The Italian authority sanctions a healthcare institution for breaches related to the management of access to the electronic health record
The decision highlights the responsibility of the controller in configuring access rights to the electronic health record, including when the tool is provided by a regional entity, and recalls that the purpose of this record is strictly limited to patient care, even in the context of a health emergency.
Facts and context
The Italian data protection authority (Garante per la protezione dei dati personali - GPDP) has today published a sanction decision against the Central Friuli University Healthcare Institution (ASUFC) for breaches related to the management of access to the electronic health record.
The case originated from a complaint by an individual concerning several unlawful accesses to their electronic health record, notably to verify their Covid-19 positivity status for staff scheduling purposes.
Reasons for the decision
- Obligation of lawfulness, purpose limitation, and data minimization (Articles 5 and 9 of the GDPR): The authority found that using an employee's health record to verify their Covid-19 status for organizing shifts constituted a purpose deviation. The health record is exclusively intended for patient care purposes and cannot be used for administrative personnel management. The authority emphasized that even the health emergency context does not allow derogation from the fundamental principles of the GDPR, notably purpose limitation and data minimization, recalling that emergency legislation did not suspend the application of the GDPR but only provided regulated simplifications.
- Obligation to ensure data protection by design and by default, and processing security (Articles 25 and 32 of the GDPR): The authority found serious shortcomings in access rights management. The system configuration allowed "cross-access" to all patient records in a service, regardless of the actual care provided by the healthcare professional. Moreover, security measures, such as automatic session locking after 30 minutes of inactivity, were deemed insufficient for a high-risk environment with shared workstations, such as an emergency department. The institution, as controller, could not evade responsibility by claiming that the tool was managed at the regional level or by arguing a "systemic vulnerability."
Authority's decision
Consequently, the authority sanctioned ASUFC for the identified breaches.
Lessons learned
This decision reminds that:
- The purpose of an electronic health record is strictly limited to patient diagnosis and care activities. Its use for human resources or administrative management, even in emergency situations, constitutes a purpose deviation.
- The controller is required to implement authorization profiles and differentiated, granular access rights, ensuring that only healthcare professionals involved in a patient's care pathway can access their data.
- Technical and organizational security measures, such as session lock timeouts, must be rigorously adapted to the context and specific risks of the processing environment, particularly in high-risk areas with shared workstations.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire