FineME
Run assessment
Back to Cases
technologyhealth · 2022

Region Hovedstaden

Datatilsynet criticized the Capital Region over excessive employee access to patient information and insufficient logging controls, implicating GDPR Articles 5 and 32.

Fine Imposed€201,000.0
Authority

Datatilsynet

Stylebalanced
Avg. investigation11 mo
View authority profile
Regulation

Key Takeaways
  • Healthcare employers must continuously validate role-based access to patient systems.