# Health insurance provider: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Hungarian National Authority for Data Protection and the Freedom of Information (NAIH)
- Date: 2022-09-25
- Original: https://www.enforcementtracker.com/ETid-1407
- Canonical: https://overview.legal/posts/47522
- Topics: Insurance, Healthcare, Personal Data, IP Address, Processing Agreement, Supervisory Authorities, Processing

## Summary

The Hungarian DPA has imposed a fine of EUR 1,200 on a health insurance provider. The insurer had published the result of a Covid-19 test of the data subject on its website. This would have allowed unauthorized persons to access the personal data of the data subject. In addition, the insurer had not adequately cooperated with the agency during the DPA's investigation.

## Full text

The Hungarian DPA has imposed a fine of EUR 1,200 on a health insurance provider. The insurer had published the result of a Covid-19 test of the data subject on its website. This would have allowed unauthorized persons to access the personal data of the data subject. In addition, the insurer had not adequately cooperated with the agency during the DPA's investigation.

GDPR Articles: Art. 5 (1) a) GDPR, Art. 5 (2) GDPR, Art. 12 (3), (4) GDPR, Art. 31 GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/47522 · 2026-08-22
