[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQBF7WqWkEBv3E4HmbYE_DMazxom0zdbpKZI79cMHr4s":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"5e0629bd-aac3-4e21-93ce-3a2ef5103502","iqvia-fined-5m-for-failed-patient-data-anonymisation","25c21f50-64ff-4c94-a83c-730a2529eb97","IQVIA Fined €5M for Failed Patient Data Anonymisation","IQVIA Operations France failed to properly anonymise patient data in their pharmacy and medical records systems, allowing individuals to be re-identified despite pseudonymisation efforts. The company also failed to adequately inform patients about how their data was being processed. This breach demonstrates that inadequate data protection controls can lead to significant regulatory fines and expose sensitive health information. Proper anonymisation requires robust technical measures beyond simple pseudonymisation to prevent re-identification attacks.","**Immediate actions:**\n- Conduct comprehensive review of all patient data anonymisation procedures\n- Implement additional technical safeguards to prevent re-identification of pseudonymised data\n- Update patient consent forms and privacy notices to ensure GDPR compliance\n\n**Long-term improvements:**\n- Establish regular privacy impact assessments for all health data processing activities\n- Implement data minimisation principles to limit collection and retention of personal health information\n- Create ongoing staff training programs on GDPR requirements and health data protection\n\n**Monitoring measures:**\n- Deploy automated tools to detect potential re-identification risks in anonymised datasets\n- Establish regular audits of data processing activities and patient consent records",[12,13,14,15,16,17],"GDPR Article 5","GDPR Article 25","GDPR Article 32","NIST Privacy Framework","CIS Control 3","CIS Control 14","published","2026-06-03T10:20:15.14984+00:00","2026-06-03T10:20:15.047+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CNIL_(France)_-_SAN-2026-008&diff=51804&oldid=51791","cnil-france-san-2026-008-ee2bfe","CNIL (France) - SAN-2026-008",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":33,"name":34,"slug":35,"description":36,"color":37},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]