Cork University Maternity Hospital
€65,000
Insufficient technical and organisational measures to ensure information security
Decision Date
August 18, 2020
Authority
Data Protection Authority of Ireland
IE
Sector
Health Care
Country
IE
Law
GDPRStatus
FINALDescription
The „Data Protection Authority of Ireland“ imposed a fine on Cork University Maternity Hospital (CUMH) after the personal data of 78 patients was discovered disposed of in a public recycling center. Among the documents disposed of, some contain special category personal data of six patients. It is believed that the breach at CUMH involves sensitive patient health data such as the medical history and future planned care programs.
Legal Citations
Art. 5Art. 32
Issues & Violations
Insufficient technical and organisational measures to ensure information security