Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #7
IQVIA fined millions after health data 'anonymization' fails GDPR test
Original: A healthcare company fined for thinking a secret code = anonymization. Narrator: it didn't. # DataPrivacy # GDPR # InfoS
Healthcare data company IQVIA has been fined 7.8 million euros after regulators found it failed to properly anonymize health data, wrongly treating coded data as anonymous. Commentators in the privacy and security community are highlighting the case as a warning that pseudonymized data is still personal data under GDPR, and a reminder that companies cannot simply assume coded health records fall outside data protection law.
Why now: The sizable fine and the mistaken belief that coded data counts as anonymization make it a cautionary tale for anyone handling health data under GDPR.
IQVIAGDPRItalian data protection authorityhealthcare sector
Evidence
- A healthcare company fined for thinking a secret code = anonymization. Narrator: it didn't. # DataPrivacy # GDPR # InfoSec # Healthcare # DataBreach https://www. bleepingcomputer.com/news/secu rity/iqvia-fined-78-million-for-failing-to-properly-anonymize-health-data/ · Javvad@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1150960