Lithuania Lithuania

InMedica UAB

450,000 €

GDPR enforcement action by Lithuanian Data Protection Authority (VDAI) on 2026-06-19.

Rank · Sector
#17
of 273 in Health Care
Rank · Lithuania
#2
of 17
Rank · All fines
#259
of 3,069

Case details

Authority
Lithuanian Data Protection Authority (VDAI)
Date
2026-06-19
Controller / Processor
InMedica UAB
Sector
Health Care
Quoted Articles
Art. 24 (1) GDPR, Art. 32 (1) b) GDPR, Art. 5 (1) f) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Lithuanian DPA has imposed a fine of EUR 100,000 on InMedica UAB. Third parties could access the medical files of 63 data subjects, who were patients of the controller, through a data processor. The data processor did not record any misappropriation, exfiltration or downloading of personal data. In another incident a third party encrypted personal data processed in four systems for 70 minutes without authorisation, but service provision was not interrupted. In both cases the controller failed to implement adequate security measures.

Open original source Links to the regulator's original publication or another source.

Related fines