Fino

Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) · 26 January 2022

Uppsala hospital board

Insufficient technical and organisational measures to ensure information security

Fine€152,000Fine issued
Regulator
Data Protection Authority of Sweden (Integritetsskyddsmyndigheten)
Decided
26 January 2022
Country
Sweden
Sector
Health Care
Regulator’s reference
Not recorded
Fino case number
2022/SE/002
Export as PDF

What happened

The Swedish DPA imposed a fine of approximately €150,000 on a hospital for a violation of Articles 5(1)(f) and 32(1) GDPR by emailing unencrypted medical records to patients and hospitals abroad.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/SE/002.