Centro Hospitalar Barreiro Montijo, EPE – €400,000 Fine (Portugal, 2018)

€400,000Commission Nationale pour la Protection des Données9 October 2018Portugal
final
ePrivacy
Fine

Another Portuguese hospital was fined for allowing unauthorized access to patient records by its staff. The investigation revealed that staff members could access sensitive information without proper controls. This case highlights the critical need for hospitals to secure patient data and restrict access to authorized personnel only.

What happened

Hospital staff accessed electronic patient records without authorization.

Who was affected

Patients whose electronic health records were improperly accessed by hospital staff.

What the authority found

The Commission Nationale pour la Protection des Données found that the hospital violated multiple GDPR rules regarding data protection and security.

Why this matters

This case underscores the importance of robust security measures in healthcare settings. Other hospitals should take this as a warning to tighten their data access protocols.

GDPR Articles Cited

AI-verified

Art. 5(1)(c) GDPR
Art. 5(1)(f) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(1)(c) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
scope corrected
Full Legal Summary
Detailed

CNPD's investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data, notably data which was part of the Electronic Patient Records (EPR) - which should only be accessed by doctors - through their information system accounts. The profile management system revealed other flaws, as the hospital had 985 registered doctor profiles, while only having 296 doctors. Moreover, doctors had unrestricted access to all patient files, regardless of the doctors' specialty. Does granting hospital’s staff, psychologists, dietitians and other professionals access to Electronic Patient Records (EPR) breach articles 5(1)(c), (f), and 32(1)(b), (d) of the GDPR? While the controller argued that (i) professionals other than doctors needed access to health data to fulfill their roles and that (ii) system access permissions were not configured by the controller, but by the Health Ministry's shared services (SPMS), the Portuguese DPA found that it was the controller who voluntarily determined said professionals should have indiscriminate access to EPRs and that the controller never asked SPMS to adjust the hospital's professionals' access profiles. When determining the amount of the fine, the Portuguese DPA took into account the number of affected data subjects (dozens of thousands), the nature of the personal data at stake (health-related data) and the intentional character of the breach by the data controller (who did not implement a reliable audit system after a prior instruction by the DPA).

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Centro Hospitalar Barreiro Montijo, EPE in PT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

9 October 2018

Authority

Commission Nationale pour la Protection des Données

Fine Amount

€400,000

GDPRhub ID

gdprhub-2221

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Centro Hospitalar Barreiro Montijo, EPE - Portugal (2018). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: