The news
Italy's data protection authority said on October 2 it fined the Italian unit of IQVIA (IQV) €7 million, about $7.8 million, over health data the company treated as anonymous but that could identify patients. The IQVIA fine lands as attackers keep hitting U.S. medical organizations.
According to the authority, known as the Garante, IQVIA Solutions Italy built a database on about one million patients using records from 800 general practitioners. Names were replaced with codes, but the regulator found each code let the company follow a patient over time. Combined with details such as year of birth, sex, diagnoses, prescriptions, tests, vaccinations and location, BleepingComputer reported, the data could single out individuals. For 3,300 patients, the database also held names, tax ID numbers and addresses.
The Garante also found no valid legal basis for the processing, inadequate notice to patients, no defined retention period for data going back to 2001, no data protection impact assessment and insufficient security. It gave the company 120 days to comply. IQVIA said it acknowledges the decision and reserves the right to appeal, according to BleepingComputer.
In Chicago, the University of Illinois Chicago's College of Medicine, which has about 1,300 students, was hit by ransomware that temporarily took some systems offline, The Record reported on October 5. A group called Booba claimed to have stolen 344 gigabytes. The university said in a statement to The Record that affected systems were restored, its main network was not affected and patient care at UI Health was not affected. It is still investigating whether personal, research or academic information was compromised.
Two more U.S. breaches now appear on the federal HHS breach portal, SecurityWeek reported on October 5. Clover Health Investments (CLOV) said in a July 17 filing that it found anomalous logins on July 4, after social engineering compromised three non-managerial employee accounts used for scheduling and broker sales. The portal lists 138,677 people affected, according to SecurityWeek and The HIPAA Journal.
AngMar Management Services of Mansfield, Texas, which supports home health and hospice providers, says in its notice letter that it spotted unusual network activity on July 20 and that data may have been accessed or taken on or around July 18. The data may include Social Security numbers, diagnoses, prescriptions and medical histories. The portal lists 126,196 people, and the Interlock ransomware group claimed in August to have taken more than 700 gigabytes, SecurityWeek reported.
The numbers
- Garante fine on IQVIA Solutions Italy
- €7 million (about $7.8 million)
- Patients in IQVIA's Italian database
- About 1 million
- General practitioners supplying the data
- 800
- Patients whose records also held names and tax IDs
- 3,300
- Days IQVIA has to comply
- 120
- Data the Booba group claims it took from UIC
- 344 GB
- Clover Health breach, people affected (HHS portal)
- 138,677
- AngMar breach, people affected (HHS portal)
- 126,196
Why CEOs should care
For chief data officers and buyers of health data, the Garante's reasoning is the warning. Swapping names for a code that stays the same over time, then attaching rich clinical detail, did not make the data anonymous in the regulator's view. Ask vendors and internal teams how de-identification is tested, whether codes are stable across years, whether a data protection impact assessment exists and how long records are kept. Records going back to 2001, held with no retention rule, were part of this finding.
For CISOs at providers and health plans, the breaches show where pressure lands. At Clover Health, attackers did not need executives; they tricked staff who handle scheduling and broker sales and whose accounts could reach member data. Limit what front-line accounts can see, require phishing-resistant multifactor authentication and alert on unusual logins. AngMar shows the vendor side: a management services firm held Social Security numbers and medical histories, so ask which outside firms hold your patient data and how fast they would report an incident.
For CFOs and boards, health data now carries two kinds of cost. One is regulatory, a fine plus a 120-day remediation order. The other is the breach bill: forensic work, notification letters and, at AngMar, 12 months of free credit monitoring. A useful board question is whether the company's own 'anonymous' datasets would pass the test Italy just applied.
The bigger picture
The two pressures meet at the same asset. Patient records are valuable to analytics firms, drug makers and researchers, which is why companies like IQVIA collect them, and the same detail makes them attractive to ransomware groups that profit from data theft and leak threats. Regulators are narrowing what counts as anonymous at the same moment attackers are widening the ways in, from social engineering to third-party administrators.
Academic medical centers sit in the middle, holding research data, teaching systems and links to hospitals. UIC's statement drew a line between College of Medicine systems and UI Health patient care, a reminder that separating clinical networks from research and teaching networks can limit the damage when one side is hit.
What’s next
Watch whether IQVIA appeals before its 120-day compliance window closes, and whether other European regulators apply the same test to coded health data. UIC has said it plans to notify affected individuals once its review ends, and the HHS Office for Civil Rights may examine the Clover Health and AngMar filings.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





