Clinic – Fine (Germany, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A clinic in Germany sent an unredacted report about a patient's psychiatric treatment to an insurance company without proper legal grounds. This breach of privacy is significant because it shows the need for strict rules when sharing sensitive health information. No fine was applied, but the incident raises awareness about patient confidentiality.
What happened
The clinic transmitted an unredacted psychiatric treatment report to an insurance fund without a valid legal basis.
Who was affected
The patient whose psychiatric treatment report was shared without consent.
What the authority found
The DPA found that the clinic did not have a valid legal basis for sharing the patient's sensitive information.
Why this matters
This ruling highlights the importance of protecting sensitive health information and ensuring that consent is obtained before sharing such data. Clinics and healthcare providers should strengthen their data sharing protocols.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The DPA of Bremen has imposed a fine on a clinic for transmitting an unredacted treatment report on the psychiatric treatment of the data subject to an accident insurance fund without a valid legal basis.
Related Enforcement Actions (1)
Other enforcement actions involving Clinic in DE
Details
Fine Date
1 January 2023
Authority
Bundesbeauftragter für den Datenschutz
Enforcement Tracker ID
ETid-2237
About this data
Cite as: Cookie Fines. Clinic - Germany (2023). Retrieved from cookiefines.eu
Last updated: