codes, combined with detailed personal information such as birth year, sex, diagnoses, symptoms, prescriptions, and location data, could be used to re-identify individual patients. Furthermore, IQVIA processed this data without a proper legal basis or patient consent, violating GDPR. The company also failed to implement data retention periods, with records dating back to 2001. For a subset of 3,300 patients, IQVIA included names, tax identification numbers, addresses, and contact details. In addition to the fine, IQVIA has been ordered to comply with data protection regulations within 120 days.
Source: Bleeping Computer
