Østfold HF Hospital

€112,000

Insufficient technical and organisational measures to ensure information security

Data della decisione

22 giugno 2020

Autorità

Norwegian Supervisory Authority (Datatilsynet)

NO

Settore

Health Care

Paese

NO

Legge

GDPR

Stato

FINAL

Descrizione

It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling access to the folders where the data was stored. Datatilsynet therefore decided that the hospital had not taken sufficient technical and organisational measures to protect personal data and was therefore in breach of the GDPR and the Patient Records Act.

Citazioni legali

Art. 32

Problemi e violazioni

Insufficient technical and organisational measures to ensure information security

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.