UODO (Poland) - DKN.5131.12.2022
How it connects
References
Related across sources
Full text
The DPA reprimanded a hospital and its email service provider for a failure to implement technical and organisational measures following a data breach that involved health data of patients. English Summary. Facts. The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022 Holding. The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the control