Back to all lessons
Awareness Lessons
3 months ago

Lithuanian Medical Firm Fined €450K for Weak Access Controls Exposing 383,000 Health Records

A Lithuanian medical company failed to implement adequate technical and organizational safeguards, leaving sensitive health data of nearly 383,000 individuals exposed due to weak password policies and the absence of multi-factor authentication. Under GDPR Article 32, organizations processing sensitive personal data — especially health records — are legally obligated to apply appropriate security measures proportionate to the risk. The lack of basic access control hygiene demonstrates that compliance is not merely a checkbox exercise but requires continuous, enforceable security standards. This case highlights how foundational security failures in healthcare environments can result in both massive regulatory penalties and profound harm to data subjects whose most sensitive information is compromised.

Tactical Insight

Immediate actions

  • Enforce strong password complexity requirements (minimum 12 characters, mixed case, symbols, and numbers) across all systems handling personal data.
  • Deploy multi-factor authentication (MFA) immediately on all systems that store or process sensitive health or personal data.
  • Conduct an emergency access rights review to remove excessive or unnecessary permissions from all user accounts.

Long-term improvements

  • Implement a formal Identity and Access Management (IAM) framework with role-based access control (RBAC) and least-privilege principles.
  • Establish a recurring access certification process (at least quarterly) to validate that user permissions remain appropriate.
  • Document and maintain an up-to-date Data Protection Impact Assessment (DPIA) for all processing activities involving sensitive personal data.

Detection & compliance measures

  • Deploy a Security Information and Event Management (SIEM) solution to monitor and alert on anomalous authentication attempts and unauthorized access.
  • Schedule annual third-party security audits specifically focused on access control and data protection compliance against GDPR requirements.
  • Establish a continuous compliance monitoring program mapped to GDPR Article 32 obligations to proactively identify and remediate control gaps.