Società Molise Dati – €10,000 Fine (Italy, 2024)

€10,000Garante per la protezione dei dati personali27 November 2024Italy
final
ePrivacy
Fine

Società Molise Dati was fined for allowing unauthorized access to patient records through a system vulnerability. This case underscores the need for strict access controls in health data management.

What happened

A user exploited a vulnerability to access other patients' files in the health records system.

Who was affected

Patients whose sensitive health information was accessed without authorization were affected by this incident.

What the authority found

The Italian authority found that Società Molise Dati did not adequately secure access to personal data, resulting in a fine of €10,000.

Why this matters

This ruling highlights the importance of implementing strong security measures in health information systems. Organizations must ensure that access to sensitive data is tightly controlled to protect patient privacy.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
View original scraped data
Art. 32(GDPR)

Original data from scraper before AI verification against source document.

Source verified 5 April 2026
amount discrepancy
Full Legal Summary
Detailed

The Region of Molise (the data controller) used an information system to handle electronic health records. In order to develop and operate the system, the controller relied on a number of processors and sub-processors, including Società Molise Dati S.p.a. (the processor), a company entirely owned by the controller. In turn, the processor itself relied on several sub-processors, including Engineering Ingegneria Informatica S.p.a. (the sub-processor). Data processing agreements were in place between controllers, processors, and sub-processors. These agreements provided for certain security measures. In particular, the agreement between the controller and the processor provided for the limitation of account privileges on a need-to-know basis. A user logged into the records system with his patient-level account. He was then able to access files of other patients by changing the url address of the page. He accessed personal data such as personal details and addresses as well as medical records and other sensitive, health-related data. The user informed the controller of the vulnerability. With the assistance of the processor and sub-processor, the controller limited access privileges for patient-level accounts. Additionally, the software was assessed for similar vulnerabilities. The controller notified the Italian authority of the data breach. Based on system logs, the controller claimed that the data of seven people were accessed without authorization. The authority held that the processor violated Article 32 GDPR by failing to implement appropriate security measures. The authority fined the controller €10,000. The authority clarified that data controllers and processors are responsible for the security of the processing of personal data even when sub-processors are involved. The authority referenced EDPB Guidelines in this regardEDPB, 'Guidelines 07/2020 on the concepts of controller and processor in the GDPR', 7 July 2021 (Version 2.1), paragraphs 129 and 159 (avail

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Società Molise Dati in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

27 November 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€10,000

GDPRhub ID

gdprhub-8897

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Società Molise Dati - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: