Bambino Gesù Pediatric Hospital – €8,000 Fine (Italy, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Bambino Gesù Pediatric Hospital was fined after a data breach exposed patient reports due to a software error. This matters because it highlights the need for hospitals to have strong data security measures in place to protect sensitive information.
What happened
The hospital reported a data breach where a patient accessed another patient's report by mistake due to a software issue.
Who was affected
Patients whose reports were mistakenly accessed were affected.
What the authority found
The authority found that the hospital did not implement adequate security measures to prevent such breaches under GDPR.
Why this matters
This case underscores the importance of robust data security in healthcare. Hospitals must ensure their systems are secure to protect patient privacy and avoid penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Entities Involved
Bambino Gesù Pediatric Hospital in Rome reported a data breach involving its "Charter of Health" portal. On a specified day, a patient mistakenly accessed another patient's report due to a software error. The issue stemmed from the Dedalus Dnlab software provided by Dedalus Italia S.p.A., which sent incorrect patient identifiers in HL7 messages. This caused reports to be wrongly associated with patients in the hospital's integrated systems. The breach affected 24 reports. The hospital promptly notified authorities and took corrective actions, including requesting Dedalus to implement non-regression testing to prevent future occurrences. They also communicated with affected patients and provided additional support. Dedalus contended that it was not contractually required to perform regular vulnerability assessments and argued that the error was accidental and limited in scope. They claimed the breach was due to an isolated incident and requested either the closure of the case or a lesser penalty. The findings underscored that Dedalus, despite its arguments about the limitations of its contractual obligations, did not adequately address the security needs or conduct necessary periodic checks and failed to implement appropriate technical and organizational security measures as required by GDPR. As a result, the breach lasted for four days and involved a manageable number of patients with no substantial evidence of damage or misuse. In response, the Authority imposed a fine of €8,000 for non-compliance with GDPR standards.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Bambino Gesù Pediatric Hospital in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
24 January 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€8,000
GDPRhub ID
gdprhub-8154About this data
Cite as: Cookie Fines. Bambino Gesù Pediatric Hospital - Italy (2024). Retrieved from cookiefines.eu
Last updated: