Haga Hospital
- Country
- Netherlands
- Fine
- 460,000 EUR
- Date
- 2019-07-16
- Sector
- Hospitals / Healthcare
- Articles
- Art. 32(1) GDPR
Not having sufficient internal security (measures) for patient records.
The Dutch Haga Hospital failed to meet the requirement of two factor authentication and regularly revies their patient files. As a result, it has not taken adequate appropriate measures as referred to in Article 32, first paragraph, of the General Data Protection Regulation (GDPR). About 200 employees had unauthorized access to the medical records of a Dutch celebrity and, moreover, personal information concerning this celebrity was leaked to the press. The AP has also decided to impose a penalty order on the Haga Hospital, which relates to the rectify this continuing violation. If Haga Hospital has not improved security before 2 October 2019, the hospital will have to pay 100,000 euros every two weeks, with a maximum of 300,000 euros.
Additional information
https://autoriteitpersoonsgegevens.nl/sites/default/files/atoms/files/haga_rapport_def.pdf
