Ospedale San Raffaele s.r.l. – €70,000 Fine (Italy, 2022)

€70,000Garante per la protezione dei dati personali28 April 2022Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Ospedale San Raffaele was fined EUR 70,000 for exposing patients' email addresses in newsletters. This breach shows the importance of securing personal data, especially in healthcare settings.

What happened

The hospital exposed patients' and caregivers' email addresses by using open distribution lists in newsletters.

Who was affected

Patients and their family members or caregivers whose email addresses were visible to other recipients.

What the authority found

The Italian DPA found the hospital violated GDPR's integrity and confidentiality principles by not securing personal data properly.

Why this matters

This case highlights the critical need for healthcare providers to implement strong data protection measures. It serves as a warning to ensure email communications are secure and private.

GDPR Articles Cited

Art. 9 GDPR
Art. 5(1)(f) GDPR
Full Legal Summary
Detailed

The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33 GDPR. In the first case, the neurology department of the hospital had sent a newsletter in an open distribution list, which resulted in the email addresses of the recipients being visible to all recipients. Of the 499 email addresses affected, 321 email addresses related to patients and 46 related to family members/caregivers of patients, which allowed these individuals to be identified by name. In the second case, a surgical department had sent a newsletter in an open distribution list, so again the recipients' email addresses were visible to all recipients. Of the 90 e-mail addresses affected, 75 e-mail addresses referred to patients and/or family members/caregivers of the patients, which meant that these individuals could be identified by name. The DPA considered this to be a violation of the principle of 'integrity and confidentiality,' which requires that personal data be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage by appropriate technical and organizational measures. With regard to the calculation of the fine, the DPA took into aggravating account the fact that the data breach also affected data relating to the health of the persons concerned. The fact that the hospital had introduced measures to prevent such events in the future and had cooperated to a high degree with the DPA was taken into beneficial consideration.

Related Enforcement Actions (0)

No other enforcement actions found for Ospedale San Raffaele s.r.l. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

28 April 2022

Authority

Garante per la protezione dei dati personali

Fine Amount

€70,000

Enforcement Tracker ID

ETid-1235

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Ospedale San Raffaele s.r.l. - Italy (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: