Haga Hospital

€350,000

Insufficient technical and organisational measures to ensure information security

Data decyzji

18 czerwca 2019

Władza

Dutch Supervisory Authority for Data Protection (AP)

NL

Sektor

Health Care

Kraj

NL

Prawo

GDPR

Status

FINAL

Opis

Original Fine Summary: The Haga Hospital does not have a proper internal security of patient records in place. This is the conclusion of an investigation by the Dutch Data Protection Authority. This investigation followed when it appeared that dozens of hospital staff had unnecessarily checked the medical records of a well-known Dutch person. To force the hospital to improve the security of patient records, the AP simultaneously imposes an order subject to a penalty. If the Haga Hospital has not improved security before 2nd of October 2019, the hospital must pay EUR 100,000 every two weeks, with a maximum of EUR 300,000. The Haga Hospital has meanwhile indicated to take measures. Update: The fine was reduced from EUR 460,000 to EUR 350,000 following a court ruling in 2021.

Cytaty prawne

Art. 32

Problemy i naruszenia

Insufficient technical and organisational measures to ensure information security

Bądź na bieżąco z egzekwowaniem przepisów dotyczących prywatności

Szanujemy Twoją prywatność. Jeden e-mail miesięcznie, bez spamu, zrezygnuj z subskrypcji w dowolnym momencie.