News

๐Ÿ‡ฎ๐Ÿ‡น Confidentiality: a doctor sends a file with his patients' data by email

Confidentiality & Security | 26/03/2025

๐Ÿšจ A doctor forgets the fundamental rules of the GDPR! ๐Ÿšจ๐Ÿ‡ฎ๐Ÿ‡น
๐Ÿ“ง Sending a patient list by email, a costly mistake!

To justify a work schedule change, a doctor sent an email attachment containing personal data of 13 patients, including their names, birth dates, phone numbers, treatment locations, services provided, and even payment detailsAll without a legal basis or data security! โŒ๐Ÿ”

โš–๏ธ €5,000 fine for the health authority
The
South Tyrol Health Authority ๐Ÿ‡ฎ๐Ÿ‡น, responsible for processing, was fined by the DPA for GDPR violations. Sensitive health data was illegally shared with multiple companies and external services. โŒ

๐Ÿ“Œ Violations identified:
๐Ÿ”น Violation of GDPR Articles 5(1)(c) and (f), 9, and 32: No legal basis for processing health data and lack of security.
๐Ÿ”น Failure to apply the principle of data minimization: The doctor could have transmitted the information without exposing sensitive patient data.
๐Ÿ”น Lack of appropriate technical and organizational measures: No clear directives on health data protection.
๐Ÿ”น Disclosure to multiple recipients without adequate safeguards: Some recipients were bound by medical confidentiality.

๐Ÿšจ Key takeaways:
โœ”๏ธ Never send sensitive data via unprotected email.
โœ”๏ธ Ensure every processing activity has a legal basis.
โœ”๏ธ Apply the principle of data minimization: only share what is necessary.
โœ”๏ธ Implement security measures and staff training.

โš ๏ธ Health data is highly sensitive!
A simple email can lead to
heavy sanctions and a serious breach of patient confidentiality.

Back to news list

Explore all our areas of expertise:

]]>