Bambino Gesù Pediatric Hospital – €8,000 Fine (Italy, 2024)

€8,000Garante per la protezione dei dati personali24 January 2024Italy
final
ePrivacy
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Bambino Gesù Pediatric Hospital faced a fine for a data breach where a patient accessed another patient's report by mistake. This incident happened due to a software error and affected 24 reports. The ruling highlights the importance of proper security measures to protect patient data.

What happened

A patient mistakenly accessed another patient's report due to a software error at Bambino Gesù Pediatric Hospital.

Who was affected

Patients whose reports were incorrectly accessed due to the hospital's software error.

What the authority found

The authority found that the hospital did not implement adequate security measures to protect personal data, violating GDPR requirements.

Why this matters

This case emphasizes the need for healthcare providers to ensure robust data protection practices. Hospitals should regularly assess their software and security protocols to prevent similar breaches.

GDPR Articles Cited

AI-verified

Art. 9(GDPR)
Art. 28(GDPR)
Art. 5(1)(f) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Art. 58(2)(i) GDPR
Art. 83(4) GDPR
Art. 83(5)(a) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 9(GDPR)
Art. 28(GDPR)
Art. 32(1)(d) GDPR
Art. 32(1)(b) GDPR
Art. 58(2)(i) GDPR
Art. 83(4) GDPR
Art. 83(5)(a) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 122 Codice Privacy

Entities Involved

Bambino Gesù Pediatric Hospital
Dedalus Italia S.p.A.
Source verified 5 April 2026
national law identified
Full Legal Summary
Detailed

Bambino Gesù Pediatric Hospital in Rome reported a data breach involving its "Charter of Health" portal. On a specified day, a patient mistakenly accessed another patient's report due to a software error. The issue stemmed from the Dedalus Dnlab software provided by Dedalus Italia S.p.A., which sent incorrect patient identifiers in HL7 messages. This caused reports to be wrongly associated with patients in the hospital's integrated systems. The breach affected 24 reports. The hospital promptly notified authorities and took corrective actions, including requesting Dedalus to implement non-regression testing to prevent future occurrences. They also communicated with affected patients and provided additional support. Dedalus contended that it was not contractually required to perform regular vulnerability assessments and argued that the error was accidental and limited in scope. They claimed the breach was due to an isolated incident and requested either the closure of the case or a lesser penalty. The findings underscored that Dedalus, despite its arguments about the limitations of its contractual obligations, did not adequately address the security needs or conduct necessary periodic checks and failed to implement appropriate technical and organizational security measures as required by GDPR. As a result, the breach lasted for four days and involved a manageable number of patients with no substantial evidence of damage or misuse. In response, the Authority imposed a fine of €8,000 for non-compliance with GDPR standards.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Bambino Gesù Pediatric Hospital in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

24 January 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€8,000

GDPRhub ID

gdprhub-8154

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Bambino Gesù Pediatric Hospital - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: