Østfold HF Hospital

€112,000

Insufficient technical and organisational measures to ensure information security

Határozat dátuma

2020. június 22.

Hatóság

Norwegian Supervisory Authority (Datatilsynet)

NO

Szektor

Health Care

Ország

NO

Törvény

GDPR

Állapot

FINAL

Leírás

It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling access to the folders where the data was stored. Datatilsynet therefore decided that the hospital had not taken sufficient technical and organisational measures to protect personal data and was therefore in breach of the GDPR and the Patient Records Act.

Jogi hivatkozások

Art. 32

Kérdések és jogsértések

Insufficient technical and organisational measures to ensure information security

Maradjon naprakész az adatvédelem érvényesítésével kapcsolatban

Tiszteletben tartjuk a magánéletét. Havonta egy e-mail, nincs spam, bármikor leiratkozhat.