Doctor´s Office

€2,500

Insufficient technical and organisational measures to ensure information security

Ημερομηνία απόφασης

1 Ιανουαρίου 2024

Αρχή

Data Protection Authority of Hessen

DE

Τομέας

Health Care

Χώρα

DE

Νόμος

GDPR

Κατάσταση

FINAL

Περιγραφή

The DPA of Hessen has imposed a fine of EUR 2,500 on a doctor´s office. The controller hired an office manager who worked partly from home. The manager worked with patient files, which he stored at home. However, he did not lock or otherwise secure the files, which resulted in guests and family members having access to them. On one occasion, the manager asked his wife to send him photos of some files via a private messaging service because he had left them in his car, which his wife was using for a long trip.

Νομικές παραπομπές

Art. 5 (1)Art. 6 (1)Art. 9 (1)Art. 32

Θέματα & Παραβάσεις

Insufficient technical and organisational measures to ensure information security

Μείνετε ενημερωμένοι για την επιβολή του απορρήτου

Σεβόμαστε την ιδιωτικότητά σας. Ένα email ανά μήνα, χωρίς spam, διαγραφή ανά πάσα στιγμή.