Centro Hospitalar Barreiro Montijo, EPE – €400,000 Fine (Portugal, 2018)
Another Portuguese hospital was fined for allowing unauthorized access to patient records by its staff. The investigation revealed that staff members could access sensitive information without proper controls. This case highlights the critical need for hospitals to secure patient data and restrict access to authorized personnel only.
What happened
Hospital staff accessed electronic patient records without authorization.
Who was affected
Patients whose electronic health records were improperly accessed by hospital staff.
What the authority found
The Commission Nationale pour la Protection des Données found that the hospital violated multiple GDPR rules regarding data protection and security.
Why this matters
This case underscores the importance of robust security measures in healthcare settings. Other hospitals should take this as a warning to tighten their data access protocols.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
CNPD's investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data, notably data which was part of the Electronic Patient Records (EPR) - which should only be accessed by doctors - through their information system accounts. The profile management system revealed other flaws, as the hospital had 985 registered doctor profiles, while only having 296 doctors. Moreover, doctors had unrestricted access to all patient files, regardless of the doctors' specialty. Does granting hospital’s staff, psychologists, dietitians and other professionals access to Electronic Patient Records (EPR) breach articles 5(1)(c), (f), and 32(1)(b), (d) of the GDPR? While the controller argued that (i) professionals other than doctors needed access to health data to fulfill their roles and that (ii) system access permissions were not configured by the controller, but by the Health Ministry's shared services (SPMS), the Portuguese DPA found that it was the controller who voluntarily determined said professionals should have indiscriminate access to EPRs and that the controller never asked SPMS to adjust the hospital's professionals' access profiles. When determining the amount of the fine, the Portuguese DPA took into account the number of affected data subjects (dozens of thousands), the nature of the personal data at stake (health-related data) and the intentional character of the breach by the data controller (who did not implement a reliable audit system after a prior instruction by the DPA).
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Centro Hospitalar Barreiro Montijo, EPE in PT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
9 October 2018
Authority
Commission Nationale pour la Protection des Données
Fine Amount
€400,000
GDPRhub ID
gdprhub-2221About this data
Cite as: Cookie Fines. Centro Hospitalar Barreiro Montijo, EPE - Portugal (2018). Retrieved from cookiefines.eu
Last updated: