Search
Contact
19.07.2019 | KPMG Law Insights

Hague hospital fined up to 760,000 euros

Hague hospital fined up to 760,000 euros

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has imposed a fine of 460,000 euros on a hospital for failing to protect patient records from unnecessary access in the hospital information system. According to the report, at least 85 hospital employees unnecessarily and unauthorizedly accessed the medical records of a known patient without being involved in the patient’s care.

The regulator made it clear in its press release that the relationship between a healthcare provider and a patient is completely confidential. This also applies within the walls of a hospital. A hospital must therefore take all technical and organizational measures to ensure the security of patient data. Each hospital would need to regularly review who consults which record. This is the only way to take timely action if an unauthorized employee accesses a file.

Patient files should also be technically secured with at least two-factor authentication. Each time a patient record is accessed, a user’s identity would have to be logged by a code or password in combination with a personnel card. Uniform passwords for entire departments or the use of a common user name to avoid having to log in again each time are not permissible.

In order to implement these requirements effectively and as quickly as possible, the supervisory authority is putting the hospital under further pressure: as long as the safety precautions have not been improved, the hospital must pay an additional fine of another 100,000 euros every two weeks, up to a maximum of 300,000 euros. As a result, the hospital faces a maximum fine of 760,000 euros.

Already in October last year, a fine of 400,000 euros was imposed on a hospital in Portugal for a similar violation. The reason for this was also the lack of security of the patient file against access by non-treating medical staff. Even if the national supervisory authorities are in principle free to determine the level of fines, a comparable level of fines must also be expected in Germany for the inadequate security of patient records due to inadequate authorization concepts in hospital information systems.

Explore #more

09.07.2025 | KPMG Law Insights

Restructuring with staff reductions: preparation is key

The downsizing or closure of a part of a company often also necessitates staff reductions. Depending on the number of employees affected, the works council…

08.07.2025 | Deal Notifications

KPMG Law advises Finish Finnfoam Group on the acquisition of the Phonotherm business of insolvent BOSIG Baukunststoffe GmbH

KPMG Law advised Finnfoam Group (Salo/Finland) on the acquisition of the business unit “Phonotherm” from BOSIG Baukunststoffe GmbH via the newly founded Warmotech GmbH as…

07.07.2025 | Deal Notifications

KPMG Law advises HEMRO International AG on the acquisition of Xenia Espresso GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) provided legal advice to HEMRO Group, a global manufacturer of coffee grinders and grinding technologies headquartered in Zurich, Switzerland,…

04.07.2025 | KPMG Law Insights

BGH clarifies the limits of the definition of customer installations

On July 3, 2025, the BGH published the reasons for its ruling of May 13, 2025 (case no. EnVR 83/20) and provided the eagerly awaited…

02.07.2025 | In the media

Guest article by Moritz Püstow on the special fund for infrastructure

The German government wants to invest 500 billion euros in infrastructure and climate neutrality. This creates new business opportunities for the construction industry – but…

01.07.2025 | Deal Notifications

KPMG Law advised Bosch on the multinational carve-out of the entire product business of Bosch Building Technologies to investor Triton

KPMG Law advises Robert Bosch on the carve-out of the building technologies division’s product business for security and communications technology (Bosch Building Technologies) in more…

27.06.2025 | KPMG Law Insights

Hospital restructuring: three steps out of the crisis

Many clinics see their existence threatened in the short or medium term. Other healthcare facilities are also experiencing economic difficulties. Inadequate remuneration structures, staff shortages,…

27.06.2025 | In the media

KPMG Law nominated at the PMN Awards

We are delighted to have been nominated directly in two categories at the PMN Awards 2025. Our “Extended Workbench” project was nominated in the…

25.06.2025 | KPMG Law Insights

Business Travel and Assignment in the USA: What you need to know about US immigration

The recent changes in US immigration rules are causing uncertainty worldwide. In particular, since the new US government took office, processes regarding entry into the…

11.06.2025 | KPMG Law Insights

Omnibus IV brings some simplifications, especially in product law

The EU Commission proposed the fourth omnibus package on May 21, 2025. Omnibus IV contains simplifications in relation to numerous product law requirements and…

Contact

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

Maik Ringel

Senior Manager

Münzgasse 2
04107 Leipzig

Tel.: +49 341 22572563
mringel@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll