Details:

Summary The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the controller after it reported a data breach to the DPA. A patient had mistakenly received medical records and clinical documentation from another patient in his digital medical record.
Link: link
Related articles:  Art. 5 (1) f) GDPR, Art. 9 GDPR
Type: Insufficient legal basis for data processing
Fine: EUR 3,500
Sector Health Care

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law