Fino

Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) · 7 June 2021

MedHelp AB

Non-compliance with general data processing principles

Fine€1,200,000Fine issued
Regulator
Data Protection Authority of Sweden (Integritetsskyddsmyndigheten)
Decided
7 June 2021
Country
Sweden
Sector
Health Care
Regulator’s reference
Not recorded
Fino case number
2021/SE/004
Export as PDF

What happened

The Swedish DPA fined the company Medhelp AB €1,179,459 (SEK 12 million). Medhelp was contracted by three Swedish regions to answer calls from the medical advice hotline 1177. Medhelp violated the GDPR by exposing an unprotected server with patient data to the internet, failing to provide enough information about the transfer of data to a third country, and failing to continuously back up patient data. In addition, Medhelp employed a subcontractor to process data in Thailand contrary to Swedish healthcare law.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security
  • Special categories
  • Transparency
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/SE/004.