FineME
Run assessment
Back to Cases
technologyhealth · 2023

Region Uppsala

IMY fined Region Uppsala after unauthorized staff access to patient records revealed inadequate access reviews and logging controls under GDPR Articles 5, 24 and 32.

Fine Imposed€650,000.0
Authority

Integritetsskyddsmyndigheten

Styleaggressive
Avg. investigation15 mo
View authority profile
Regulation

Key Takeaways
  • Regional health authorities must review access logs proactively, not only after incidents.