Public Hospital

€400,000

Insufficient technical and organisational measures to ensure information security

Data della decisione

17 luglio 2018

Autorità

Portuguese Data Protection Authority (CNPD)

PT

Settore

Health Care

Paese

PT

Legge

GDPR

Stato

FINAL

Descrizione

Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management system appeared deficient – the hospital had 985 registered doctor profiles while only having 296 doctors. Moreover, doctors had unrestricted access to all patient files, regardless of the doctor’s specialty.

Citazioni legali

Art. 5 (1)Art. 32

Problemi e violazioni

Insufficient technical and organisational measures to ensure information security

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.