Search
Contact
19.07.2019 | KPMG Law Insights

Hague hospital fined up to 760,000 euros

Hague hospital fined up to 760,000 euros

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has imposed a fine of 460,000 euros on a hospital for failing to protect patient records from unnecessary access in the hospital information system. According to the report, at least 85 hospital employees unnecessarily and unauthorizedly accessed the medical records of a known patient without being involved in the patient’s care.

The regulator made it clear in its press release that the relationship between a healthcare provider and a patient is completely confidential. This also applies within the walls of a hospital. A hospital must therefore take all technical and organizational measures to ensure the security of patient data. Each hospital would need to regularly review who consults which record. This is the only way to take timely action if an unauthorized employee accesses a file.

Patient files should also be technically secured with at least two-factor authentication. Each time a patient record is accessed, a user’s identity would have to be logged by a code or password in combination with a personnel card. Uniform passwords for entire departments or the use of a common user name to avoid having to log in again each time are not permissible.

In order to implement these requirements effectively and as quickly as possible, the supervisory authority is putting the hospital under further pressure: as long as the safety precautions have not been improved, the hospital must pay an additional fine of another 100,000 euros every two weeks, up to a maximum of 300,000 euros. As a result, the hospital faces a maximum fine of 760,000 euros.

Already in October last year, a fine of 400,000 euros was imposed on a hospital in Portugal for a similar violation. The reason for this was also the lack of security of the patient file against access by non-treating medical staff. Even if the national supervisory authorities are in principle free to determine the level of fines, a comparable level of fines must also be expected in Germany for the inadequate security of patient records due to inadequate authorization concepts in hospital information systems.

Explore #more

17.04.2025 | KPMG Law Insights

What the coalition agreement means for the financial sector

The coalition agreement between the CDU/CSU and SPD also has an impact on the financial sector. Here is an overview. Increasing the energy supply The…

17.04.2025 | KPMG Law Insights

AWG amendment provides for tougher penalties for sanction violations

Due to the ongoing Russian war of aggression against Ukraine, the EU wants to make it easier to prosecute violations of EU sanctions. The corresponding…

16.04.2025 | KPMG Law Insights

What the new digitization plans in the coalition agreement mean

The coalition agreement shows how the future government wants to shape Germany’s digital future. What do the plans mean for companies in concrete terms? Here…

14.04.2025 | KPMG Law Insights

How the new coalition wants to accelerate investment in infrastructure

The coalition agreement between the CDU/CSU and SPD marks a fundamental new beginning in German infrastructure policy. In view of a considerable investment backlog, the…

14.04.2025 | KPMG Law Insights

Coalition agreement 2025 and NKWS: Booster for environmental and planning law?

In the current coalition agreement, environmental and planning law is mentioned at various points throughout the coalition agreement, highlighting its great importance. However, the…

11.04.2025 | KPMG Law Insights

What’s next for foreign trade? The plans in the 2025 coalition agreement

Foreign trade and foreign trade have become particularly explosive in view of the new US tariffs. The CDU/CSU and SPD have agreed on the following…

11.04.2025 | KPMG Law Insights

Coalition agreement 2025: What the plans mean for the economy

The CDU/CSU and SPD have agreed on a coalition agreement. The central theme is the renewal of the promise of the social market economy. The…

10.04.2025 | KPMG Law Insights

Coalition agreement 2025: Housing construction on the move

In the coalition agreement, the CDU/CSU and SPD have agreed comprehensive reform plans in the area of housing construction. The aim is to speed…

10.04.2025 | KPMG Law Insights

Energy in the 2025 coalition agreement: what the future government is planning

In the coalition agreement, the CDU/CSU and SPD commit to the German and European climate targets and Germany’s climate neutrality by 2045. To this…

10.04.2025 | KPMG Law Insights

Focus on labor law – this is what the 2025 coalition agreement provides for

The CDU/CSU and SPD agreed on a coalition agreement on April 9, 2025. The overarching title of the paper is “Responsibility for Germany”. On 146…

Contact

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

Maik Ringel

Senior Manager

Münzgasse 2
04107 Leipzig

Tel.: +49 341 22572563
mringel@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll