FineME
Run assessment
Back to Cases
technologyhealth · 2018

Centro Hospitalar Barreiro Montijo

CNPD fined a Portuguese hospital for allowing excessive numbers of users, including doctors without active functions, to access patient records, violating GDPR Articles 5, 24 and 32.

Fine Imposed€400,000.0
Authority

Comissão Nacional de Proteção de Dados

Stylebalanced
Avg. investigation15 mo
View authority profile
Regulation

Key Takeaways
  • Hospital role design must prevent broad default access to patient records.