Back to all lessons
Awareness Lessons
3 months ago

€450K GDPR Fine After Weak Access Controls Exposed 383,000 Patient Records

Lithuanian medical company UAB InMedica suffered two separate breaches exposing the health data of up to 383,000 patients due to inadequate access controls, weak password policies, and the absence of multi-factor authentication. Health data is among the most sensitive categories under GDPR, making robust technical safeguards not just best practice but a legal obligation under Articles 5, 24, and 32. The failure to implement baseline security measures — controls that are widely understood and readily available — demonstrates a significant gap between the organisation's data protection obligations and its operational security posture. This case illustrates that regulatory fines scale with the severity and volume of affected data subjects, and that preventable control failures carry disproportionate reputational and financial consequences.

Tactical Insight

Immediate actions

  • Enforce multi-factor authentication (MFA) on all systems that store or process sensitive personal or health data.
  • Audit and remediate all user accounts with weak, shared, or default passwords immediately.
  • Conduct a privilege review to ensure access to patient data follows the principle of least privilege.

Long-term improvements

  • Establish a formal Access Control Policy that mandates MFA, password complexity standards, and periodic access reviews.
  • Implement a data classification framework to ensure that special-category data (e.g., health records) receives the highest tier of technical controls.
  • Schedule annual third-party security assessments focused on access management and GDPR Article 32 compliance.

Detection & monitoring measures

  • Deploy centralised logging and SIEM alerting for anomalous or unauthorised access attempts to systems holding personal data.
  • Set up automated alerts for bulk data access or export events involving health records.
  • Establish a data breach detection and notification workflow to meet the 72-hour GDPR reporting requirement.