Back to Feed
PolicySep 15, 2026

Garante per la protezione dei dati personali (Italy) - 616/2026

Italian DPA fines University Health Agency for improper access to patient records.

Summary

Italy's Garante per la protezione dei dati personali (DPA) investigated a complaint regarding unauthorized access to a patient's electronic health records. The University Health Agency of Friuli Centrale was found to have inadequate data protection measures, including insufficient access controls and logging, and an inappropriate automatic computer lockout period. The DPA emphasized data minimization and limiting access to patient data strictly to those involved in direct care.

Full text

Help Garante per la protezione dei dati personali (Italy) - 616/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 12:13, 14 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 editsmTag: Visual edit← Older edit Latest revision as of 14:23, 15 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators415 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 113: Line 113: === Facts ====== Facts === The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The data subject complained about a few activities of the controller: The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. - The access of her medical records, for the purpose of verifying whether she had Covid-19 in order to schedule her shifts. - The access to her medical records by individuals who were not caring for the data subject, through a reservation system. - The ability for healthcare professionals to access medical records from other healthcare facilities. - The ability for healthcare professionals to access all records from the surgical department regardless of whether they are treating the patient. - The lack of access logs. The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The controller deemed the use of these verification methods justified as it was the only method to quickly ensure a negative test and allow the data subject access to a ward.The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The controller deemed the use of these verification methods justified as it was the only method to quickly ensure a negative test and allow the data subject access to a ward. Line 131: Line 121: Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. === Holding ====== Holding === The DPA found the fact that the data subject was already admitted for treatment at the time that her file was accessed irrelevant because the access to her records had nothing to do with her treatment, but rather for the management of the schedule of shifts. The DPA insisted on the principle of data minimisation, the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. Emphasis was placed by the DPA on the need for data minimisation, the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. Latest revision as of 14:23, 15 September 2026 Garante per la protezione dei dati personali - 616/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(c) GDPR Article 5(1)(f) GDPR Article 9 GDPR Article 25 GDPR Article 32 GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 24000.0 EUR Parties: Azienda sanitaria universitaria Friuli centrale National Case Number/Name: 616/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a controller €24,000 for having an inadequate configuration of access to electronic health records, which resulted in unlawful processing of the data subject’s personal data in violation of Article 5(1)(a), (b), (c) and (f), Article 9, Article 25 and Article 32 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The controller deemed the use of these verification methods justified as it was the only method to quickly ensure a negative test and allow the data subject access to a ward. The controller underscored that the purpose of such verification was to comply with the requirement that the shift schedule be finalised by the 20th of each month. In this regard it was underlined that on the day that the data subject’s records were accessed, she was already admitted for treatment. Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. Holding The DPA insisted on the principle of data minimisation, the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. Th

Entities

Garante per la protezione dei dati personali (vendor)electronic health record system (product)