Back to Cases
technologyhealth · 2018
Centro Hospitalar Barreiro Montijo
CNPD fined a Portuguese hospital for allowing excessive numbers of users, including doctors without active functions, to access patient records, violating GDPR Articles 5, 24 and 32.
Fine Imposed€400,000.0
Authority
Comissão Nacional de Proteção de Dados
Stylebalanced
Avg. investigation15 mo
Regulation
Key Takeaways
- Hospital role design must prevent broad default access to patient records.