FineME
Run assessment
Back to Cases
technologyhealth · 2022

HUS Helsinki University Hospital

The Ombudsman sanctioned HUS over unauthorized internal access to patient records and insufficient monitoring of user activity, engaging GDPR Articles 5, 24 and 32.

Fine Imposed€300,000.0
Authority

Office of the Data Protection Ombudsman

Stylebalanced
Avg. investigation15 mo
View authority profile
Regulation

Key Takeaways
  • Hospitals must actively monitor access logs for misuse of patient data.