Breach notificationHealth data
Data breaches in healthcare due to human errors: two hospitals and a Local Health Administration Unit sanctioned by the Italian Data Protection Authority
Data breaches are violations of database security that may result not only from cyber attacks, as it is usually assumed, but also from human errors committed by persons who, under the direct authority of the data controller or the data processor, are authorized to process personal data. The absence of corporate procedures for the proper handling of patient data within a healthcare facility throughout their lifecycle or the inadequacy of these policies to cover all possible cases, in particular, can lead to material errors being made by the staff, such as the communication of patient's data to persons other than the data subject or to unauthorised persons. Such breaches in the health sector have a potentially very serious and detrimental impact on the rights of data subjects, given the special nature of the data processed, which consist of information on a person's state of health. This issue has been the subject of three recent decisions of the Italian Data Protection Authority which are briefly described in this news.
13 April 2021