Back to Cases
technologyhealth · 2022
Region Hovedstaden
Datatilsynet criticized the Capital Region over excessive employee access to patient information and insufficient logging controls, implicating GDPR Articles 5 and 32.
Fine Imposed€201,000.0
Regulation
Key Takeaways
- Healthcare employers must continuously validate role-based access to patient systems.