Azienda ULSS 6 Euganea – €22,000 Fine (Italy, 2024)
Azienda ULSS 6 Euganea was fined €22,000 after a cyberattack exposed personal data of patients and employees. This is significant because it shows the need for strong security measures to protect sensitive information. Health organizations must prioritize cybersecurity to safeguard personal data.
What happened
A cyberattack on Azienda ULSS 6 Euganea led to unauthorized access to personal data stored on their servers.
Who was affected
Patients and employees whose personal information was compromised in the cyberattack.
What the authority found
The Italian DPA found that the organization failed to implement adequate security measures to prevent unauthorized access to personal data.
Why this matters
This ruling stresses the importance of cybersecurity in protecting sensitive data. Organizations should adopt strong security protocols to prevent breaches.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The controller, a health authority managing several hospitals and other health facilities, experienced a cyberattack. This led to the unauthorised access to files stored in the controller's servers. These files contained personal data of both employees and patients, including medical documents and images. The controller notified the data breach to the DPA in accordance with Article 33 GDPR and to data subjects according to Article 34 GDPR. Moreover, several data subjects filed a complaint with the DPA. The controller argued that it was in the process of updating its IT system and improving its security measures. First, the DPA considered that the data breach notification to itself and data subjects was made without an undue delay and, therefore, did not find a violation of Article 33 and 34 GDPR. However, the DPA noted that the controller did not implement appropriate measures to ensure that it could timely learn about unauthorised accesses to the IT system. Therefore, it found a violation of Article 5(1)(f) GDPR in combination with Article 32(1) GDPR. Secondly, the DPA held that the technical and organisational measures implemented by the controller to avoid cyberattacks were not adequate. For example, two-factor authentication was not implemented. Therefore, the DPA found a violation of Article 5(1)(f) GDPR in combination with Article 32(1) GDPR. On these grounds, the DPA fined the controller €22,000.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (1)
Other enforcement actions involving Azienda ULSS 6 Euganea in IT
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
17 July 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€22,000
GDPRhub ID
gdprhub-8336About this data
Cite as: Cookie Fines. Azienda ULSS 6 Euganea - Italy (2024). Retrieved from cookiefines.eu
Last updated: