CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L. – €18,000 Fine (Spain, 2021)

€18,000Agencia Española de Protección de Datos20 September 2021Spain
reduced
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Spain fined CEDICO €18,000 for sharing a patient's medical records with an insurance company without proper consent. This mistake led to the patient being denied sick leave. The case highlights the importance of handling sensitive health information carefully.

What happened

CEDICO shared a patient's medical records with an insurance company without proper consent.

Who was affected

A patient whose medical records were shared with an insurance company, affecting their sick leave request.

What the authority found

The Spanish DPA found that CEDICO violated the principle of integrity and confidentiality by improperly sharing medical records.

Why this matters

This case underscores the need for healthcare providers to protect patient information and ensure it is shared only with proper authorization. It serves as a reminder of the serious consequences of mishandling sensitive data.

GDPR Articles Cited

Art. 5(1)(f) GDPR
Full Legal Summary
Detailed

The Spanish DPA (AEPD) has imposed a fine on CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.. The data subject filed a complaint with the AEPD. He had requested an MRI scan of his knee due to an accident at work. In addition, he had contacted his insurance company in order to obtain a sick leave. The insurance company then contacted the controller, who transmitted the data subject's medical records. In doing so, the controller also provided the insurer with the report of a previous MRI scan of the knee that the data subject had undergone due to an event outside of work. In its evaluation, the insurer thus also referred to the MRI report outside working hours and attributed the data subject's incapacity to work to this event. In consequence, no sick leave was granted to the data subject. The DPA considered the disclosure of the earlier MRI report to the insurance company to be a violation of the principle of integrity and confidentiality. The original fine of EUR 30,000 was reduced to EUR 18,000 due to the voluntary payment and admission of guilt.

Related Enforcement Actions (0)

No other enforcement actions found for CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L. in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

20 September 2021

Authority

Agencia Española de Protección de Datos

Fine Amount

€18,000

Enforcement Tracker ID

ETid-844

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L. - Spain (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: