Search
Contact
19.07.2019 | KPMG Law Insights

Hague hospital fined up to 760,000 euros

Hague hospital fined up to 760,000 euros

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has imposed a fine of 460,000 euros on a hospital for failing to protect patient records from unnecessary access in the hospital information system. According to the report, at least 85 hospital employees unnecessarily and unauthorizedly accessed the medical records of a known patient without being involved in the patient’s care.

The regulator made it clear in its press release that the relationship between a healthcare provider and a patient is completely confidential. This also applies within the walls of a hospital. A hospital must therefore take all technical and organizational measures to ensure the security of patient data. Each hospital would need to regularly review who consults which record. This is the only way to take timely action if an unauthorized employee accesses a file.

Patient files should also be technically secured with at least two-factor authentication. Each time a patient record is accessed, a user’s identity would have to be logged by a code or password in combination with a personnel card. Uniform passwords for entire departments or the use of a common user name to avoid having to log in again each time are not permissible.

In order to implement these requirements effectively and as quickly as possible, the supervisory authority is putting the hospital under further pressure: as long as the safety precautions have not been improved, the hospital must pay an additional fine of another 100,000 euros every two weeks, up to a maximum of 300,000 euros. As a result, the hospital faces a maximum fine of 760,000 euros.

Already in October last year, a fine of 400,000 euros was imposed on a hospital in Portugal for a similar violation. The reason for this was also the lack of security of the patient file against access by non-treating medical staff. Even if the national supervisory authorities are in principle free to determine the level of fines, a comparable level of fines must also be expected in Germany for the inadequate security of patient records due to inadequate authorization concepts in hospital information systems.

Explore #more

02.05.2026 | In the media

Guest article in IT Business: Business Judgement Rule in the use of AI

AI is increasingly becoming the basis for important business decisions. But what happens if the “black box” AI delivers faulty or inadequate results? Nikolaus Manthey

29.04.2026 | KPMG Law Insights

The Procurement Acceleration Act changes access to Bundeswehr contracts

The Planning and Procurement Acceleration Act, which came into force on February 14, 2026, is intended to significantly accelerate Bundeswehr procurement by allowing deviations from…

24.04.2026 | KPMG Law Insights

Correct application of the Transport Block Exemption Regulation – Guidelines for public bodies

On March 16, 2026, the European Commission adopted a comprehensively renewed state aid framework for land and multimodal transport, which came into force on…

21.04.2026 | In the media

Guest article in HR Journal: Working without borders, limited legal certainty: Managing the risks of international remote work

Cross-border home office is strategically relevant – but also an underestimated area of risk. Between permanent establishment risk and residence law hurdles, companies are faced…

16.04.2026 | KPMG Law Insights

Index clauses in commercial leases: BGH ruling opens up clawback risks for landlords

Value assurance provisions in the form of index clauses in standard commercial leases are not only subject to the restrictions of the Price Clause Act,…

16.04.2026 | In the media

Guest article in Beschaffung aktuell: Faster procurement for the Bundeswehr

With the Planning and Procurement Acceleration Act, the German government wants to make Bundeswehr procurement significantly faster. The temporary special law simplifies procurement procedures, allows…

09.04.2026 | Press releases

KPMG Law strengthens its insurance practice in Cologne with Dr. Julia Faenger

Since April 1, 2026, Dr. Julia Faenger, LL.M., has been strengthening the insurance law advice of KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) in Cologne as…

08.04.2026 | KPMG Law Insights

New Package Travel Directive 2026: Complaint management becomes mandatory

The EU is reforming the Package Travel Directive. The amendments were adopted by the European Parliament and Council in March 2026 and are expected to…

02.04.2026 | KPMG Law Insights

Building Modernization Act (GMG): What is now important for companies

The planned Building Modernization Act (GMG) is set to replace significant parts of the previous Building Energy Act (GEG). Companies in the real estate industry,…

01.04.2026 | In the media

Manager Magazin: KPMG Law in first place for legal advice

Every two years, Manager Magazin, together with the Wissenschaftliche Gesellschaft für Management und Beratung (WGMB), awards Germany’s best auditors with a “Best-in-Class” seal and evaluates

Contact

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

Maik Ringel

Senior Manager

Münzgasse 2
04107 Leipzig

Tel.: +49 341 22572563
mringel@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll