IMY (Sweden) - 2023-2522
| IMY - 2023-2522 | |
|---|---|
| Authority: | IMY (Sweden) |
| Jurisdiction: | Sweden |
| Relevant Law: | Article 32(1) GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 29.11.2022 |
| Decided: | 24.04.2025 |
| Published: | |
| Fine: | n/a |
| Parties: | Sjukhusstyrelsen i Region Uppsala |
| National Case Number/Name: | 2023-2522 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Swedish |
| Original Source: | IMY (in SV) |
| Initial Contributor: | cci |
The DPA reprimanded a health care provider for sending sensitive data via unencrypted emails, in violation of Article 32(1) GDPR.
English Summary
Facts
The Hospital Board of the Region of Uppsala (the controller) is responsible for providing health care at the Uppsala University Hospital and the Enköping Hospital.
On 29 November 2022 the DPA received a report about a data breach regarding the controller’s processing of patients’ data. According to the report, personal data of patients (including their personal identity numbers and health data) were processed via insecure emails. The DPA started an ex officio investigation.
The investigation found that the controller implemented an email encryption tool (on top of standard, in-transit encryption) in order to secure internal emails. The controller required all its staff to use the tool to encrypt any sensitive data sent via internal emails. However, the staff did not always follow this policy: at least 15 emails were sent unencrypted between 2010 and 2022. The DPA noted that this practice potentially exposed personal data in certain situations: for instance, if a staff member accidentally forwarded an email to an unintended recipient, the recipients would be able to read it. The risk of unintended disclosure was especially high because the controller did not monitor traffic to and from the email accounts of its staff.
Additionally, DPA found that the controller used automated messaging system relating to identify number merging. These messages were unencrypted and contained personal data of patients.
Holding
The DPA held that the controller failed to implement proper security measures, in violation of Article 32(1) GDPR.
The DPA issues a warning against the controller but considered a fine to be unnecessary. In this regard, the DPA considered that the controller already took steps to address its lacking security before the decision. In particular, the controller:
- carried out a risk and vulnerability analysis;
- deleted the emails containing unencrypted sensitive data;
- better instructed the staff about its data policy;
- changed its automated messaging system;
- implemented a system to warn staff members that they were about to send emails containing personal identity numbers, in order to prevent accidental disclosures.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details.
1(9) Uppsala Regional Hospital Board Registration number: IMY-2023-2522 Decision after supervision according to Your registration number: data protection regulation – SHS2023-00030 Date: Uppsala Regional Hospital Board 2025-04-24 Decision of the Privacy Protection Authority The Privacy Protection Authority (IMY) finds that the Uppsala Regional Hospital Board from 25 May 2018 to 29 November 2022, in its capacity as data controller , has processed personal data in violation of Article 32(1) of the Data Protection Regulation by not having taken appropriate technical and organizational measures to ensure a level of security that is appropriate in relation to the risks of the processing of patients' personal data in the business's email service. IMY reprimands the Hospital Board in the Uppsala Region based on Article 58.2 b of the Data Protection Regulation for the established violation. Statement of the supervisory case Background The Hospital Board in the Uppsala Region (hereinafter the Hospital Board) conducts and performs care in accordance with the Health and Medical Services Act (2017:30), HSL, at Uppsala Academic Hospital and the Hospital in Enköping. On November 29, 2022, IMY received a notification of a personal data incident that occurred within the framework of the Hospital Board's care operations. The notification concerned the discovery that personal data about patients, including personal identification numbers and health information, during the period 2014–2022, had been processed in the Microsoft Outlook e-mail service. According to the notification, the incident was due to inadequate organizational routines or processes. Following the notification, IMY initiated supervision of the Hospital Board with the aim of checking whether the Hospital Board, in its activities as a healthcare provider according to HSL, has taken appropriate measures to ensure the protection of patients' Postal address: personal data when processing their personal data in the Microsoft Box 8114 104 20 Stockholm Outlook email service. As part of the supervision, an on-site inspection was carried out on 8 March 2023 at the Hospital Board's premises. Website: www.imy.se IMY's review covers the question of whether the Hospital Board meets the security requirements Email: imy@imy.se set out in Article 32 of the Data Protection Regulation regarding the processing of personal data in the email service. The examination of the case has been limited to the question of whether Telephone: The Hospital Board has taken sufficient organizational and technical measures to 08-657 61 00Integrity Protection Authority Case number: IMY-2023-2522 2(9) Date: 2025-04-24 prevent and detect unauthorized processing of personal data in the email service. The review does not cover whether the processing is compatible with the regulations in the Data Protection Regulation in general. The Data Protection Regulation began to apply on 25 May 2018. IMY's supervision therefore covers the period from 25 May 2018 to 29 November 2022 when the notification of the personal data incident was received. Previous decisions On 26 January 2022, the IMY issued an administrative sanction against the Hospital Board after finding that the Hospital Board had processed personal data in violation of Articles 5(1)(f) and 32(1) of the Data Protection Regulation by sending unencrypted sensitive personal data to patients and remitters in third countries and storing sensitive personal data in the email service (DI-2021-5595). The supervision was initiated in light of a personal data incident that was received by IMY in 2019. IMY assessed that the Hospital Board had not taken appropriate technical and organizational measures to ensure a level of security that was appropriate in relation to the risk of the processing. Statement from the Hospital Board Within the framework of the supervision, the Hospital Board has stated, among other things, the following. Personal data responsibility The Hospital Board operates and provides care in accordance with HSL at Uppsala Academic Hospital and the Hospital in Enköping. The Hospital Board is the personal data controller according to Chapter 2, Section 6 of the Patient Data Act (2008:355), PDL. It is thus the personal data controller when it processes personal data about patients according to the purposes in Chapter 2, Section 4 of the PDL, such as documenting information in patient records. General information about the e-mail service Within the operations at Uppsala Academic Hospital and the Hospital in Enköping , the e-mail service Microsoft Outlook has been used since 2014. Microsoft provides the operation of the e-mail service in its data centers and provides support to Region Uppsala's administrative object Digital Workplace, which in turn administers the service within the region. The current e-mail service has around 8,300 users within the Hospital Board's operations, of which the majority (around 6,400) work with care. The personal data incident When processing a request for a register extract on November 24, 2022, it was discovered that personal data about patients had been sent in an email between employees within the framework of the Hospital Board's healthcare operations. The email stored in the email service contained Excel files with information about patients, including their name, social security number, number of hospital visits and number of days of care. After this discovery, the Hospital Board launched an investigation and then found additional unencrypted emails that had been sent during the period 2010–2022 containing personal data about patients. During the investigation, 15 e-mails with personal information about patients were discovered, as well as a recurring automatic mailing for personal identification number mergers.Integrity Protection Authority Case number: IMY-2023-2522 3(9) Date: 2025-04-24 The e-mails were between hospital staff and there were no indications of direct e-mail conversations between healthcare staff and patients. Technical and organizational measures There are governing document management plans for Uppsala University Hospital and Enköping Hospital, which state which documents and information volumes are handled, in which systems they should be stored and how long the information should be kept. There is also an archive manual that generally describes rules and procedures for disposal, including the disposal of e-mail, and a preservation and disposal plan for administrative documents, which sets out specific rules for the disposal of e-mail. When an e-mail message is received, the starting point is that it should be handled and registered in the system where the documents belong. The documents should then be deleted from the e-mail service. Correspondence of temporary and minor importance can be deleted if no longer relevant. At a regional level, there are guidelines and decisions stating that sensitive information should not be handled via e-mail. Uppsala Academic Hospital and Enköping Hospital each have their own rules for handling e-mail, which state that sensitive information, such as confidential information and sensitive personal data, may not be included in e-mail unless the files are encrypted. By default, e-mail is encrypted with TLS during transport. However, it cannot be guaranteed that all e-mail is encrypted with TLS during transport as this setting depends on the recipient/sender. If e-mail is used to send sensitive information, it must be encrypted using the encryption solutions that Region Uppsala has approved for sending such information. It is also stated in a regional director's decision from 2019 and in the guideline Information security for employees that if e-mail is to be used for sensitive information, the information must be encrypted. Other information channels where the importance of secure email is emphasized include, for example, manager letters and mandatory training courses. Despite the measures taken, there may be individuals who, out of ignorance or by mistake, email sensitive personal information unencrypted. The Hospital Board considers the maturity level regarding the secure handling of sensitive information to be high. However, since healthcare personnel do not primarily work in the email service, there is a risk that routines for the correct handling of sensitive information will become less known. Individual employees' email content is not monitored. Employees work based on a trust that is obtained in connection with employment to follow the internal regulations regarding storage and disposal. Only the individual employee has access to their email and can delete their emails that contain sensitive information. When an employee leaves, the email account is closed and all emails are deleted, but there is no permanent, technical functionality to automatically filter emails. However, work is underway to review the conditions for filtering emails older than 2014. Actions after the incident When the incident was discovered, it was reported to the data protection officer and meetings were called to quickly investigate the scope of the incident and to assess the type of information that was found. A group was appointed with responsibility for handling the incident and identifying and implementing the immediate actions that were required. In the emergency situation after the incident was discovered and reported, the identified emails were filtered. The emails that had previously been automatically generated were also deleted. Information was sent to employees to, among other things, clarify how sensitive personal data is handled correctly. The Hospital Board completed a risk and vulnerability analysis in the spring of 2022 – i.e. after IMY's previous decision (DI-2021-5595). This resulted in a list of measures (the activity list) to address a number of identified risks linked to, among other things, email handling. In connection with the current incident, the ongoing work on the activity list was re-prioritized. Work is ongoing on the identified measures. Examples of measures that have been implemented include investigating options for filtering out subsets of the email service and introducing functions in the email service that can inform and warn users who attempt to send emails containing personal identification numbers. The ability to send secure messages between users has been launched and work is also underway to connect the Uppsala Region to the national service Secure Digital Communication provided by the Digital Governance Authority (DIGG). As for the automatic mailings, they shall cease in the form that existed at the time of the incident. Justification of the decision Applicable rules Responsibility of the controller The controller is the person who alone or jointly with others determines the purposes and means of the processing of personal data. If the purposes and means of the processing are determined by Union law or the national law of the Member States, the controller or the specific criteria for his or her appointment may be prescribed in Union law or the national law of the Member States. This is stated in Article 4(7) of the Data Protection Regulation. According to Chapter 2, Section 6, first paragraph, of the PDL, a healthcare provider is the data controller for the processing of personal data carried out by the healthcare provider. In a region and a municipality, each authority that provides healthcare is the data controller for the processing of personal data carried out by the authority. The data controller has a responsibility to implement appropriate technical and organizational measures to ensure and demonstrate that the processing of personal data is carried out in accordance with the Data Protection Regulation. This is stated in the fundamental principles in Article 5, but is also regulated in Article 24 of the Regulation. The measures shall be implemented taking into account the nature, scope, context and purpose of the processing and the risks, of varying likelihood and severity, for the rights and freedoms of natural persons. The measures shall be reviewed and updated when necessary. 1https://www.digg.se/saker-digital-kommunikationIntegritetskyddsmyndigheten Case number: IMY-2023-2522 5(9) Date: 2025-04-24 The requirement for security when processing personal data, etc. Health data constitutes so-called sensitive personal data. It is prohibited to process such personal data according to Article 9(1) of the Data Protection Regulation, unless the processing is covered by one of the exceptions in Article 9(2) of the Regulation. Article 32(1) of the Data Protection Regulation states that the controller shall take appropriate technical and organizational measures to ensure a level of security that is appropriate in relation to the risk of the personal data processing. This shall be done taking into account the latest developments, the implementation costs and the nature, scope, context and purposes of the processing, as well as the risks, of varying degrees of likelihood and severity, to the rights and freedoms of natural persons. This includes, where appropriate, the ability to ensure the confidentiality, integrity, availability and resilience of the processing systems and services at all times, and a procedure for regularly testing, examining and evaluating the effectiveness of the technical and organisational measures to ensure the security of the processing. In assessing the appropriate level of security, particular account shall be taken of the risks presented by the processing, in particular from accidental or unlawful destruction, loss or alteration or from unauthorised disclosure of or access to the personal data transmitted, stored or otherwise processed. This is stated in Article 32(2) of the GDPR. Recital 75 of the GDPR sets out the factors to be taken into account when assessing the risk to the rights and freedoms of natural persons which may arise from the processing of personal data. Among other things, it must be taken into account whether the processing concerns personal data about health or about vulnerable natural persons, especially children, or whether the processing involves a large number of personal data and concerns a large number of data subjects. IMY's assessment Personal data responsibility The Hospital Board has stated that it operates and provides care at Uppsala Academic Hospital and the Hospital in Enköping and is the personal data controller according to Chapter 2, Section 6 of the PDL. The Hospital Board is thus the personal data controller for the personal data processing that the Hospital Board carries out within the framework of its care activities, which according to IMY includes the personal data processing that takes place when personal data about patients within the Hospital Board's operations are processed in the email service. The Hospital Board is thus the personal data controller for the processing of personal data in the email service in the case at issue. Technical and organizational measures The processing has entailed a high risk and required a high level of protection The Hospital Board conducts healthcare activities, which means that sensitive and particularly protected personal data is processed within the operations to a large extent. IMY can also state that the majority of the Hospital Board's users of the e-mail service consist of approximately 6,400 people who work with healthcare. This entails a significant risk that personal data, including sensitive and particularly protected data, may be handled in the e-mail service. That this is the case is supported by the Hospital Board's statement thatIntegritetsskyddsmyndigheten Filing number: IMY-2023-2522 6(9) Date: 2025-04-24 there is a risk that a user may accidentally send sensitive personal data in the e-mail service. The overall purpose of an email service is to be able to receive, distribute and communicate information. In a previous supervision of the Hospital Board (DI-2021- 5595), IMY has assessed that email systems are generally an unsuitable storage location for sensitive personal data. An email system is exposed to the internet, which means that the data in the system is at risk of being accessed by unauthorized persons. The fact that it is primarily the individual users who have knowledge of what data the users handle in the email service can further cause difficulties for the data controller to ensure that data is not handled in the service in an unauthorized manner. The processing of personal data in an email service thus inherently entails special risks. Against this background, IMY believes that high demands must be placed on the technical and organizational measures that the Hospital Board needs to take to ensure an appropriate level of security regarding the processing of personal data in the email service. The Hospital Board has not taken sufficient security measures As is clear from Article 32(2) of the Data Protection Regulation, when assessing the appropriate level of security, particular consideration shall be given to the risks presented by the processing, in particular from accidental or unlawful destruction, loss or alteration or to unauthorised disclosure of or access to the personal data processed. The controller shall therefore take measures to avoid personal data incidents as far as possible. 2 The measures may include, among other things, the ability to continuously ensure the confidentiality, integrity, availability and resilience of the processing systems and services, as well as a procedure for regularly testing, examining and evaluating the effectiveness of the technical and organisational measures to ensure the security of the processing. Against this background, it is important that the controller takes measures to be able to prevent and detect unauthorised processing of personal data. The investigation into the case shows that during the period in question there were central documents and rules applied within the Hospital Board and which, among other things, aim at the handling of documents and information volumes and the handling of personal data in e-mail. These state, among other things, that privacy-sensitive information such as personal identification numbers, confidential information and sensitive personal data may not appear in e-mail unless the files are encrypted with the approved encryption solution. Employees may also undergo mandatory training, including regarding information security and handling of personal data in the e-mail service. The Hospital Board had thus taken a number of measures to prevent the unauthorized processing of personal data in the e-mail service. In light of the fact that in the personal data incident in question, it emerged that sensitive and particularly protected personal data was processed in the e-mail service, it is clear, however, that employees did not follow the guidelines that existed regarding the processing of such personal data in the e-mail service. It can also be stated that there were set 2EU Court of Justice judgment of 14 December 2023, Natsionalna agentsia za prihodite, case C-340/21, ECLI:EU:C:2023:986, paragraph 30.Integrity Protection Authority Case number: IMY-2023-2522 7(9) Date: 2025-04-24 services for automatic mailings that continuously sent personal data about patients via e-mail in violation of the guidelines. According to IMY, the measures taken to prevent unauthorized processing of personal data in the e-mail service have primarily included organizational security measures, including rules, guidelines and training on how personnel working within the operation should handle sensitive data. The Hospital Board has, after the incident, taken a number of technical measures to prevent unauthorized processing, for example, functions to inform and warn users who attempt to send e-mails containing personal identification numbers. However, no such functions were in place at the time of the incident. Several of the e-mail messages involved in the incident had been stored in the e-mail service for a long time, which suggests that the Hospital Board did not have an effective procedure for following up and evaluating the effectiveness of the measures taken. The fact that the discovery of a large amount of sensitive and particularly sensitive personal data that had been processed for a long time in the e-mail service occurred when processing a request for a register extract also indicates a lack of proactive measures to detect unauthorized processing. IMY further notes that at the time of the personal data incident, it was up to individual employees to detect and delete e-mail messages containing sensitive or particularly sensitive personal data. Overall, IMY assesses that the Hospital Board has not taken sufficient measures to prevent and detect unauthorized personal data processing in the e-mail service. The Hospital Board has therefore, from 25 May 2018 to 29 November 2022, in its capacity as controller, processed personal data in breach of Article 32(1) by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks presented by the processing of patients' personal data in the email service. Choice of intervention It is clear from Article 58(2) and Article 83(2) of the GDPR that the IMY has the power to impose an administrative penalty. Depending on the circumstances of the individual case, an administrative penalty shall be imposed in addition to or instead of the other measures referred to in Article 58(2), such as injunctions and prohibitions. Article 83(2) further states which factors shall be taken into account when deciding whether an administrative penalty shall be imposed and when determining the amount of the penalty. Aggravating and mitigating circumstances in the case shall be taken into account, such as the nature, gravity and duration of the infringement and previous infringements of relevance. In the case of a minor infringement, the IMY may, as set out in recital 148, issue a reprimand in accordance with Article 58(2)(b) instead of imposing a penalty payment. The IMY has assessed above that the Hospital Board has processed personal data in violation of Article 32(1) of the Data Protection Regulation. A violation of that provision may result in a penalty fee. During the period in question, the Hospital Board has not taken sufficient technical and organizational measures to prevent and detect unauthorized processing of personal data in the e-mail service. The insufficient measures have led to a large amount of sensitive and particularly sensitive personal data being processed in the e-mail service in violation of the Hospital Board's guidelines. In a previous supervisory decision from IMY, the Hospital Board has been ordered to pay an administrative sanction fee for, among other things, a violation of Article 32(1) when handling personal data in the e-mail service (DI-2021-5595). Following IMY's previous decision, the Hospital Board completed a risk and vulnerability analysis that resulted in an activity list to address identified risks linked to, among other things, e-mail use. In connection with the personal data incident in question in this case, reprioritizations were made in the ongoing work on the activity list. The activity list shows both implemented and planned technical and organizational measures that, among other things, aim to increase the ability to prevent and detect unauthorized processing of personal data. The Hospital Board has also decided to cease the automatic mailing of personal data number mergers in the form that was current at the time of the incident. In a comprehensive assessment of the circumstances of the case, IMY considers that it is not proportionate to decide on a penalty fee for the violation that was found within the framework of this supervision. The Hospital Board shall therefore, instead of a penalty fee, be given a reprimand in accordance with 58.1 b of the Data Protection Regulation. __________________________ This decision has been made by the head of unit Christelle Bourquin after a presentation by IT and information security specialist Johnny Gordon Tornesjö. The departmental lawyer Andreas Persson has also participated in the final handling of the case. Christelle Bourquin Copy to the Data Protection OfficerIntegrity Protection Authority Filing number: IMY-2023-2522 9(9) Date: 2025-04-24 How to appeal If you wish to appeal the decision, you should write to IMY. Indicate in the letter which decision you are appealing and the change you are requesting. The appeal must be received by IMY within three weeks of the date you received the decision. If you are a party representing the public, however, the appeal must be received within three weeks of the date the decision was announced. If the appeal has been received in good time, IMY will forward it to the Administrative Court in Stockholm for review. You can e-mail the appeal to IMY if it does not contain any privacy-sensitive personal data or information that may be subject to confidentiality. The authority contact details are stated on the first page of the decision.




