IMY (Sweden) - 2023-2522

From GDPRhub
IMY - 2023-2522
Authority: IMY (Sweden)
Jurisdiction: Sweden
Relevant Law: Article 32(1) GDPR
Type: Investigation
Outcome: Violation Found
Started: 29.11.2022
Decided: 24.04.2025
Published:
Fine: n/a
Parties: Sjukhusstyrelsen i Region Uppsala
National Case Number/Name: 2023-2522
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Swedish
Original Source: IMY (in SV)
Initial Contributor: cci

The DPA reprimanded a health care provider for sending sensitive data via unencrypted emails, in violation of Article 32(1) GDPR.

English Summary

Facts

The Hospital Board of the Region of Uppsala (the controller) is responsible for providing health care at the Uppsala University Hospital and the Enköping Hospital.

On 29 November 2022 the DPA received a report about a data breach regarding the controller’s processing of patients’ data. According to the report, personal data of patients (including their personal identity numbers and health data) were processed via insecure emails. The DPA started an ex officio investigation.

The investigation found that the controller implemented an email encryption tool (on top of standard, in-transit encryption) in order to secure internal emails. The controller required all its staff to use the tool to encrypt any sensitive data sent via internal emails. However, the staff did not always follow this policy: at least 15 emails were sent unencrypted between 2010 and 2022. The DPA noted that this practice potentially exposed personal data in certain situations: for instance, if a staff member accidentally forwarded an email to an unintended recipient, the recipients would be able to read it. The risk of unintended disclosure was especially high because the controller did not monitor traffic to and from the email accounts of its staff.

Additionally, DPA found that the controller used automated messaging system relating to identify number merging. These messages were unencrypted and contained personal data of patients.

Holding

The DPA held that the controller failed to implement proper security measures, in violation of Article 32(1) GDPR.

The DPA issues a warning against the controller but considered a fine to be unnecessary. In this regard, the DPA considered that the controller already took steps to address its lacking security before the decision. In particular, the controller:

  • carried out a risk and vulnerability analysis;
  • deleted the emails containing unencrypted sensitive data;
  • better instructed the staff about its data policy;
  • changed its automated messaging system;
  • implemented a system to warn staff members that they were about to send emails containing personal identity numbers, in order to prevent accidental disclosures.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details.

1(9)

Uppsala Regional Hospital Board

Registration number:
IMY-2023-2522 Decision after supervision according to

Your registration number: data protection regulation –
SHS2023-00030

Date: Uppsala Regional Hospital Board
2025-04-24

Decision of the Privacy Protection Authority

The Privacy Protection Authority (IMY) finds that the Uppsala Regional Hospital Board

from 25 May 2018 to 29 November 2022, in its capacity as data controller
, has processed personal data in violation of Article 32(1) of the Data Protection Regulation by
not having taken appropriate technical and organizational measures to ensure a
level of security that is appropriate in relation to the risks of the processing of patients'

personal data in the business's email service.

IMY reprimands the Hospital Board in the Uppsala Region based on Article 58.2 b of the Data Protection Regulation for the established violation.

Statement of the supervisory case

Background

The Hospital Board in the Uppsala Region (hereinafter the Hospital Board) conducts and performs

care in accordance with the Health and Medical Services Act (2017:30), HSL, at Uppsala Academic
Hospital and the Hospital in Enköping. On November 29, 2022, IMY received a notification
of a personal data incident that occurred within the framework of the Hospital Board's
care operations. The notification concerned the discovery that personal data about patients,

including personal identification numbers and health information, during the period 2014–2022, had
been processed in the Microsoft Outlook e-mail service. According to the notification, the incident was due to
inadequate organizational routines or processes.

Following the notification, IMY initiated supervision of the Hospital Board with the aim of
checking whether the Hospital Board, in its activities as a healthcare provider according to
HSL, has taken appropriate measures to ensure the protection of patients'
Postal address: personal data when processing their personal data in the Microsoft
Box 8114
104 20 Stockholm Outlook email service. As part of the supervision, an on-site inspection was carried out on 8 March 2023 at
the Hospital Board's premises.
Website:
www.imy.se IMY's review covers the question of whether the Hospital Board meets the security requirements
Email:
imy@imy.se set out in Article 32 of the Data Protection Regulation regarding the processing of
personal data in the email service. The examination of the case has been limited to the question of whether
Telephone: The Hospital Board has taken sufficient organizational and technical measures to
08-657 61 00Integrity Protection Authority Case number: IMY-2023-2522 2(9)
Date: 2025-04-24

prevent and detect unauthorized processing of personal data in the email service.
The review does not cover whether the processing is compatible with the regulations in
the Data Protection Regulation in general.

The Data Protection Regulation began to apply on 25 May 2018. IMY's supervision therefore covers
the period from 25 May 2018 to 29 November 2022 when the notification of
the personal data incident was received.

Previous decisions

On 26 January 2022, the IMY issued an administrative sanction against
the Hospital Board after finding that the Hospital Board had processed personal data in violation of
Articles 5(1)(f) and 32(1) of the Data Protection Regulation by sending

unencrypted sensitive personal data to patients and remitters in third countries and storing sensitive personal data in the email service (DI-2021-5595). The supervision was initiated in light of
a personal data incident that was received by IMY in 2019. IMY assessed

that the Hospital Board had not taken appropriate technical and organizational measures
to ensure a level of security that was appropriate in relation to the risk of
the processing.

Statement from the Hospital Board

Within the framework of the supervision, the Hospital Board has stated, among other things, the following.

Personal data responsibility
The Hospital Board operates and provides care in accordance with HSL at Uppsala Academic Hospital
and the Hospital in Enköping. The Hospital Board is the personal data controller according to
Chapter 2, Section 6 of the Patient Data Act (2008:355), PDL. It is thus the personal data controller
when it processes personal data about patients according to the purposes in Chapter 2, Section 4 of the PDL,
such as documenting information in patient records.

General information about the e-mail service
Within the operations at Uppsala Academic Hospital and the Hospital in Enköping
, the e-mail service Microsoft Outlook has been used since 2014. Microsoft provides the operation
of the e-mail service in its data centers and provides support to Region Uppsala's
administrative object Digital Workplace, which in turn administers the service within
the region.

The current e-mail service has around 8,300 users within the Hospital Board's
operations, of which the majority (around 6,400) work with care.

The personal data incident

When processing a request for a register extract on November 24, 2022, it was discovered
that personal data about patients had been sent in an email between
employees within the framework of the Hospital Board's healthcare operations. The email

stored in the email service contained Excel files with information about patients, including
their name, social security number, number of hospital visits and number of days of care.

After this discovery, the Hospital Board launched an investigation and then found additional
unencrypted emails that had been sent during the period 2010–2022
containing personal data about patients. During the investigation, 15 e-mails with personal information about patients were discovered, as well as a recurring automatic mailing for personal identification number mergers.Integrity Protection Authority Case number: IMY-2023-2522 3(9)
Date: 2025-04-24

The e-mails were between hospital staff and there were no indications of direct e-mail conversations between healthcare staff
and patients.

Technical and organizational measures
There are governing document management plans for Uppsala University Hospital and

Enköping Hospital, which state which documents and information volumes are
handled, in which systems they should be stored and how long the information should be kept.

There is also an archive manual that generally describes rules and procedures for disposal,

including the disposal of e-mail, and a preservation and disposal plan for administrative
documents, which sets out specific rules for the disposal of e-mail.

When an e-mail message is received, the starting point is that it should be handled and
registered in the system where the documents belong. The documents should then
be deleted from the e-mail service. Correspondence of temporary and minor importance can be deleted
if no longer relevant.

At a regional level, there are guidelines and decisions stating that sensitive information

should not be handled via e-mail. Uppsala Academic Hospital and Enköping Hospital
each have their own rules for handling e-mail, which state that sensitive information,
such as confidential information and sensitive personal data, may not be included in

e-mail unless the files are encrypted. By default, e-mail is encrypted with TLS during
transport. However, it cannot be guaranteed that all e-mail is encrypted with TLS during
transport as this setting depends on the recipient/sender. If e-mail

is used to send sensitive information, it must be encrypted using the encryption solutions
that Region Uppsala has approved for sending such information.

It is also stated in a regional director's decision from 2019 and in the guideline
Information security for employees that if e-mail is to be used for sensitive
information, the information must be encrypted. Other information channels where the importance of secure
email is emphasized include, for example, manager letters and mandatory training courses.

Despite the measures taken, there may be individuals who, out of ignorance or
by mistake, email sensitive personal information unencrypted. The Hospital Board considers the maturity level regarding the secure
handling of sensitive information to be high. However, since
healthcare personnel do not primarily work in the email service, there is a risk that routines for
the correct handling of sensitive information will become less known.

Individual employees' email content is not monitored. Employees work based on a
trust that is obtained in connection with employment to follow the internal regulations regarding
storage and disposal. Only the individual employee has access to their email and can delete their emails that contain sensitive information.

When an employee leaves, the email account is closed and all emails are deleted, but there is no permanent, technical functionality to automatically filter emails. However, work is underway to review the conditions for filtering emails older than 2014.

Actions after the incident

When the incident was discovered, it was reported to the data protection officer and meetings were called to quickly investigate the scope of the incident and to assess the type of information that was found. A group was appointed with responsibility for handling the incident and identifying and implementing the immediate actions that were required. In the emergency situation after the incident was discovered and reported, the identified emails were filtered. The emails that had previously been automatically generated were also deleted. Information was sent to employees to, among other things, clarify how sensitive personal data is handled correctly. The Hospital Board completed a risk and vulnerability analysis in the spring of 2022 – i.e. after IMY's previous decision (DI-2021-5595). This resulted in a list of measures (the activity list) to address a number of identified risks linked to, among other things, email handling. In connection with the current incident, the ongoing work on the activity list was re-prioritized. Work is ongoing on the identified measures. Examples of measures that have been implemented include investigating options for filtering out subsets of the email service and introducing functions in the email service that can inform and warn users who attempt to send emails containing personal identification numbers. The ability to send secure messages between users has been launched and work is also underway to connect the Uppsala Region to the national service Secure Digital Communication provided by the Digital Governance Authority (DIGG). As for the automatic mailings, they shall cease in the form that existed at the time of the incident. Justification of the decision Applicable rules Responsibility of the controller The controller is the person who alone or jointly with others determines the purposes and means of the processing of personal data. If the purposes and means of the processing are determined by Union law or the national law of the Member States, the controller or the specific criteria for his or her appointment may be prescribed in Union law or the national law of the Member States. This is stated in
Article 4(7) of the Data Protection Regulation.

According to Chapter 2, Section 6, first paragraph, of the PDL, a healthcare provider is the data controller for the
processing of personal data carried out by the healthcare provider. In a region and a municipality,

each authority that provides healthcare is the data controller for the
processing of personal data carried out by the authority.

The data controller has a responsibility to implement appropriate technical and
organizational measures to ensure and demonstrate that the processing of
personal data is carried out in accordance with the Data Protection Regulation. This is stated in

the fundamental principles in Article 5, but is also regulated in Article 24 of the Regulation.

The measures shall be implemented taking into account the nature, scope,

context and purpose of the processing and the risks, of varying likelihood and severity,

for the rights and freedoms of natural persons. The measures shall be reviewed and updated when
necessary.

1https://www.digg.se/saker-digital-kommunikationIntegritetskyddsmyndigheten Case number: IMY-2023-2522 5(9)
Date: 2025-04-24

The requirement for security when processing personal data, etc.
Health data constitutes so-called sensitive personal data. It is prohibited to

process such personal data according to Article 9(1) of the Data Protection Regulation, unless
the processing is covered by one of the exceptions in Article 9(2) of the Regulation.

Article 32(1) of the Data Protection Regulation states that the controller

shall take appropriate technical and organizational measures to ensure a
level of security that is appropriate in relation to the risk of the personal data processing.
This shall be done taking into account the latest developments, the implementation costs

and the nature, scope, context and purposes of the processing, as well as the risks, of
varying degrees of likelihood and severity, to the rights and freedoms of natural persons.
This includes, where appropriate, the ability to ensure

the confidentiality, integrity, availability and resilience of the processing systems

and services at all times, and a procedure for regularly testing, examining and evaluating
the effectiveness of the technical and organisational measures to ensure

the security of the processing.

In assessing the appropriate level of security, particular account shall be taken of the risks presented by

the processing, in particular from accidental or unlawful destruction, loss or

alteration or from unauthorised disclosure of or access to the personal data transmitted, stored or otherwise processed. This is stated in Article 32(2) of

the GDPR.

Recital 75 of the GDPR sets out the factors to be taken into account when

assessing the risk to the rights and freedoms of natural persons which may arise from the processing of personal data. Among other things, it must be taken into account whether
the processing concerns personal data about health or about vulnerable natural persons,

especially children, or whether the processing involves a large number of personal data and
concerns a large number of data subjects.

IMY's assessment

Personal data responsibility

The Hospital Board has stated that it operates and provides care at Uppsala Academic
Hospital and the Hospital in Enköping and is the personal data controller according to Chapter 2, Section 6
of the PDL. The Hospital Board is thus the personal data controller for the

personal data processing that the Hospital Board carries out within the framework of its
care activities, which according to IMY includes the personal data processing that takes place when
personal data about patients within the Hospital Board's operations are processed in

the email service. The Hospital Board is thus the personal data controller for the processing of personal data in the email service in the case
at issue.

Technical and organizational measures

The processing has entailed a high risk and required a high level of protection

The Hospital Board conducts healthcare activities, which means that sensitive and particularly
protected personal data is processed within the operations to a large extent. IMY can

also state that the majority of the Hospital Board's users of the e-mail service
consist of approximately 6,400 people who work with healthcare. This entails a significant risk that
personal data, including sensitive and particularly
protected data, may

be handled in the e-mail service. That this is the case is supported by the Hospital Board's statement thatIntegritetsskyddsmyndigheten Filing number: IMY-2023-2522 6(9)
Date: 2025-04-24

there is a risk that a user may accidentally send sensitive personal data in

the e-mail service.

The overall purpose of an email service is to be able to receive, distribute and

communicate information. In a previous supervision of the Hospital Board (DI-2021-
5595), IMY has assessed that email systems are generally an unsuitable storage location for sensitive
personal data. An email system is exposed to the internet, which means that

the data in the system is at risk of being accessed by unauthorized persons. The fact that it is primarily the
individual users who have knowledge of what data the users handle in

the email service can further cause difficulties for the data controller to
ensure that data is not handled in the service in an unauthorized manner. The processing of
personal data in an email service thus inherently entails special risks.

Against this background, IMY believes that high demands must be placed on the technical and
organizational measures that the Hospital Board needs to take to ensure an

appropriate level of security regarding the processing of personal data in the email service.

The Hospital Board has not taken sufficient security measures

As is clear from Article 32(2) of the Data Protection Regulation, when assessing the appropriate

level of security, particular consideration shall be given to the risks presented by the processing, in particular
from accidental or unlawful destruction, loss or alteration or to unauthorised disclosure of
or access to the personal data processed. The

controller shall therefore take measures to avoid
personal data incidents as far as possible. 2

The measures may include, among other things, the ability to continuously ensure
the confidentiality, integrity, availability and resilience of the processing systems

and services, as well as a procedure for regularly testing, examining and evaluating
the effectiveness of the technical and organisational measures to ensure
the security of the processing.

Against this background, it is important that the controller takes measures to
be able to prevent and detect unauthorised processing of personal data.

The investigation into the case shows that during the period in question
there were central documents and rules applied within the Hospital Board
and which, among other things, aim at the handling of documents and
information volumes and the handling of personal data in e-mail. These
state, among other things, that privacy-sensitive information such as personal identification numbers, confidential
information and sensitive personal data may not appear in e-mail unless the files are
encrypted with the approved encryption solution. Employees may also undergo
mandatory training, including regarding information security and handling
of personal data in the e-mail service.

The Hospital Board had thus taken a number of measures to prevent the unauthorized
processing of personal data in the e-mail service. In light of the fact that in the personal data incident in question, it emerged that sensitive and particularly

protected personal data was processed in the e-mail service, it is clear, however, that
employees did not follow the guidelines that existed regarding the processing of such

personal data in the e-mail service. It can also be stated that there were set

2EU Court of Justice judgment of 14 December 2023, Natsionalna agentsia za prihodite, case C-340/21, ECLI:EU:C:2023:986,
paragraph 30.Integrity Protection Authority Case number: IMY-2023-2522 7(9)
Date: 2025-04-24

services for automatic mailings that continuously sent personal data about
patients via e-mail in violation of the guidelines.

According to IMY, the measures taken to prevent unauthorized processing of personal data in the e-mail service have primarily included organizational security measures, including rules, guidelines and training on how personnel working within the operation should handle sensitive data. The Hospital Board has, after the incident, taken a number of technical measures to prevent unauthorized processing, for example, functions to inform and warn users who attempt to send e-mails containing personal identification numbers. However, no such functions were in place at the time of the incident. Several of the e-mail messages involved in the incident had been stored in the e-mail service for a long time, which suggests that the Hospital Board did not have an effective procedure for following up and evaluating the effectiveness of the measures taken. The fact that the discovery of a large amount of sensitive and
particularly sensitive personal data that had been processed for a long time in
the e-mail service occurred when processing a request for a register extract also indicates a
lack of proactive measures to detect unauthorized processing. IMY further notes
that at the time of the personal data incident, it was up to individual
employees to detect and delete e-mail messages containing sensitive
or particularly sensitive personal data.

Overall, IMY assesses that the Hospital Board has not taken sufficient measures to
prevent and detect unauthorized personal data processing in the e-mail service.
The Hospital Board has therefore, from 25 May 2018 to 29 November 2022, in its capacity as controller, processed personal data in breach of Article 32(1)
by failing to implement appropriate technical and organisational measures to
ensure a level of security appropriate to the risks presented by the
processing of patients' personal data in the email service.

Choice of intervention

It is clear from Article 58(2) and Article 83(2) of the GDPR that the IMY has

the power to impose an administrative penalty. Depending on the circumstances
of the individual case, an administrative penalty shall be imposed in addition to or instead of
the other measures referred to in Article 58(2), such as injunctions and prohibitions.

Article 83(2) further states which factors shall be taken into account when deciding whether an
administrative penalty shall be imposed and when determining the amount of the penalty.
Aggravating and mitigating circumstances in the case shall be taken into account, such as

the nature, gravity and duration of the infringement and previous infringements of
relevance. In the case of a minor infringement, the IMY may, as set out in
recital 148, issue a reprimand in accordance with Article

58(2)(b) instead of imposing a penalty payment.

The IMY has assessed above that the Hospital Board has processed personal data in violation of

Article 32(1) of the Data Protection Regulation. A violation of that provision may
result in a penalty fee.

During the period in question, the Hospital Board has not taken sufficient
technical and organizational measures to prevent and detect unauthorized
processing of personal data in the e-mail service. The insufficient measures have led to a

large amount of sensitive and particularly sensitive personal data being processed in the e-mail service in violation of the Hospital Board's guidelines. In a previous supervisory decision from IMY, the Hospital Board has been ordered to pay an administrative sanction fee for, among other things, a violation of Article 32(1) when handling personal data in the e-mail service (DI-2021-5595). Following IMY's previous decision, the Hospital Board completed a risk and vulnerability analysis that resulted in an activity list to address identified risks linked to, among other things, e-mail use. In connection with the personal data incident in question in this case, reprioritizations were made in the ongoing work on the activity list. The activity list shows both implemented and planned technical and organizational measures that, among other things, aim to increase the ability to prevent and detect unauthorized processing of personal data. The Hospital Board has also decided to cease the automatic mailing of personal data number mergers in the form that was current at the time of the incident. In a comprehensive assessment of the circumstances of the case, IMY considers that it is

not proportionate to decide on a penalty fee for the violation that
was found within the framework of this supervision. The Hospital Board shall therefore, instead of
a penalty fee, be given a reprimand in accordance with 58.1 b of the Data Protection Regulation.

__________________________

This decision has been made by the head of unit Christelle Bourquin after a presentation by IT and information security specialist Johnny Gordon Tornesjö. The departmental lawyer Andreas Persson has also participated in the final
handling of the case.

Christelle Bourquin

Copy to
the Data Protection OfficerIntegrity Protection Authority Filing number: IMY-2023-2522 9(9)
Date: 2025-04-24

How to appeal

If you wish to appeal the decision, you should write to IMY. Indicate in the letter which decision you are appealing and the change you are requesting. The appeal must be received by IMY

within three weeks of the date you received the decision. If you are a party representing
the public, however, the appeal must be received within three weeks of the date the decision was announced. If the appeal has been received in good time, IMY will forward it
to the Administrative Court in Stockholm for review.

You can e-mail the appeal to IMY if it does not contain any privacy-sensitive
personal data or information that may be subject to confidentiality. The authority

contact details are stated on the first page of the decision.