The Italian authority imposes a €15,000 fine on a hospital for data processing failures in the health record

The Italian data protection authority (GPDP) sanctioned a hospital for multiple failures related to the management of its computerized patient record, notably regarding information, consent, access rights, and traceability of consultations.

Facts and context

The Italian data protection authority (Garante per la protezione dei dati personali, GPDP) today published a sanction decision against the Hôpital des Collines, Monaldi-Cotugno-CTO of Naples (including the imposition of a €15,000 fine) for failures related to the management of its computerized patient record.

The case originated from an inspection conducted in January 2026, aimed at verifying the compliance of data processing via the computerized patient record, notably with regard to the authority's 2015 guidelines.

Reasons for the decision

  • Obligation of transparency and information (Article 5(1)(a) and Article 13 of the GDPR): The authority found that the information notice provided to patients was inadequate. It described processing (purposes and types of documents) broader than those actually implemented, contained incorrect legal references, and did not indicate any data retention period. The GPDP recalled, based on Recital 39 of the GDPR, that data processing modalities must be transparent to data subjects and that deletion or periodic review deadlines must be established.
  • Obligation to obtain explicit and specific consent (Article 9 of the GDPR): The hospital did not obtain specific consent for integrating data and documents related to clinical events prior to the creation of the said record. The authority emphasized that the creation of a computerized patient record is a separate optional processing requiring explicit consent. According to its 2015 guidelines, the inclusion of prior data must also be subject to separate and informed consent to ensure the data subject's freedom of choice.
  • Obligation of data protection by design and minimization (Article 5(1)(c) and Article 25 of the GDPR): Authorization profiles allowed overly broad access to data. A "patient search" function allowed doctors to search for any patient in the establishment, even if not currently treated, and to consult their service history. Moreover, the health management could consult records for administrative control purposes, which the authority deemed contrary to the care purpose of the record. The GPDP recalled that access must be strictly limited to healthcare personnel involved in the care process of the concerned patient.
  • Obligation to ensure processing security (Article 32 of the GDPR): The system did not trace simple consultation operations of records, recording only creation, modification, and deletion. The authority also noted the absence of alert systems to detect abnormal access and audit procedures for event logs. These shortcomings prevented effective access control and the ability to respond to patients' requests to know who accessed their record, violating security requirements and the recommendations of the 2015 guidelines.

Authority's decision

Consequently, the authority imposed a €15,000 fine on the Hôpital des Collines, Monaldi-Cotugno-CTO of Naples.

Furthermore, the authority ordered the publication of its decision on its website.

Lessons learned

This decision reminds that:

  • The information notice related to a computerized patient record must accurately describe its real and functional scope, including retention periods, and must not contain generic or incorrect information.
  • Consent to the creation of a computerized patient record must be granular; separate and explicit consent is required to include health data prior to its creation.
  • Access rights to the patient record must be strictly limited to healthcare personnel involved in the current care process of the patient, excluding generalized or administrative access.
  • Traceability of access to health data is an essential security measure that must imperatively include simple consultation operations, not only modification or deletion.
  • The implementation of anomaly detection systems (alerts) and audit procedures for access logs is a necessary component of the security of health data processing.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire