Azienda sanitaria universitaria Friuli Occidentale

€50,000

Insufficient technical and organisational measures to ensure information security

결정 날짜

2022년 5월 26일

권한

Italian Data Protection Authority (Garante)

IT

섹터

Health Care

국가

IT

법률

GDPR

상태

FINAL

설명

The Italian DPA imposed a fine of EUR 50,000 on the healthcare facility Azienda sanitaria universitaria Friuli Occidentale. Employees of the healthcare facility had accessed patients' health data even though they were not involved in the treatment of the patients and such access was not required. During its investigation, the DPA found that the healthcare facility's IT platform allowed any employee to access patients' personal data, even if they did not actually treat certain patients. In addition, the DPA found that the health care facility's IT platform did not install systems that indenfied improper use of the personal data.

법적 인용

Art. 5 (1)Art. 9Art. 25Art. 32

문제 및 위반 사항

Insufficient technical and organisational measures to ensure information security

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.