Italian Health Agency Fined €24K for Weak EHR Access Controls and Missing Anomaly Detection
The University Health Agency of Friuli Centrale failed to enforce the principle of least privilege within its electronic health record (EHR) system, allowing staff access to sensitive patient data — including Covid-19 results and surgical records — beyond what their care role required. Compounding this, the system's automatic screen lockout inactivity timeout was set to an inappropriately long interval, increasing the risk of unauthorized access to unattended sessions. Perhaps most critically, the agency had no mechanism in place to detect anomalous or unauthorized data processing activities, meaning breaches could go unnoticed indefinitely. In healthcare, where patient data is among the most sensitive personal information, these combined failures represent serious non-compliance with GDPR's data minimization and integrity principles and create real risk of harm to patients.
Tactical Insight
Immediate actions
- Audit and restrict EHR system access roles so that staff can only view patient records directly relevant to their care responsibilities.
- Reduce automatic screen/session lockout inactivity timeouts to a maximum of 5 minutes on all systems handling sensitive health data.
Long-term improvements
- Implement role-based access control (RBAC) with regular access reviews (at least quarterly) to ensure permissions remain appropriate as staff roles change.
- Deploy a User and Entity Behavior Analytics (UEBA) or Security Information and Event Management (SIEM) solution to automatically flag anomalous data access patterns in the EHR system.
- Conduct a formal Data Protection Impact Assessment (DPIA) for all systems processing special category health data under GDPR Article 35.
Detection & monitoring measures
- Establish audit logging for all access to sensitive patient records, with automated alerts triggered by bulk downloads, off-hours access, or access to records outside a clinician's assigned patient list.
- Appoint or empower the Data Protection Officer (DPO) to perform periodic access control compliance reviews aligned with GDPR accountability requirements.