Skip to content
Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Istituti ospedalieri bergamaschi: Insufficient technical and organisational measures to ensure information security

€45,000 Fine
Istituti ospedalieri bergamaschi
ITALY
Art. 5 GDPR Art. 9 GDPR Art. 32 GDPR

How it connects

Full text

The Italian DPA (Garante) has imposed a fine of EUR 45,000 on Istituti ospedalieri bergamaschi. The DPA initiated an investigation against the controller after it reported a data breach to the DPA. A patient had mistakenly received medical records and clinical documentation from seven other patients in his digital medical record.

Industry: Health Care

Similar Content