[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHPybGSyms9GP7d1pg8czviCPRrdkvsWT5mObbewqaAU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"e3f36e83-b134-4787-9b19-67226fd9df7e","450k-gdpr-fine-after-weak-access-controls-exposed-383000-patient-records","fd6b064f-7a13-4a1b-b9c5-335c1220f64b","€450K GDPR Fine After Weak Access Controls Exposed 383,000 Patient Records","Lithuanian medical company UAB InMedica suffered two separate breaches exposing the health data of up to 383,000 patients due to inadequate access controls, weak password policies, and the absence of multi-factor authentication. Health data is among the most sensitive categories under GDPR, making robust technical safeguards not just best practice but a legal obligation under Articles 5, 24, and 32. The failure to implement baseline security measures — controls that are widely understood and readily available — demonstrates a significant gap between the organisation's data protection obligations and its operational security posture. This case illustrates that regulatory fines scale with the severity and volume of affected data subjects, and that preventable control failures carry disproportionate reputational and financial consequences.","**Immediate actions:**\n- Enforce multi-factor authentication (MFA) on all systems that store or process sensitive personal or health data.\n- Audit and remediate all user accounts with weak, shared, or default passwords immediately.\n- Conduct a privilege review to ensure access to patient data follows the principle of least privilege.\n\n**Long-term improvements:**\n- Establish a formal Access Control Policy that mandates MFA, password complexity standards, and periodic access reviews.\n- Implement a data classification framework to ensure that special-category data (e.g., health records) receives the highest tier of technical controls.\n- Schedule annual third-party security assessments focused on access management and GDPR Article 32 compliance.\n\n**Detection & monitoring measures:**\n- Deploy centralised logging and SIEM alerting for anomalous or unauthorised access attempts to systems holding personal data.\n- Set up automated alerts for bulk data access or export events involving health records.\n- Establish a data breach detection and notification workflow to meet the 72-hour GDPR reporting requirement.",[12,13,14,15,16,17,18,19,20,21,22,23],"GDPR Article 5(1)(f) – Integrity and confidentiality principle","GDPR Article 24(1) – Responsibility of the controller","GDPR Article 32(1)(b) – Appropriate technical and organisational measures","CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","CIS Control 13 – Network Monitoring and Defence","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 IA-5 – Authenticator Management","NIST SP 800-53 IA-2 – Multi-Factor Authentication","NIST SP 800-53 AU-2 – Event Logging","ISO\u002FIEC 27001:2022 A.8.3 – Information Access Restriction","ISO\u002FIEC 27001:2022 A.8.5 – Secure Authentication","published","2026-07-07T14:21:12.374195+00:00","2026-07-07T14:21:12.045+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=VDAI_(Lithuania)_-_3R-1143&diff=52083&oldid=0","vdai-lithuania-3r-1143-41d209","VDAI (Lithuania) - 3R-1143",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]