The Spanish authority declares the expiration of a procedure against the Extremadura Health Service for unjustified access to a medical record

The Spanish authority closes a procedure due to expiration, the legal 12-month period to rule having been exceeded, thus annulling any possibility of sanction for unlawful access to a medical file.

Facts and context

The Spanish data protection authority (AEPD) has today published a decision to close the procedure against the Extremadura Health Service (SES) for alleged breaches related to the security of health data.

The case originated from a complaint by a patient denouncing unauthorized access to her medical record by a practitioner who did not provide care to her within the public service.

Reasons for the decision

The authority had initiated proceedings for the following potential breach:

  • Obligation of integrity and confidentiality (Article 5(1)(f) of the GDPR): The authority had initiated a sanction procedure due to alleged unlawful access to a patient's medical record by a healthcare professional. These accesses, which occurred on 2 October 2019 and 29 October 2021, would have been made outside any care relationship within the public service, which would have constituted a violation of the obligation to ensure the security of health data. An internal disciplinary procedure had already sanctioned the practitioner for one of these accesses.

However, the authority's decision is not based on the analysis of this breach but on a procedural defect. The Spanish Organic Law 3/2018 imposes a maximum period of twelve months to conclude a sanction procedure from its opening date. The procedure having been initiated on 25 October 2024, this period had expired at the date of this decision, resulting in its expiration.

Authority's decision

Consequently, the authority declared the expiration of the sanction procedure and proceeded to archive the file.

Lessons learned

This decision reminds that:

  • Compliance with internal procedural deadlines is imperative for supervisory authorities, their exceeding potentially leading to the extinction of the action and the impossibility to impose a sanction.
  • Access to a medical record by a healthcare professional outside a care relationship constitutes a serious breach of the confidentiality obligation, even if an internal disciplinary procedure has already been conducted.
  • The controller, such as a health service, remains responsible for implementing appropriate technical and organizational measures to prevent unauthorized access to health data by its own staff.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire