FineME
Run assessment
Back to Cases
technologyhealth · 2024

Mehiläinen Oy

The Ombudsman fined Mehiläinen for inadequate governance over processor access to patient systems and insufficient audit logging under GDPR Articles 28 and 32.

Fine Imposed€210,000.0
Authority

Office of the Data Protection Ombudsman

Stylebalanced
Avg. investigation15 mo
View authority profile
Regulation

Key Takeaways
  • Private healthcare groups must contractually and technically constrain processor access.