Back to Cases
technologyhealth · 2024
Mehiläinen Oy
The Ombudsman fined Mehiläinen for inadequate governance over processor access to patient systems and insufficient audit logging under GDPR Articles 28 and 32.
Fine Imposed€210,000.0
Authority
Office of the Data Protection Ombudsman
Stylebalanced
Avg. investigation15 mo
Regulation
Key Takeaways
- Private healthcare groups must contractually and technically constrain processor access.