Østfold HF Hospital

€112,000

Insufficient technical and organisational measures to ensure information security

Data deciziei

22 iunie 2020

Autoritatea

Norwegian Supervisory Authority (Datatilsynet)

NO

Sector

Health Care

Țara

NO

Legea

GDPR

Statut

FINAL

Descriere

It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling access to the folders where the data was stored. Datatilsynet therefore decided that the hospital had not taken sufficient technical and organisational measures to protect personal data and was therefore in breach of the GDPR and the Patient Records Act.

Citări juridice

Art. 32

Probleme și încălcări

Insufficient technical and organisational measures to ensure information security

Rămâneți la curent cu aplicarea normelor de confidențialitate

Îți respectăm confidențialitatea. Un e-mail pe lună, fără spam, dezabonare oricând.