St. Olavs Hospital – €65,250 Fine (Norway, 2021)

€65,250Datatilsynet (Norway)20 September 2021Norway
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

St. Olavs Hospital in Norway was fined for not protecting patient data properly. Sensitive health information was left exposed due to poor system upgrades and access controls. This case highlights the importance of strong data security measures in healthcare.

What happened

St. Olavs Hospital had multiple data breaches exposing sensitive patient information due to inadequate system upgrades and access controls.

Who was affected

Patients whose sensitive health data, including social security numbers and health metrics, were stored insecurely by the hospital.

What the authority found

The Norwegian DPA fined the hospital for failing to implement necessary security measures to protect personal data, violating GDPR's requirements for data security and accountability.

Why this matters

This case underscores the critical need for healthcare providers to maintain robust data security practices. It serves as a reminder that organizations must regularly audit and update their systems to prevent unauthorized access to sensitive information.

GDPR Articles Cited

Art. 24 GDPR
Art. 32 GDPR
Art. 5(1)(f) GDPR
Art. 5(2) GDPR

National Law Articles

Health Records Act (pasientjournalloven) §§ 22-23
Personal Data Act § 26(1)
Full Legal Summary
Detailed

A Norwegian hospital notified the DPA of three personal data breaches lasting between two and nine years. The breaches found their origin in deficient internal systems upgrades, poorly managed access controls, routines not being followed, and lack of data deletion. The concerned personal data included names, social security numbers, health metrics data, sensitive health data (including information on substance abuse, or health data relating to children), and passwords stored in clear text in an unprotected server. These breaches were discovered during an audit by the Norwegian Office of the Auditor General. A significant number of patients were affected (e.g. about 21,000 records containing sensitive health data in one breach alone). However, the hospital did not have a comprehensive log, making it impossible to fully determine the extent of each breach. The DPA fined the hospital €76,870 (NOK 750,000) for breaching the requirements of internal control, security and safety for the processing of personal data under Article 32 GDPR, Article 24, [https://gdprhub.eu/index.php?title=Article_5_GDPR#1f Article 5(1)(f)] and [https://gdprhub.eu/index.php?title=Article_5_GDPR#2 Article 5(2)], as well as § 26(1) of the [https://lovdata.no/dokument/NL/lov/2018-06-15-38/ Personal Data Act] and §§ 22 and 23 of the [https://lovdata.no/dokument/NL/lov/2014-06-20-42 Health Records Act] (pasientjournalloven) . The DPA also pointed out that the highest-level management position, on behalf of the hospital, is accountable for the (negligent) violation.

Related Enforcement Actions (0)

No other enforcement actions found for St. Olavs Hospital in NO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

20 September 2021

Authority

Datatilsynet (Norway)

Fine Amount

€65,250

750,000 NOK

GDPRhub ID

gdprhub-4250

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. St. Olavs Hospital - Norway (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: