PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Portuguese hospital receives and contests 400,000 € fine for GDPR infringement

Posted on October 26, 2018June 25, 2025 by Dissent

Anna Oberschelp de Meneses and Kristof Van Quathem write:

On July 17, 2018, the Portuguese Supervisory Authority (“CNPD”) imposed a fine of 400.000 € on a hospital for infringement of the European Union General Data Protection Regulation (“GDPR”). The decision has not been made public. Earlier this week, the hospital publicly announced that it will contest the fine.

According to press reports, the CNPD carried out an investigation at the hospital which revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management system appeared deficient – the hospital had 985 registered doctor profiles while only having 296 doctors. Moreover, doctors had unrestricted access to all patient files, regardless of the doctor’s specialty. The CNPD reportedly concluded that the hospital did not put in place appropriate technical and organizational measures to protect patient data.

Read more on Covington & Burling Inside Privacy.

Related posts:

  • California fines hospitals for breaches of medical privacy
Category: Featured NewsHealthcareNon-U.S.

Post navigation

← ICO issues maximum £500,000 fine to Facebook for failing to protect users’ personal information
International privacy guardians call for stronger protection of student privacy as e-learning expands →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States
  • India backs off mandatory ‘cyber safety’ app after surveillance backlash
  • Judge orders Trump administration to halt warrantless immigration arrests in District of Columbia
  • EU court says websites on the hook for user privacy harms

RSS Recent Posts at DataBreaches.net

  • Marquis data breach impacts over 74 US banks, credit unions
  • Virginia Twins Arrested for Conspiring to Destroy Government Databases
  • Cyberattack on Puerto Rico IT vendor Truenorth hits 3 agencies
  • Easy Question, Complicated Answer: What Does It Take to Stop Workers From Snooping?
  • Update on Dos-OP’s report on Nova RaaS
©2025 PogoWasRight.org. All rights reserved.