OLVG

€440,000

Insufficient technical and organisational measures to ensure information security

Ημερομηνία απόφασης

11 Φεβρουαρίου 2021

Αρχή

Dutch Supervisory Authority for Data Protection (AP)

NL

Τομέας

Health Care

Χώρα

NL

Νόμος

GDPR

Κατάσταση

FINAL

Περιγραφή

The Dutch DPA (AP) imposed a fine of EUR 440,000 on the Amsterdam hospital OLVG. The controller had taken insufficient measures between 2018 and 2020 to prevent access by unauthorized employees to medical records. The controller did not check adequately who had access to which file nor did the controller ensure that the computer system presented sufficient security. This resulted, among others, in working students and other employees being able to access patient files without this being necessary for their work. Besides medical records, the patient files also contained, the social security numbers, addresses and telephone numbers of the data subjects.

Νομικές παραπομπές

Art. 32

Θέματα & Παραβάσεις

Insufficient technical and organisational measures to ensure information security

Μείνετε ενημερωμένοι για την επιβολή του απορρήτου

Σεβόμαστε την ιδιωτικότητά σας. Ένα email ανά μήνα, χωρίς spam, διαγραφή ανά πάσα στιγμή.