Østfold HF Hospital

€112,000

Insufficient technical and organisational measures to ensure information security

Sprendimo priėmimo data

2020 m. birželio 22 d.

Institucija

Norwegian Supervisory Authority (Datatilsynet)

NO

Sektorius

Health Care

Šalis

NO

Teisė

GDPR

Statusas

FINAL

Aprašymas

It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling access to the folders where the data was stored. Datatilsynet therefore decided that the hospital had not taken sufficient technical and organisational measures to protect personal data and was therefore in breach of the GDPR and the Patient Records Act.

Teisinės citatos

Art. 32

Problemos ir pažeidimai

Insufficient technical and organisational measures to ensure information security

Gaukite naujausią informaciją apie privatumo vykdymo užtikrinimą

Gerbiame jūsų privatumą. Vienas el. laiškas per mėnesį, jokių šlamšto, atsisakykite prenumeratos bet kada.