# Istituti ospedalieri bergamaschi: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Italian Data Protection Authority (Garante)
- Date: 2021-02-11
- Original: https://www.enforcementtracker.com/ETid-625
- Canonical: https://overview.legal/posts/46740
- Topics: Data Breaches, Healthcare, Health Data, Healthcare, Security, Processing Agreement, Controllers, Supervisory Authorities, Data Controller

## Summary

The Italian DPA (Garante) has imposed a fine of EUR 45,000 on Istituti ospedalieri bergamaschi. The DPA initiated an investigation against the controller after it reported a data breach to the DPA. A patient had mistakenly received medical records and clinical documentation from seven other patients in his digital medical record.

## Full text

The Italian DPA (Garante) has imposed a fine of EUR 45,000 on Istituti ospedalieri bergamaschi. The DPA initiated an investigation against the controller after it reported a data breach to the DPA. A patient had mistakenly received medical records and clinical documentation from seven other patients in his digital medical record.

GDPR Articles: Art. 5 (1) a), f) GDPR, Art. 9 GDPR, Art. 32 GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/46740 · 2026-08-22
