IQVIA fined $7.8M for improper health data practices
Italy’s privacy regulator has fined IQVIA $7.8 million for failing to properly anonymize the health data of about one million patients. Investigators found IQVIA’s database, built from information collected by 800 doctors, could be used to reidentify individuals despite the use of coded records. Regulators also said some records were kept with no set retention period and included sensitive details, violating EU data rules. IQVIA plans to appeal.
- Roughly one million patient records were exposed to reidentification risk
- Some records included names, IDs, addresses and contacts
- Data spanned from 2001 with no set deletion policy
- IQVIA was ordered to change practices within 120 days
Sources covering this
More in Cybersecurity
ClingSTUN malware exploits IoT vulnerabilities as stealth proxy network
A new Linux malware, called ClingSTUN or Cling, is turning unpatched and vulnerable internet-facing IoT devices into remote-controlled…
CrowdStrike launches Falcon Data Security for SaaS in Microsoft 365
CrowdStrike has announced general availability of Falcon Data Security for SaaS, a new product that secures sensitive data within…
Meta fixed major security flaw in Muse AI before launch
Meta engineers identified and urgently fixed several security vulnerabilities in its Muse AI agent just weeks before launch, according…
Dell System Update flaw exposes servers to remote code execution
Dell has alerted customers to a critical security flaw in its System Update tool for PowerEdge servers, which could allow remote…