Italian DPA Finds Hospital Exposed Patient Records Through Weak Access Controls and Logging
The University Health Agency of Friuli Centrale failed to adequately restrict access to electronic health records, allowing unauthorized individuals to view sensitive patient data. Insufficient logging meant the organization lacked the visibility needed to detect, investigate, and respond to unauthorized access events in a timely manner. An improperly configured automatic screen lockout period further compounded the risk by leaving workstations exposed in clinical environments. This case illustrates that healthcare organizations must treat access control and audit logging as foundational safeguards — not optional additions — especially given the sensitivity of health data under GDPR and sector-specific regulations. Without enforcing the principle of least privilege and maintaining robust audit trails, organizations cannot demonstrate accountability or effectively contain breaches.
Tactical Insight
Immediate actions
- Audit all user accounts with access to electronic health records and revoke permissions for any staff not directly involved in patient care.
- Reduce automatic workstation lockout timeout to no more than 5 minutes of inactivity across all clinical systems.
- Enable comprehensive audit logging for all access to patient health records, capturing user, timestamp, record accessed, and action taken.
Long-term improvements
- Implement role-based access control (RBAC) aligned to clinical roles, enforcing the principle of least privilege and data minimization by default.
- Conduct periodic access reviews (at least quarterly) to certify that staff permissions remain appropriate as roles change.
- Develop and enforce a formal data access policy for health records that is documented, communicated, and signed off by all relevant staff.
Detection measures
- Deploy a SIEM or log management solution to generate real-time alerts on anomalous or out-of-hours access to sensitive patient records.
- Establish a regular log review process, with defined escalation procedures when unauthorized or suspicious access is identified.
- Implement user behavior analytics (UBA) to baseline normal access patterns and flag deviations for investigation.