Østfold HF Hospital

€112,000

Insufficient technical and organisational measures to ensure information security

결정 날짜

2020년 6월 22일

권한

Norwegian Supervisory Authority (Datatilsynet)

NO

섹터

Health Care

국가

NO

법률

GDPR

상태

FINAL

설명

It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling access to the folders where the data was stored. Datatilsynet therefore decided that the hospital had not taken sufficient technical and organisational measures to protect personal data and was therefore in breach of the GDPR and the Patient Records Act.

법적 인용

Art. 32

문제 및 위반 사항

Insufficient technical and organisational measures to ensure information security

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.