Ospedale San Raffaele s.r.l. – €70,000 Fine (Italy, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Ospedale San Raffaele was fined EUR 70,000 for exposing patients' email addresses in newsletters. This breach shows the importance of securing personal data, especially in healthcare settings.
What happened
The hospital exposed patients' and caregivers' email addresses by using open distribution lists in newsletters.
Who was affected
Patients and their family members or caregivers whose email addresses were visible to other recipients.
What the authority found
The Italian DPA found the hospital violated GDPR's integrity and confidentiality principles by not securing personal data properly.
Why this matters
This case highlights the critical need for healthcare providers to implement strong data protection measures. It serves as a warning to ensure email communications are secure and private.
GDPR Articles Cited
The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33 GDPR. In the first case, the neurology department of the hospital had sent a newsletter in an open distribution list, which resulted in the email addresses of the recipients being visible to all recipients. Of the 499 email addresses affected, 321 email addresses related to patients and 46 related to family members/caregivers of patients, which allowed these individuals to be identified by name. In the second case, a surgical department had sent a newsletter in an open distribution list, so again the recipients' email addresses were visible to all recipients. Of the 90 e-mail addresses affected, 75 e-mail addresses referred to patients and/or family members/caregivers of the patients, which meant that these individuals could be identified by name. The DPA considered this to be a violation of the principle of 'integrity and confidentiality,' which requires that personal data be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage by appropriate technical and organizational measures. With regard to the calculation of the fine, the DPA took into aggravating account the fact that the data breach also affected data relating to the health of the persons concerned. The fact that the hospital had introduced measures to prevent such events in the future and had cooperated to a high degree with the DPA was taken into beneficial consideration.
Related Enforcement Actions (0)
No other enforcement actions found for Ospedale San Raffaele s.r.l. in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
28 April 2022
Authority
Garante per la protezione dei dati personali
Fine Amount
€70,000
Enforcement Tracker ID
ETid-1235
About this data
Cite as: Cookie Fines. Ospedale San Raffaele s.r.l. - Italy (2022). Retrieved from cookiefines.eu
Last updated: