[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3pvp92kARMgzBrgN5lC8bDFNYDCcpeBahcQKNHS1aRI":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"8e313289-9194-4a73-ade1-14660a16f356","Garante per la protezione dei dati personali (Italy) - 616\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-616-2026-799686","← Older revision Revision as of 12:13, 14 September 2026 (One intermediate revision by the same user not shown) Line 108: Line 108: }} }} The DPA fined a controller €24,000 for having an inadequate configuration of access to electronic health records, which resulted in unlawful processing of the data subject’s personal data in violation of Article 5(1)(a), (b), (c) and (f), Article 9, Article 25 and [[Article 32 GDPR|Article 32 GDPR]]. The DPA fined a controller €24,000 for having an inadequate configuration of access to electronic health records, which resulted in unlawful processing of the data subject’s personal data in violation of [[Article 5 GDPR|Article 5(1)(a), (b), (c) and (f)]], [[Article 9 GDPR|Article 9]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]]. == English Summary == == English Summary == Line 114: Line 114: === Facts === === Facts === The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The data subject complained about a few activities of the controller: The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The data subject complained about a few activities of the controller: - The access of her medical records, for the purpose of verifying whether she had Covid-19 in order to schedule her shifts. - The access of her medical records, for the purpose of verifying whether she had Covid-19 in order to schedule her shifts. - The access to her medical records by individuals who were not caring for the data subject, through a reservation system. - The access to her medical records by individuals who were not caring for the data subject, through a reservation system. - The ability for healthcare professionals to access medical records from other healthcare facilities. - The ability for healthcare professionals to access medical records from other healthcare facilities. - The ability for healthcare professionals to access all records from the surgical department regardless of whether they are treating the patient. - The ability for healthcare professionals to access all records from the surgical department regardless of whether they are treating the patient. - The lack of access logs. - The lack of access logs. Line 125: Line 130: Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. === Holding === The DPA found the fact that the data subject was already admitted for treatment at the time that her file was accessed irrelevant because the access to her records had nothing to do with her treatment, but rather for the management of the schedule of shifts. Emphasis was placed by the DPA on the need for data minimisation, the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. === Holding === The DPA found the fact that the data subject was already admitted for treatment at the time that her file was accessed was irrelevant because the access actually had nothing to do with her treatment, but rather for the management of the schedule of shifts. Emphasis was placed by the DPA on the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. This would ensure data minimisation, allowing employees to access the data that is essential for their tasks and nothing more. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. Similarly, the reference to the large number of staff on duty was found to be invalid by the DPA as the implementation of an automatic lockout based on the specific needs and nature of tasks would have constituted a technical measure which is suitable to ensure a level of security appropriate to the risk of unauthorised access. The systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access. Finally, the DPA found that the controller never adopted a system for automatic detection of anomalies possibly constituting unlawful processing nor alters of such. The DPA found that the controller insufficiently relies on after the fact complaints by data subjects, and does not have a system of conducting random checks to electronic health record access which could have also been a mechanism to deter employees from gaining access to records that they should not have access too. Similarly, the reference to the large number of staff on duty was found invalid by the DPA as the implementation of an automatic lockout based on the specific needs and nature of tasks would have constituted a technical measure which is suitable to ensure a level of security appropriate to the risk of unauthorised access. The systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access. In light of the foregoing, the DPA found the controller in violation of Articles 5(1)(a), (b), (c), and (f), Article 9, Article 25 and [[Article 32 GDPR|Article 32 GDPR]] and correspondingly imposed a fine of €24.000 on them. Finally, the DPA found that the controller never adopted a system for automatic detection of anomalies possibly constituting unlawful processing. The DPA found that the controller insufficiently relied on conducting checks after data subject's complain rather than implementing a system of random checks to electronic health record access which could have also been a mechanism to deter employees from gaining access to records that they should not have access too. In light of the foregoing, the DPA found the controller in violation of [[Article 5 GDPR|Articles 5(1)(a), (b), (c), and (f)]], [[Article 9 GDPR|Article 9]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]] and correspondingly imposed a fine of €24.000 on them. == Comment == == Comment ==","Italy's Garante per la protezione dei dati personali (DPA) has fined the University Health Agency of Friuli Centrale €24,000 for inadequate access configurations to electronic health records. The DPA found that access was granted for reasons unrelated to patient care, such as scheduling shifts, and that access logs were insufficient. The agency also failed to implement adequate automatic lockout periods and anomaly detection systems, leading to violations of GDPR articles related to data processing, security, and data protection by design.","Italy's DPA fines healthcare agency €24,000 for inadequate access controls to electronic health records.","Help Garante per la protezione dei dati personali (Italy) - 616\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:04, 14 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 edits Tag: Decisions [1.0] Latest revision as of 12:13, 14 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 editsmTag: Visual edit (One intermediate revision by the same user not shown)Line 108: Line 108: }}}} The DPA fined a controller €24,000 for having an inadequate configuration of access to electronic health records, which resulted in unlawful processing of the data subject’s personal data in violation of Article 5(1)(a), (b), (c) and (f), Article 9, Article 25 and [[Article 32 GDPR|Article 32 GDPR]].The DPA fined a controller €24,000 for having an inadequate configuration of access to electronic health records, which resulted in unlawful processing of the data subject’s personal data in violation of [[Article 5 GDPR|Article 5(1)(a), (b), (c) and (f)]], [[Article 9 GDPR|Article 9]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]]. == English Summary ==== English Summary == Line 114: Line 114: === Facts ====== Facts === The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The data subject complained about a few activities of the controller: The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The data subject complained about a few activities of the controller: - The access of her medical records, for the purpose of verifying whether she had Covid-19 in order to schedule her shifts. - The access of her medical records, for the purpose of verifying whether she had Covid-19 in order to schedule her shifts. - The access to her medical records by individuals who were not caring for the data subject, through a reservation system. - The access to her medical records by individuals who were not caring for the data subject, through a reservation system. - The ability for healthcare professionals to access medical records from other healthcare facilities. - The ability for healthcare professionals to access medical records from other healthcare facilities. - The ability for healthcare professionals to access all records from the surgical department regardless of whether they are treating the patient.- The ability for healthcare professionals to access all records from the surgical department regardless of whether they are treating the patient. - The lack of access logs.- The lack of access logs. Line 125: Line 130: Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. === Holding === The DPA found the fact that the data subject was already admitted for treatment at the time that her file was accessed irrelevant because the access to her records had nothing to do with her treatment, but rather for the management of the schedule of shifts. Emphasis was placed by the DPA on the need for data minimisation, the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. === Holding === The DPA found the fact that the data subject was already admitted for treatment at the time that her file was accessed was irrelevant because the access actually had nothing to do with her treatment, but rather for the management of the schedule of shifts. Emphasis was placed by the DPA on the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. This would ensure data minimisation, allowing employees to access the data that is essential for their tasks and nothing more. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. Similarly, the reference to the large number of staff on duty was found to be invalid by the DPA as the implementation of an automatic lockout based on the specific needs and nature of tasks would have constituted a technical measure which is suitable to ensure a level of security appropriate to the risk of unauthorised access. The systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access. Finally, the DPA found that the controller never adopted a system for automatic detection of anomalies possibly constituting unlawful processing nor alters of such. The DPA found that the controller insufficiently relies on after the fact complaints by data subjects, and does not have a system of conducting random checks to electronic health record access which could have also been a mechanism to deter employees from gaining access to records that they should not have access too.Similarly, the reference to the large number of staff on duty was found invalid by the DPA as the implementation of an automatic lockout based on the specific needs and nature of tasks would have constituted a technical measure which is suitable to ensure a level of security appropriate to the risk of unauthorised access. The systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access. In light of the foregoing, the DPA found the controller in violation of Articles 5(1)(a), (b), (c), and (f), Article 9, Article 25 and [[Article 32 GDPR|Article 32 GDPR]] and correspondingly imposed a fine of €24.000 on them. Finally, the DPA found that the controller never adopted a system for automatic detection of anomalies possibly constituting unlawful processing. The DPA found that the controller insufficiently relied on conducting checks after data subject's complain rather than implementing a system of random checks to electronic health record access which could have also been a mechanism to deter employees from gaining access to records that they should not have access too. In light of the foregoing, the DPA found the controller","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_616\u002F2026&diff=53005&oldid=53003","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-14T12:13:54+00:00","2026-09-14T14:00:18.621214+00:00",7,[18,21],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor",{"name":22,"type":23},"electronic health records","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]