Azienda sanitaria unica regionale Marche

€14,000

Insufficient technical and organisational measures to ensure information security

Lēmuma datums

2022. gada 13. janvāris

Iestāde

Italian Data Protection Authority (Garante)

IT

Nozare

Health Care

Valsts

IT

Likums

GDPR

Statuss

FINAL

Apraksts

The Italian DPA has imposed a fine of EUR 14,000 on Azienda sanitaria unica regionale Marche. The DPA launched an investigation against the health department following media reports of deficiencies in the system used to collect and manage Covid 19 screening data. The health department used an app that generated QR codes for people who were tested for Covid-19. The QR code was generated based on a progressive criterion rather than on a random basis. Thus, each person was assigned a number. Because of this, it would have been possible for unauthorized persons to change a digit and gain access to another person's profile and thus personal data. The DPA found that the health authority failed to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk to the data subjects.

Juridiskās atsauces

Art. 5 (1)Art. 32Art. 35

Jautājumi un pārkāpumi

Insufficient technical and organisational measures to ensure information security

Atjauniniet informāciju par konfidencialitātes ieviešanu

Mēs respektējam jūsu konfidencialitāti. Viens e-pasts mēnesī, bez surogātpasta, jebkurā laikā varat atteikties no abonēšanas.