Poland Poland

University Hospital of the Medical University of Warsaw

2,120 €

GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2022-07-06.

Rank · Sector
#220
of 270 in Health Care
Rank · Poland
#101
of 111
Rank · All fines
#2,211
of 3,050

Case details

Authority
Polish National Personal Data Protection Office (UODO)
Date
2022-07-06
Controller / Processor
University Hospital of the Medical University of Warsaw
Sector
Health Care
Quoted Articles
Art. 33 GDPR, Art. 34 GDPR
Type of violation
Insufficient fulfilment of data breach notification obligations

Summary

The Polish DPA has imposed a fine of EUR 2,120 on the University Hospital of the Medical University of Warsaw. The university hospital had suffered a data breach in which a patient had received a referral from a doctor that contained, among other things, personal data (name, address, etc.) of another patient. The DPA found that neither the doctor nor the hospital informed the patient or the DPA about the data breach.

Open original source Links to the regulator's original publication or another source.

Related fines