Italian Hospital Fined €24K for Granting Unauthorized Access to Patient Health Records
The Azienda sanitaria universitaria Friuli centrale failed to properly configure access controls on its electronic health record (EHR) system, allowing staff involved in shift scheduling — who had no legitimate care relationship with patients — to view sensitive patient data. This violated core GDPR principles of data minimization and purpose limitation, which require that personal data be accessible only to those who genuinely need it for the specific purpose it was collected. The misconfiguration likely stemmed from convenience-driven system setup rather than a deliberate security review, a common failure in healthcare IT environments. This case underscores that inadequate access configuration is not merely a technical oversight — it is a regulatory violation with measurable financial and reputational consequences.
Tactical Insight
Immediate actions
- Audit all EHR and health information system user roles to verify that access permissions align strictly with each role's clinical or administrative necessity.
- Revoke access rights for any staff whose job function does not require direct involvement in patient care or treatment.
Long-term improvements
- Implement Role-Based Access Control (RBAC) with clearly documented role definitions reviewed and approved by both IT security and clinical leadership.
- Establish a formal access recertification process (at least quarterly) to ensure permissions remain appropriate as staff roles change.
- Embed Privacy by Design principles into all future EHR configuration and procurement decisions to prevent purpose-limitation violations from the outset.
Detection & monitoring measures
- Deploy audit logging on all EHR access events and configure automated alerts for anomalous access patterns (e.g., scheduling staff accessing clinical records).
- Conduct periodic data protection impact assessments (DPIAs) when configuring or modifying access to systems holding special-category health data.