Azienda Ospedaliero Universitaria di Parma – €10,000 Fine (Italy, 2021)

€10,000Garante per la protezione dei dati personali27 January 2021Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Italy's data protection authority fined a hospital in Parma EUR 10,000 for mistakenly disclosing patient data. In two separate incidents, patients' personal and health information was sent to the wrong people. This case highlights the importance of hospitals safeguarding sensitive patient data.

What happened

A hospital in Parma accidentally sent patient data to the wrong people in two incidents.

Who was affected

Patients whose personal and health information was mistakenly shared with others.

What the authority found

The Italian authority found that the hospital failed to protect patient data, violating GDPR rules on data security and sensitive data handling.

Why this matters

This case underscores the critical need for healthcare providers to ensure robust data protection measures. It serves as a reminder that even unintentional data breaches can lead to significant fines and reputational damage.

GDPR Articles Cited

Art. 9 GDPR
Art. 5(1)(f) GDPR
Full Legal Summary
Detailed

The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which patient data was mistakenly disclosed to third parties. In the first incident, parents found the report of a microbiological examination of another patient in the file of their minor child. The report revealed the data subject´s name, tax number, address, birth date and various health data. In the second incident, the heir of a patient received the health report of another patient, which contained the name and birth date as well as data on the health status of the data subject.

Related Enforcement Actions (0)

No other enforcement actions found for Azienda Ospedaliero Universitaria di Parma in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

27 January 2021

Authority

Garante per la protezione dei dati personali

Fine Amount

€10,000

Enforcement Tracker ID

ETid-561

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Azienda Ospedaliero Universitaria di Parma - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: