Italian Health Agency Fined €24K for Lax EHR Access Controls and Insufficient Audit Logging
The University Health Agency of Friuli Centrale failed to restrict access to electronic health records based on the principle of least privilege, allowing staff to access sensitive patient data for administrative purposes unrelated to care. Compounding this, audit logs were inadequate and no automatic session lockout or anomaly detection systems were in place, leaving violations undetectable for extended periods. This matters because healthcare data is among the most sensitive personal information, and permissive access combined with poor monitoring creates a high risk of both accidental and intentional misuse. The GDPR mandates that data controllers implement technical and organisational measures — including data protection by design — to ensure access is granted only where necessary and that processing activities are continuously monitored.
Tactical Insight
Immediate actions
- Audit all current user roles and revoke access to electronic health records for any accounts whose duties do not require direct patient care.
- Enable automatic session lockout on all EHR systems after a defined period of inactivity to reduce exposure from unattended terminals.
Long-term improvements
- Implement a formal Role-Based Access Control (RBAC) framework that maps each job function to the minimum data access required for that role.
- Embed data protection by design principles into all future system procurement and configuration processes, requiring vendors to demonstrate built-in access controls.
- Establish a periodic access review cycle (at least quarterly) to validate that user permissions remain appropriate as roles change.
Detection measures
- Deploy an automated anomaly detection system that flags unusual access patterns, such as bulk record retrieval or off-hours access, for immediate review.
- Ensure access logs capture sufficient detail (user ID, timestamp, record accessed, action performed) and retain them for the period required by applicable law.
- Configure real-time alerting for privileged account activity and integrate log data into a centralised SIEM platform.