News
Lack of Security and Failure to Report Data Breach โ๏ธ
Administrative sanction against two doctors of 3,000 and 6,000 Euros, following a data leak.
Source: SAN 2019-014
๐ Context:
Thousands of medical images belonging to two physicians were made publicly accessible on the internet due to:
- ๐ถ Improper configuration of their internet router.
- ๐ฅ๏ธ Misconfiguration of their medical imaging software.
โ Identified Violations:
๐ Failure to Ensure Data Security (Article 32 of GDPR):
The CNIL found that the two physicians:
-
- ๐ซ Did not adhere to basic principles of IT security.
- โ Did not ensure that their IT network configuration prevented unrestricted access to data
๐ Did not systematically encrypt hosted personal data.
๐ข Failure to Notify Data Breach (Article 33 of GDPR):
-
- The physicians did not report the data breach to the CNIL, even after being informed that their patients’ medical images were freely accessible online.
โ๏ธ Consequences:
๐ Administrative fines (December 7, 2020): €3,000 and €6,000.
๐ Public sanction aimed at raising awareness among healthcare professionals.
๐ฏ Purpose of Public Decisions:
The CNIL’s restricted committee aims to:
- โ๏ธ Raise awareness among healthcare professionals about their obligations.
- ๐ก๏ธ Emphasize the importance of vigilance in securing personal data.