# Public Hospital: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Portuguese Data Protection Authority (CNPD)
- Date: 2018-07-17
- Original: https://www.enforcementtracker.com/ETid-45
- Canonical: https://overview.legal/posts/46160
- Topics: Healthcare, Healthcare, Health Data, Security, Human Resources, Supervisory Authorities, Law Enforcement

## Summary

Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management system appeared deficient – the hospital had 985 registered doctor profiles while only having 296 doctors. Moreover, doctors had unrestricted access to all patient files, regardless of the doctor’s specialty.

## Full text

Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management system appeared deficient – the hospital had 985 registered doctor profiles while only having 296 doctors. Moreover, doctors had unrestricted access to all patient files, regardless of the doctor’s specialty.

GDPR Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/46160 · 2026-08-22
