Back to Cases
technologyhealth · 2023
Region Uppsala
IMY fined Region Uppsala after unauthorized staff access to patient records revealed inadequate access reviews and logging controls under GDPR Articles 5, 24 and 32.
Fine Imposed€650,000.0
Regulation
Key Takeaways
- Regional health authorities must review access logs proactively, not only after incidents.