Aleris Sjukvård AB – €1,463,000 Fine (Sweden, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Sweden fined Aleris Sjukvård AB for not properly securing patient data. The company didn't limit access to sensitive information, allowing more employees than necessary to view it. This highlights the importance of protecting patient privacy and ensuring only authorized personnel can access sensitive data.
What happened
Aleris Sjukvård AB failed to implement adequate security measures, allowing unauthorized access to patient data.
Who was affected
Patients whose data was stored in the hospital information system TakeCare.
What the authority found
The Swedish DPA found that Aleris Sjukvård AB violated GDPR by not securing patient data properly and not following the principle of minimum access.
Why this matters
This case underscores the need for healthcare providers to conduct risk analyses and limit access to patient data. It serves as a warning that failing to protect sensitive information can lead to significant fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Swedish DPA (Integritetsskyddsmyndigheten) fined Aleris Sjukvård AB SEK 15,000,000 (EUR 1,463,000) for failing to implement adequate technical and organizational measures to ensure information security. It was found that there was no risk analysis regarding the access to patient data. Authorizations for users of the hospital information system TakeCare were not assigned according to the principle of minimum access. This gave users full access to confidential patient data that they did not need for work purposes.
Related Enforcement Actions (1)
Other enforcement actions involving Aleris Sjukvård AB in SE
Details
Fine Date
3 December 2020
Authority
Integritetsskyddsmyndigheten
Fine Amount
€1,463,000
Enforcement Tracker ID
ETid-466
About this data
Cite as: Cookie Fines. Aleris Sjukvård AB - Sweden (2020). Retrieved from cookiefines.eu
Last updated: