Østfold HF Hospital

€112,000

Insufficient technical and organisational measures to ensure information security

Date de décision

22 juin 2020

Autorité

Norwegian Supervisory Authority (Datatilsynet)

NO

Secteur

Health Care

Pays

NO

Droit

GDPR

Statut

FINAL

Description

It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling access to the folders where the data was stored. Datatilsynet therefore decided that the hospital had not taken sufficient technical and organisational measures to protect personal data and was therefore in breach of the GDPR and the Patient Records Act.

Citations légales

Art. 32

Questions et violations

Insufficient technical and organisational measures to ensure information security

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.