# Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Italian Data Protection Authority (Garante)
- Date: 2025-09-11
- Original: https://www.enforcementtracker.com/ETid-2889
- Canonical: https://overview.legal/posts/49004
- Topics: Healthcare, Health Data, Security, Controllers, Processing Agreement, Supervisory Authorities, Data Controller

## Summary

The Italian DPA has imposed a fine of EUR 12,000 on the Casa di Cura Città di Roma. The controller used patient management software that gave users access to excessive amounts of patient data.

## Full text

The Italian DPA has imposed a fine of EUR 12,000 on the Casa di Cura Città di Roma. The controller used patient management software that gave users access to excessive amounts of patient data.

GDPR Articles: Art. 5 (1) a), b), c), e), f), (2) GDPR, Art. 9 GDPR, Art. 25 GDPR, Art. 32 GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/49004 · 2026-08-22
