C.B. Sistemi s.r.l. – Complaint Upheld (Italy, 2023)
C.B. Sistemi s.r.l. faced a complaint after a person found a flaw in their medical platform that let users see other patients' reports. This matters because it highlights the importance of keeping sensitive health data secure. The company quickly fixed the issue, but it raises questions about how well they protect personal information.
What happened
A person accessed a medical platform and discovered a vulnerability that allowed viewing other patients' reports.
Who was affected
Patients using the StudioWEB platform who had their medical reports exposed due to the vulnerability.
What the authority found
The Italian DPA requested more information from the health care provider to evaluate its data protection practices.
Why this matters
This case shows that companies must ensure their platforms are secure to protect sensitive health information. It serves as a reminder for all businesses handling personal data to regularly check for vulnerabilities.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
CB Sistemi s.r.l. (the processor) provided health care provider Medical Center s.r.l. (the controller) with the StudioWEB platform, which made the results of medical examinations available to patients through an authentication process. A person accessed the StudioWEB platform with his grandmother's credentials. He then discovered a vulnerability that allowed logged-in patients to access other reports by changing the URL link. Specifically, the person stressed that by changing the final number of the URL link, it was possible to access other patients' reports. It was also even possible to see the "Event Log" of the report, which showed a list of the users who have downloaded the report. Thus, the person informed both the controller and the Italian DPA of the vulnerability. The processor immediately fixed the vulnerability and later explained that it was due to a bug introduced with a software update. Pursuant to [https://www.garanteprivacy.it/documents/10160/0/Codice+in+materia+di+protezione+dei+dati+personali+%28Testo+coordinato%29.pdf/b1787d6b-6bce-07da-a38f-3742e3888c1d?version=7.0 Article 157 of the Italian Privacy Code], the DPA requested the controller to provide more information on the matter that were necessary to evaluate its data protection practices. To begin with, the Italian DPA held that the medical reports shown on the platform could be considered as data concerning health pursuant to Article 4(15) GDPR. In this regard, and taking into consideration the submission by the controller, the DPA noted that the vulnerability of the system had been foreseen in the initial test phase and appropriately blocked. Therefore, since the processor did not take into account the vulnerability following the software update of the same portal, the DPA believed that the processor had not adopted appropriate measures to guarantee a level of security adequate to the risk, as provided by Article 5(1)(f) GDPR and Article 32 GDPR to ensure the confidentiality, integrity, ava
Outcome
Complaint Upheld
A data subject complaint that was upheld by the DPA.
Related Enforcement Actions (0)
No other enforcement actions found for C.B. Sistemi s.r.l. in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Decision Date
30 November 2023
Authority
Garante per la protezione dei dati personali
GDPRhub ID
gdprhub-7578About this data
Cite as: Cookie Fines. C.B. Sistemi s.r.l. - Italy (2023). Retrieved from cookiefines.eu
Last updated: