ST. OLAVS HOSPITAL HF – €75,600 Fine (Norway, 2021)

€75,600Datatilsynet (Norway)20 September 2021Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

St. Olavs Hospital was fined for not securing patient data properly, leading to multiple data leaks. Sensitive information was left accessible due to poor access controls and system errors. This case highlights the need for strong data security in healthcare.

What happened

St. Olavs Hospital experienced data leaks where sensitive patient information was accessible due to inadequate access controls and system errors.

Who was affected

Patients whose sensitive health data, including treatment reports and passwords, were exposed due to the hospital's security lapses.

What the authority found

The Norwegian DPA fined the hospital for failing to establish effective access controls, violating GDPR's data security requirements.

Why this matters

The case serves as a warning to healthcare providers about the importance of maintaining strict access controls and regularly reviewing security protocols to protect patient data. It highlights the potential consequences of neglecting data security responsibilities.

GDPR Articles Cited

Art. 32 GDPR
Full Legal Summary
Detailed

The Norwegian DPA has fined St. Olav's Hospital in the amount of EUR 75,600. The hospital suffered three data leaks in accordance with Art. 33 the GDPR. The first incident had occurred between January 13, 2011, and January 27, 2020, at the hospital's cardiology department following an upgrade for a new treatment-oriented health registry for the cardiology laboratory. In connection with the upgrade, a test server was used on which treatment reports were temporarily cached and then copied to the new system. However, the reports in the test server were not deleted. Moreover, another error occurred, which allowed all authenticated employees to access the reports. About 21,000 reports were affected. The second breach occurred in the period from May 17, 2015 to January 28, 2020, when reports from medical devices (pulse oximeters for long-term measurement of oxygen saturation and pulse) were stored in a file area accessible to any employee with an authenticated and active account. The third breach occurred in the period from January 01, 2018 to December 09, 2019. Passwords for various databases were stored in plain text in a file on the hospital's server. Employees with an active hospital system account were able to first connect to the server viaRemote Desktop and then search for a file with a password in the database. The DPA found that the hospital had failed to establish effective access controls.

Related Enforcement Actions (0)

No other enforcement actions found for ST. OLAVS HOSPITAL HF in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

20 September 2021

Authority

Datatilsynet (Norway)

Fine Amount

€75,600

Enforcement Tracker ID

ETid-859

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. ST. OLAVS HOSPITAL HF - Norway (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: