I work in the Life Sciences sector and know a little about how patient data is handled. Most companies follow the guidelines set up by the US known as
HIPAA. These are pretty much the toughest guidelines out there and also the biggest single pharmaceutical market. There are of course regional variations (for example personal data from Belgium cannot leave the EU) but they mostly follow the HIPAA model.
Trust me, the penalties for HIPAA violations are harsh. Violators risk huge fines, emprisonment and potential closure of a countries market. The facility that handles patient data is incredibly secure!
Also, patient data is shared with pharmaceutical companies now with Adverse Drug Reporting and the like.