442 published accounts of health record problems from 145 countries and territories
Our own short summaries of reports from regulators, courts, parliaments and the news, published October 2024 to October 2026, found in sources in 50 languages. The kind of problem written up most often: breach (171 of 442 cases). A regulator or court decided 175 of them. In 100 more, the organization involved admitted the problem; the rest are allegations or a person's own account. The list last changed on October 7, 2026, when a case was added or taken down. These cases are not a sample: they show what is published and findable, not how common a problem is.
The Health Record Rights Index, by SuperTruth, scores how much say a person has over their own health record in 198 countries and territories. These cases illustrate the scores and never change them. We searched every one of the 198; for the other 53 we found no published account from the last two years.
Pick a kind of problem to see its share of each bar. Hover, tap or use the arrow keys on a bar for its count.
all cases that monththe kind of problem you pickeda month not yet overevery panel on the same scale, 0 to 15 cases a month
Africa47 cases, 25 countries and territoriesAmericas89 cases, 29 countries and territoriesAsia76 cases, 25 countries and territoriesEurope187 cases, 47 countries and territoriesMiddle East25 cases, 13 countries and territoriesOceania18 cases, 6 countries and territories
Each bar counts the cases whose source was published that month, October 2024 to October 2026, by region. Pick a kind of problem to see its share of each bar. Counts show what was published and what our searches found, not how often problems happen. October 2026 runs only to October 3, 2026, the newest source date, so its bars are drawn as outlines. Every case as a spreadsheet (CSV).
Lost between providers, as we file it: the record did not follow the person between providers, systems or countries.
Other: a real problem with a health record that fits none of the six. 36 cases are filed this way; they stay on this page.
Within each country, cases a regulator or court decided come first, then those the organization admitted, then allegations, then a person's own account; newest first within each.
Africa: 47 cases from 25 countries and territories
A patient told El Watan that a first laboratory reported an alarming test result. Repeat tests at two other laboratories did not confirm it, and she concluded the first result was an error.
Hospital directors and the national hospitals director said there is no single health information system, so a patient may be registered several times, exams are repeated, and transfers between hospitals happen without the patient's information reaching the receiving team.
From a Portuguese source; summary ours.
Lost between providersThe organization admitted the problemCase AGO-S001
A June 2026 fire at a public hospital in the North-West Region destroyed its medical records unit, along with its drug store and computer equipment, while the health ministry planned reconstruction.
Following a complaint, the regulator learned that several health facilities sent patient samples abroad for lab work, sharing sensitive personal data. It issued an alert reminding providers that patient consent is required.
A news report says lab results and scans at a public hospital pile up unread. Patients told reporters they waited ten days to two weeks without receiving the report on their own tests.
A Kinshasa outlet reports that Congo joined 14 African countries in US health deals that tie funding to expanded health data systems and fast reporting, while critics warn of lost control over health data and public trust.
Health workers reportedly filmed a patient during treatment and the video circulated on social media. A provincial governor told staff they must keep professional secrecy and asked managers to identify who made it.
Eswatini signed a US health funding agreement that, under the wider scheme, trades funding for access to pathogen samples and surveillance data. Critics warned the deal could expose the country's health data to abuse.
Deaf patients told investigative reporters that public hospitals rarely provide sign language interpreters, so relatives or strangers relay what clinicians say. They said this strips them of privacy and risks errors in what they are told.
A specialist told reporters that records back to 2020 were inaccessible after the national system shut down for weeks. Patients were asked to recall their own medicines, and staff logged new data in exercise books.
The minister said a private vendor held exclusive access to patients' electronic records, refused state administrative control, and switched the system off, leaving it down for two weeks. The vendor publicly disputes his account.
After a dispute over a shutdown of the national electronic records system, the regulator said it would assess how patient data is stored, retained and secured, and whether patients' rights are protected. No findings were reported.
The system's project manager said the contract expired in 2024 and an extension never came, leaving the project uncertain. Hospitals reverted to manual records and patients reported longer waits; the insurer told facilities to use a phone-based workaround.
A patient treated at a clinic abroad was refused the medical file and follow-up paperwork until a further fee was paid, the outlet reports. The file was released once the bill was settled.
The regulator found a staff member recorded a patient during treatment and the hospital showed the footage on its screens as promotion. It could not prove consent, so it must pay Sh500,000 and delete the adverts.
Sold or sharedA regulator decidedCase KEN-S005
· Office of the Data Protection Commissioner (Kenya) · archived copy
An investigation the regulator opened itself found the hospital had no process for patients' access or correction requests, shared data with third parties without agreements, and was unregistered. An enforcement notice was issued.
OtherA regulator decidedCase KEN-S002
· Office of the Data Protection Commissioner (Kenya) · archived copy
The regulator investigated on its own initiative and found no role-based checks on who received sensitive data, which led to several breaches, plus no process for access or correction requests. An enforcement notice followed.
The insurer issued a notice that a critical failure at its digital platform since 1 March had stopped pre-authorisation and eligibility checks at contracted facilities nationwide. It apologised for the disruption to patient care.
Delay or costThe organization admitted the problemCase KEN-S006
Former mineworkers home in Lesotho say incomplete mine records and poor coordination between South African and Lesotho authorities leave them without the proof a compensation fund requires. Some say they were refused with no reason given.
Lost between providersAlleged, not decidedCase LSO-S001
A retired mineworker says a medical certification about him was made when he retired, but nobody told him until four years later, when he saw the certificate.
A government agency suspended a hospital worker, accusing him of escorting journalists through wards and broadcasting live on social media. The agency said this exposed vulnerable patients and compromised their privacy, and ordered an investigation.
After posing as a patient at a public hospital, the health minister said several patients were seen together and had to describe their health problems in front of others. She ordered public facilities to see patients individually.
OtherThe organization admitted the problemCase MWI-S001
The health minister said 19 patient files had been reported missing in public hospitals since November 2024, and 349 files and 24 consultation cards were not available when needed because they sat in other departments. All were later found.
From a French source; summary ours.
Lost between providersThe organization admitted the problemCase MUS-S001
Health records clerks in public hospitals say their departments run with about half the staff they should have. Some counters close, so patients must come back the next day to collect their card and learn their follow-up date.
A patient says the doctor who treated her at a private clinic refused her a detailed report of her care. A social security doctor asked too and was refused. She needs it for a medical board.
Reporting a health ministry statement, the outlet says a five-year US funding memorandum includes an agreement to share national health data and biological samples, which the government says will follow national data protection rules.
From a Portuguese source; summary ours.
Sold or sharedThe organization admitted the problemCase MOZ-S001
A civil society leader says the terms of the health data sharing agreement are opaque and asks the ministry to publish them, including whether data sent abroad is anonymised or individual clinical records, and how long it is kept.
Photos showed patient files on a hospital floor, some soaked. Hospital management said it ran out of storage space, kept files on unusable beds, and acknowledged the store did not comply with archives law.
OtherThe organization admitted the problemCase NAM-S001
After a national telecom data leak, the health ministry confirmed attackers breached an internet-facing pharmaceutical dashboard. It said only counts of patients using services were exposed, not personal details, and took the system offline.
BreachThe organization admitted the problemCase NAM-S002
Responding to reports of consultation delays and piles of paper folders, the hospital's chief medical director said electronic records cover only two departments so far and the rest will follow in phases.
Delay or costThe organization admitted the problemCase NGA-S002
· Sahara Reporters (republishing a Daily Trust report)
A patient told reporters that each new hospital, private then public, made her repeat and pay for routine tests she had already done, because results were not transferable. A records officer said each hospital keeps its own unlinked system.
Lost between providersThe person's own accountCase NGA-S001
After an anonymous report and an inspection, the national data protection commission ordered the clinic to take down cameras in its treatment rooms, switch off sound recording and declare its system properly.
Reporters found that people arrested in a police crackdown were routinely tested, and their test results and names were then printed in national newspapers. Health workers said frightened patients are now staying away from clinics.
A national public health council said wide media coverage of arrests had exposed people's health status, noted that unauthorised disclosure is punished under a 2010 law and may engage state liability, and warned people may avoid testing.
BBC reported that a gendarmerie press release quoted a medical certificate from a test that police had ordered on a person in custody, including what it found.
The regulator found the lab had suffered breaches and not notified affected people within a reasonable time. It ordered better security and notification processes, then fined the lab R100,000 for not complying. The lab paid.
Launching a records digitisation drive, the provincial health MEC said patients' care had been interrupted by misplaced records, delayed care and lost files, compromising patient safety and exposing the department to legal claims.
OtherThe organization admitted the problemCase ZAF-S003
A hospital official said staff left and patient files and data stayed inside after the building was taken over. Displaced patients lost the link to their records and doctors, and some now carry their own papers between centres.
From an Arabic source; summary ours.
Lost between providersThe organization admitted the problemCase SDN-S001
An investigative outlet found that a regional authority published online a named list of disabled people holding taxi licences, revealing health information about each person, while the national data protection regulator remains frozen.
A man held in several prisons says that after he was moved to a new prison, staff ignored his medical file, and care arrangements agreed at earlier prisons were dropped.
From a French source; summary ours.
Lost between providersThe person's own accountCase TUN-S002
A reporter found patients from inland regions carrying bags of scans and test results between hospitals, because regional and university hospital systems do not share data. An older patient said nothing moves unless he hands over paper in person.
From an Arabic source; summary ours.
Lost between providersThe person's own accountCase TUN-S003
A clinic recorded a wrong test result for a man that later tests did not support, and acted on it for years. The error surfaced when he applied for a benefit. The High Court found negligence and awarded damages.
A man brought to a hospital under guard says staff passed his test results to the officers holding him and never gave or explained them to him. He also says the hospital recorded him under another name.
In a negligence case, the High Court found a nurse had shaded over an original entry on a patient's form instead of striking it out. It accepted this was human error and dismissed the claims.
Record wrongA court decidedCase ZMB-S001
· National Assembly of Zambia, Public Accounts Committee (report on the Auditor General's 2024 accounts)
Auditors found clinic staff with full system rights and 528 shared administrator accounts in the national electronic patient record. The ministry told Parliament that staff going on leave handed their passwords to colleagues.
OtherThe organization admitted the problemCase ZMB-S002
· National Assembly of Zambia, Committee on Health, Community Development and Social Services
Evidence summarised by a parliamentary committee said the national health insurer's own database still held inaccurate patient records, so some hospital claims were rejected because patients' sex was wrongly recorded as male.
A fire in a storage building at a large public hospital destroyed patient records going back almost twenty years, according to a news report published after the health minister toured the damage.
OtherAlleged, not decidedCase ZWE-S001
Americas: 89 cases from 29 countries and territories
The national medical association said a fire at a shared medical building destroyed the offices, equipment and years of patient records of six doctors' practices, a loss it called a blow to the patients who rely on them.
In a court claim reported by the outlet, a patient alleges that she asked a private clinic several times for her medical records and never received them. No defence had been filed.
A formal complaint to the Ministry of Health alleges that staff at a public hospital falsified a patient's records to justify keeping her longer. The Ministry opened an internal review and has not published findings.
A fact-checking investigation found at least 40 purchase files on the insurer's public procurement search showing members' clinical histories, test results and ID copies. The insurer called it a serious anomaly, removed the files and opened internal inquiries.
From a Spanish source; summary ours.
BreachThe organization admitted the problemCase ARG-S004
A ransomware attack encrypted the shared databases of three large testing and laboratory centres, affecting thousands of patients for ten days. The group said no patient data was taken, but labs closed and reports were handed out manually.
From a Spanish source; summary ours.
Delay or costThe organization admitted the problemCase ARG-S001
Attackers claimed to be selling 700 GB from a national government health database, including clinical records and personal details of up to 52 million people. A national deputy filed requests for information. The leak was unconfirmed.
Criminals put up for sale 665,128 medical test results with patients' personal details, taken from a company that stores imaging for about 30 clinics and hospitals in several provinces. After extortion failed, the data went on sale.
A patient said she applied for her own hospital records and paid the fee, but nearly three months later still had not received them, stalling an official application. She alleged staff help faster if tipped.
A patient said a private hospital refused to release her records despite letters from her lawyer since the previous year. She wanted them to understand her past care. Her lawyer said he would go to court to obtain them.
A friend acting for a patient said a private hospital denied their request for the patient's medical records, citing hospital policy, after something went wrong in the patient's care. No one from the hospital had met them to explain.
Relatives of an adult patient said in a constitutional claim that a written request for his clinical record went unanswered. His lawyer later acknowledged obtaining copies. The Constitutional Court denied protection without examining the merits.
Data about a woman's medical test could be opened directly from a major search engine, with no password. A Santa Catarina court found two clinics failed to protect it and upheld R$5,000 in damages, ordering the data removed.
From a Portuguese source; summary ours.
BreachA regulator decidedCase BRA-S004
· Tribunal Regional do Trabalho da 4ª Região (Rio Grande do Sul) · archived copy
A hospital nursing technician opened another person's record 18 times, though she was not caring for her, over a personal dispute. A labour court in Rio Grande do Sul upheld her dismissal for cause.
Minas Gerais consumer authority Procon fined a pharmacy chain over stores requiring customers' CPF at the counter. The decision warned hidden profiling of purchases could expose medicine records, for example to insurers refusing cover.
A ransomware attack on an organisation running public health units in several states affected records of about 500,000 patients. The data authority opened a sanction case, citing poor notice to those affected. The operator denies any data leaked.
Ontario's privacy commissioner found several workers at an Ontario hospital network opened patient records without authority between 2023 and 2025. In one breach up to 326 patients were affected, and some were not told for ten months.
BreachA regulator decidedCase CAN-S004
· Information and Privacy Commissioner of Ontario (PHIPA Decision 332) · archived copy
A patient in Ontario asked their doctor for access to their health information and got no reply within the legal time limit. The commissioner treated the silence as a refusal and ordered the doctor to respond.
Access refusedA regulator decidedCase CAN-S001
· Office of the Information and Privacy Commissioner for British Columbia (Order F26-09) · archived copy
A patient in British Columbia asked for her own hospital records. The health authority released them but blacked out three sentences. The commissioner found no good reason to withhold them and ordered them disclosed.
Access refusedA regulator decidedCase CAN-S002
· Office of the Saskatchewan Information and Privacy Commissioner (Investigation Report 266-2024, 031-2025) · archived copy
An employee opened the electronic health records of 70 people in Saskatchewan 210 times without a work reason. The commissioner found the health authority did not contain the breach properly or tell those affected enough.
A clinic refused to give a deceased patient's record to some of his children, saying all heirs had to ask together. The appeals court called the refusal illegal and arbitrary and ordered a full copy delivered within three working days.
After a cyberattack slowed the national public health institute's systems, confirmatory results for patients in at least seven hospitals took about 30 days instead of 12 to 15. The institute blamed a switch to a manual system.
From a Spanish source; summary ours.
Delay or costThe organization admitted the problemCase CHL-S004
For about 48 hours, a people-search website let anyone enter a Chilean ID number and see that person's diagnoses under the national guaranteed-care scheme, alongside address and contact details. Police and the cybersecurity agency are investigating.
A ransomware group reportedly took about 250 GB from a private clinic, including clinical records, test results and identity card copies. Chile's consumer agency ordered the clinic to report how many patients were affected and how they were told.
Sensitive details from a woman's health record reached third parties without her consent. The data protection regulator found the hospital and her health insurer at fault and ordered five corrective measures, including staff training and stronger confidentiality.
During a workplace illness review, a health insurer sent a patient's complete record, including sensitive test results, to four managers at the patient's employer. The data protection regulator sanctioned the insurer, saying the disclosure had no necessity or relevance.
Clinic staff shared a woman's personal and medical details with an outside organisation, which then called and messaged her. The Constitutional Court ruled her privacy was violated and ordered the clinic to apologise publicly and investigate its staff.
The national health regulator confirmed unauthorised access to its document system. Reports say files downloaded included medical histories and patients' petitions and complaints, about 1.6 percent of its document store.
From a Spanish source; summary ours.
BreachThe organization admitted the problemCase COL-S004
Two television channels broadcast images of a person's medical prescriptions taken from a confidential case file. The constitutional court ruled this violated his privacy, ordered every image removed and made the channels liable for damages.
A data centre failure took the public insurer's digital health record and app offline for hours. Users could not view their records or appointments, and the insurer told clinics to contact affected patients and rebook them.
From a Spanish source; summary ours.
Delay or costThe organization admitted the problemCase CRI-S003
A patient found a specialist appointment he never requested in his digital health record. The public insurer said a clerk mistyped an ID number, cancelled the appointment and said it has no statistics on similar errors.
From a Spanish source; summary ours.
Record wrongThe organization admitted the problemCase CRI-S002
A patient found entries in his digital health record showing medicines given in a hospital department he says he never visited. He complained to the hospital, says no clear answer came, and went public. Officials say it is being investigated.
A patient said her earlier care history stayed on paper and was never moved into the national digital record. She also said she cannot easily give a private doctor access to her own record.
From a Spanish source; summary ours.
Lost between providersThe person's own accountCase CRI-S005
A reported feature on complaints about medical errors finds that patients and families struggle to get the complete record, which stays with the institution, and that access can be limited or delayed.
An adult prisoner told the outlet that after a hospital stay he was given no medicines in prison and could not learn what the specialist had prescribed, because he had never been given access to his medical record.
The outlet reports that the mother of an adult woman in prison asked the clinic director for her daughter's medical file and was refused. She fears the record lists consultations and treatments that never happened.
A video of a patient receiving hospital care circulated on social media. The hospitals authority called it a breach of privacy, condemned its sharing, and said staff found involved would face strict discipline.
BreachThe organization admitted the problemCase DMA-S001
A woman found her health insurance file listed an unknown man as her husband. The regulator fined the insurer, which moved 1,708 people onto its books without consent between 2023 and 2025 using invented family records.
A health insurance member has sued doctors and former insurer staff, saying they pulled her file from a confidential database and forged her signature to bill for procedures she never received.
Prosecutors say former staff of a health insurer took confidential member data and filed 4,363 authorizations for services members never sought. Interviewed members said they never requested, signed or received them.
A patient won a data access case ordering a dental clinic to give her certified copies of her record. The clinic did not comply. The Constitutional Court found it in breach, ordered delivery, a public apology and possible fines.
A newspaper reports that an attacker allegedly took 14.8 million records and 10.6 million photos from the public health system in 2025, including clinical histories and emergency forms, later passed off as civil registry data.
A health workers' union reported a week of slowdowns and failures in the social security institute's computer system, affecting electronic records, prescriptions and lab orders and delaying patients. The institute had not responded.
A family asked the health authority for an adult relative's medical record. It refused, citing confidentiality and the data law, although the patient was not in a position to sign the authorisation it required.
A health rights coalition said the paper records of patients treated before a national hospital was rebuilt and moved to a new hospital network have disappeared, so earlier test results are unavailable and some studies may need repeating.
From a Spanish source; summary ours.
Lost between providersAlleged, not decidedCase SLV-S003
Reporting on the state's AI telemedicine app found no public agreement setting out how the cloud technology partner may use patients' data. The company said the data belong to the client and did not say whether it is paid.
As the health ministry's new information system was joined to the social security institute's electronic record, a doctors' union said the rollout came without training or coordination and the new system had shown multiple failures.
Attackers encrypted the system holding a national specialist hospital's clinical plans and images and demanded payment. The hospital's leadership said it refused to negotiate, reported the attack to prosecutors and police, and rescheduled 194 patients.
From a Spanish source; summary ours.
BreachThe organization admitted the problemCase GTM-S001
The health ministry confirmed an attack that encrypted internal files at its national laboratory. It said backups restored the files and it found no evidence that patient data was accessed, but some processes and its web platform were interrupted.
From a Spanish source; summary ours.
BreachThe organization admitted the problemCase GTM-S002
A video of an adult patient filmed inside the hospital without permission circulated online. The hospital said a technician was the suspect, called it a violation of patient privacy, apologised, and referred the matter to police.
BreachThe organization admitted the problemCase GUY-S001
The paper reports that a woman says a health worker disclosed confidential health information about her, and it spread among people around her. A doctor quoted in the piece says confidentiality breaches happen.
The outlet reports that armed groups vandalised and burned nearly fifty years of archives at a public specialist hospital. A doctor there says he has had to restart some patients' follow-up from zero.
Insured patients were told there was no system for several days, so appointments, medicine and laboratory results stopped. The hospital director said the system had failed, as many times before, because of an internet provider problem.
From a Spanish source; summary ours.
Delay or costThe organization admitted the problemCase HND-S002
A patient arrived for a booked consultation and was sent away because staff could not open her medical history. The institute's board said 14 of 24 storage disks failed, forcing staff to record visits by hand for weeks.
From a Spanish source; summary ours.
Access refusedThe organization admitted the problemCase HND-S001
The National Health Fund confirmed a cyber incident after a hacker group said it held clients' medication data. The fund reported it to the Information Commissioner and police investigators and said affected stakeholders were contacted.
BreachThe organization admitted the problemCase JAM-S001
A federal appeals court ruled that when a person says a health institution is denying access to their clinical record, judges may grant immediate protection, treating record access as part of the right to health.
From a Spanish source; summary ours.
Access refusedA regulator decidedCase MEX-S003
· Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI/013/2025)
A person asked a public health insurer for copies of their imaging studies and the reports on them. The insurer missed the legal deadline and only found the files after a complaint. The regulator ordered delivery free of charge.
From a Spanish source; summary ours.
Delay or costA regulator decidedCase MEX-S001
· Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI/142/2024) · archived copy
A person paid a public insurer for certified copies of their deceased father's record but was handed a relative's record instead. After a complaint, the insurer found the father's file. The regulator ordered free certified copies.
A report says a cyberattack exposed patients' names, addresses, phones, emails and diagnoses, later offered for sale. The hospital filed a criminal complaint; earlier it said only part of a website was hit and patient records were safe.
A seller claimed to offer 400,000 lines of data from a private hospital group: patients' names, national ID and tax numbers, phones, emails, insurance policies, diagnoses and medical notes. The report carried no response from the hospital.
Officials discussed a person's health history and private life at a press conference. Specialists interviewed said this breached confidentiality standards for health information.
A woman says two appointments were cancelled for lack of doctors, then staff said they could not locate her file. She repeated her tests and waited more than a year for follow-up.
The outlet reports that a public hospital published photos of patients undergoing scans, some partly undressed and recognisable, in political messaging. Lawyers and health workers say this breaks the health law's confidentiality rules; no explanation was given.
After authorities shut a private clinic network serving social security members, an inside source says surgeries were cancelled and patients were left with doctors who did not know their medical histories. Members were redirected elsewhere.
From a Spanish source; summary ours.
Lost between providersAlleged, not decidedCase NIC-S004
Reporters said they could search and download insured people's medical histories, signatures and phone numbers from a site run by hackers who offered the data for sale. Security experts said they had warned the institution for weeks.
An audit by the Superintendencia de Salud found that the original entry in a patient's digital clinical record at the social security hospital was deleted and replaced six minutes later with a different account. The regulator identified the user responsible.
The national incident response team CERT-PY said a cyber incident hit the Ministry of Health and was contained. A security expert warned that data taken in such attacks usually ends up exposed on dark web forums.
From a Spanish source; summary ours.
BreachThe organization admitted the problemCase PRY-S002
A reported ransomware attack on a private hospital group encrypted electronic clinical records and booking systems, forcing staff back to paper and delaying admissions, tests and appointments while attackers reportedly demanded payment.
A clinic emailed a patient's complete record, covering about fifteen years, to prosecutors without her consent, her representative's approval or a court order. The national health regulator found this broke health law and fined the clinic.
A photo of a computer screen showing a hospitalised patient's record spread online. The national health regulator ruled the disclosure a grave breach of confidentiality and fined the clinic more than 668,000 soles; the clinic said it would appeal.
Details from a patient's record were broadcast on a television programme. The public health insurer issued a statement rejecting the leak and opened an internal audit to identify the people who breached its system and supplied the information.
From a Spanish source; summary ours.
BreachThe organization admitted the problemCase PER-S003
Reporters found private clinics and health insurers collecting sensitive health and personal data without consent and using it beyond care. Misuse led to one patient's suspension from work and to marketing harassment; regulators fined the sector over four million soles.
A man suing a public health authority over his hospital care was allowed to go ahead despite filing late. The authority told the High Court it could not locate some of his medical records.
OtherThe organization admitted the problemCase TTO-S001
Lawyers for a person in state detention told the High Court that prison officials decided not to disclose the medical records compiled during the detention, as part of a wider legal challenge.
A patient made six requests for his health information and waited more than a year to receive it. The regulator proposed a penalty; the provider settled before a hearing and paid $112,500.
Delay or costA regulator decidedCase USA-S002
· U.S. Department of Health and Human Services, Office for Civil Rights
A complaint said a group of care facilities put a patient's name, photo and care details on its website as a success story. The regulator found the same had happened to 150 patients without valid written authorization.
Sold or sharedA regulator decidedCase USA-S003
· California Department of Justice, Office of the Attorney General
The state found a health information website sent identifiers and the titles of articles readers viewed to advertisers, ignored opt-out requests, and ran a consent banner that did not stop tracking. It paid $1.55 million.
The regulator's administrator began a second round of payments, over $2.6 million, to customers of an online counseling service. Under a 2023 order, the company paid $7.8 million for sharing email addresses and health questionnaire answers with advertisers.
Sold or sharedA regulator decidedCase USA-S008
· U.S. Department of Health and Human Services, Office for Civil Rights
A patient's representative asked an academic health center for her records. Part came quickly; the rest arrived more than two years later, after two complaints to the regulator. The center did not contest a $200,000 penalty.
Delay or costA regulator decidedCase USA-S007
· U.S. Department of Health and Human Services, Office for Civil Rights
A patient asked a health system for his medical records by mail, telephone and its patient portal. He received them about nine months later, only after the regulator opened an investigation. The system paid $60,000.
Delay or costA regulator decidedCase USA-S004
· U.S. Department of Health and Human Services, Office for Civil Rights
A patient made a written request for her records, went to collect them, then phoned many times. A county clinic sent them seven months later, after the regulator opened an investigation. The regulator imposed a $100,000 penalty.
A company storing electronic medical records for healthcare providers told federal regulators hackers stole personal information and medical records of more than 3.75 million people, including Social Security numbers, health information, ID numbers and banking details.
BreachThe organization admitted the problemCase USA-S012
Hackers copied insurance policy numbers, claims and benefits data, medical record numbers and Social Security numbers from a health billing software vendor. The vendor reported 3.8 million people affected to federal regulators about nine months after discovering the intrusion.
BreachThe organization admitted the problemCase USA-S014
A ransomware attack on a claims-processing company exposed names, ID numbers, insurance details and medical information such as test results and medications. Its parent company raised the count to about 190 million people. Attackers used a stolen credential.
BreachThe organization admitted the problemCase USA-S005
A federal regulator, joined by two states, alleges a telehealth company passed customers' health information to advertising platforms through customer lists and website tracking, despite privacy promises. The case is pending in federal court.
An anonymous staff member at a private health provider told a newspaper that records are often filled in after care and adjusted, so complications are minimised or left out of the patient's record.
Relatives searching for people after the earthquakes say hospital patient lists held entries that were not names at all, only question marks or single letters, and that some people lost all trace during transfers between hospitals.
Families say people rescued alive and taken by ambulance were never recorded at any hospital; one was possibly admitted under another name. They say no public, unified register of those rescued in the first hours existed.
From a Spanish source; summary ours.
Lost between providersAlleged, not decidedCase VEN-S002
The government announced a website listing patients treated in eleven hospitals after the earthquakes. The outlet found its links and phone numbers led nowhere, and the list could only be searched by exact name or ID number.
A report says a doctor at a clinic filmed a patient during care and posted it as an advertisement. A physician called publishing such footage without consent a breach of medical secrecy.
An outlet reports that a doctor posted video taken during care that showed a patient's body uncovered. The posting drew public criticism over patient confidentiality.
An outlet reports that a private clinic's laboratory gave a patient an incorrect negative test result. The Ministry of Health responded that screening results outside the specialist centre must be confirmed there.
A patient's X-ray report described the image as normal although a specialist saw clear signs of injury on the film. The diagnostic centre admitted the error, saying it happened while reports were obtained remotely by email.
From a Bangla source; summary ours.
Record wrongThe organization admitted the problemCase BGD-S002
A patient's scan report from a diagnostic centre contained entries that contradicted each other, and a doctor reading it gave alarming advice. A repeat test elsewhere found nothing wrong. The centre apologised in writing.
From a Bangla source; summary ours.
Record wrongThe organization admitted the problemCase BGD-S001
A patient's family filed a complaint that a clinic's scan report said normal, while three later scans at other centres found a serious problem. The clinic stood by its report; the local health officer promised an investigation.
The national health directorate told government hospitals that pharmaceutical sales representatives may no longer photograph prescriptions, patient information or hospital documents, and warned of legal action against anyone who breaks the rule.
A network failure made the Bru-HIMS record system unavailable at a government screening centre. Worker screening, vaccination and occupational health services were affected and people with appointments were told to reschedule. The ministry apologised.
Delay or costThe organization admitted the problemCase BRN-S002
An internet fault left a government health centre unable to reach the national Bru-HIMS record system. Test result reviews, sample collection and medicine pickups stopped there, and patients were sent to other centres. The ministry apologised.
Delay or costThe organization admitted the problemCase BRN-S001
A national cybersecurity notice listed 71 apps breaking personal data rules, including several medical and health apps. Violations included giving personal data to third parties without separate consent, no way to withdraw consent, and missing encryption.
From a Chinese source; summary ours.
Sold or sharedA regulator decidedCase CHN-S005
· Supreme People's Court of China (typical cases) · archived copy
A software firm that ran a hospital's online appointment system copied registration details of about 2.88 million patients into its own database over several years. A court convicted the firm and its managers, with fines and prison terms.
Shanghai's cyberspace regulator penalised several online medical service firms. One had unpatched flaws and suspicious foreign access that led to data theft; another stored over 6.5 million patient records, including conditions and prescriptions, without encryption.
From a Chinese source; summary ours.
BreachA regulator decidedCase CHN-S004
· China Women's News (via Tencent News) · archived copy
Several large hospitals' online services released test reports and records to anyone with a patient's name and ID number. Someone a woman knew used this for two years to obtain and circulate her records. Some hospitals then added identity checks.
From a Chinese source; summary ours.
BreachThe organization admitted the problemCase CHN-S006
Reporters found some hospital staff and outside contractors selling patients' names, addresses and phone numbers to private companies, about 50 yuan per record. A patient described being contacted by a company that already knew her private details.
Two linked hospitals did not give a patient's family the complete medical records despite repeated requests. A district consumer commission ordered the full records, including consent forms and procedure details, within 45 days, with interest if late.
A private hospital did not give a retired patient the discharge summary, case papers and receipts, so the insurance claim could not be filed. A district consumer commission ordered compensation and the papers supplied within one month.
Records of more than 30 million customers, including ID images and claim documents, were offered through chatbots and later a website. The insurer acknowledged unauthorized and illegal access to certain data and obtained a court injunction.
BreachThe organization admitted the problemCase IND-S001
A hospital group's chief executive told police that patients' personal details and medical records, with staff data and internal documents, were posted on an outside website. The state cyber bureau registered a case and is investigating.
Security researchers reported finding a file on a subsidiary website holding patient records, vaccination reports and identity documents. They told national cyber agencies; more than 60 days later the report saw no meaningful response and the chain had not replied.
A patient in East Kalimantan alleges that the records a public hospital sent with his referral abroad were incomplete, including a video of his care cut at crucial moments, and that the referral letter misstated his state of health.
From an Indonesian source; summary ours.
Lost between providersAlleged, not decidedCase IDN-S002
A woman asked a regional public hospital in Banten for copies of her medical records through her lawyer. The lawyer says only incomplete copies came, a legal notice went unanswered, and a Health Ministry complaint would follow.
Hard drives two public hospitals sent for destruction were listed on internet auctions, holding names, addresses, clinical notes and nursing records for up to 510,000 people. The disposal firm said destroyed and intact drives were kept in identical containers.
From a Japanese source; summary ours.
BreachThe organization admitted the problemCase JPN-S004
A public hospital's administrative support worker opened another person's electronic record several times with no work reason and told others what it showed. The prefectural hospital bureau suspended her for three months.
From a Japanese source; summary ours.
BreachThe organization admitted the problemCase JPN-S003
A university hospital announced that a ransomware attack, entering through a VPN device used for medical equipment maintenance, led to the theft of names, addresses, birth dates and patient IDs of about 10,000 patients.
From a Japanese source; summary ours.
BreachThe organization admitted the problemCase JPN-S002
A clinic announced that ransomware hit its servers, possibly exposing about 300,000 patient and staff records, including contact details, medical history and checkup results. It paused new outpatient bookings and said it had consulted police.
From a Japanese source; summary ours.
BreachThe organization admitted the problemCase JPN-S001
An adult patient says an automatic clinic notice about her care went to a family member. The health ministry said the clinic had likely never updated a relative's number added years earlier, and it is reviewing the SMS system.
Users of the national health app reported seeing other people's test results in their accounts. One woman said a clinic told her she was recorded as dead and had been removed from its patient list.
Personal data of about 16.3 million people appeared online. The prime minister said preliminary findings pointed to medical organisations that had access to state databases but failed to protect them. A criminal case was opened.
The state data protection agency inspected 17 private labs and diagnostic centres. It found no access limits, unclear retention, unrecorded patient consent to sharing, and weak IT security, and ordered fixes.
Readers said clinics urged them to collect paper outpatient records quickly or they might not be found in the archive. The health ministry confirmed it, saying uncollected cards stay archived and can be signed out.
From a Russian source; summary ours.
OtherThe organization admitted the problemCase KGZ-S002
The Malaysian Medical Council found a doctor guilty of posting a complainant's personal information on a clinic's Facebook page without written consent, failing to protect patient confidentiality, and suspended the doctor for two years.
The Malaysian Medical Council found a doctor guilty of posting a patient's personal and medical information on a social media account without written consent, against a promise not to reveal it, and issued a reprimand.
The Malaysian Medical Council found that a doctor supplied a requested medical report roughly ten months after the request, failing to provide it within a reasonable time, and reprimanded the doctor along with a separate charge.
The Malaysian Medical Council found a doctor guilty of disclosing a complainant's medical report, without consent, in an affidavit filed in court proceedings against the complainant, and issued a reprimand.
A public hospital released a statement giving health details of a named patient. Lawyers said this broke the patient confidentiality article of the Health Services Act, which allows disclosure only with written consent, a court order or a legal duty.
A patient's clinical images were reportedly leaked by a hospital nurse and shared online with identity details. The Health Ministry said it was investigating; whether anyone faced action was not disclosed.
After hackers took and posted names, ID and phone numbers of about 200,000 patients, a patient complained. The commission found weak cyber security, no rules for handling personal data and no breach plan, and ordered an audit and fixes.
From a Mongolian source; summary ours.
BreachA regulator decidedCase MNG-S001
· National Human Rights Commission of Mongolia, 24th report on human rights · archived copy
A relative complained that a hospital head described a patient's health in a live interview with a news site. The commission found this broke the personal data law; the hospital head was warned and the press council asked to review.
Hackers demanded $50,000 for data said to include patients' names, ID numbers, phone numbers and medical histories. The hospital publicly apologised for the risk of leaked data. One patient said they reported it to police; the promised call never came.
From a Mongolian source; summary ours.
BreachThe organization admitted the problemCase MNG-S003
People close to a military-guarded public hospital in Sagaing Region say staff notify the army when emergency patients arrive, and treatment waits until soldiers and police have checked them, so patient details reach security forces first.
A newspaper reports that a hospital submitted a claim with false bills for care it never gave an insured patient, and repeat claims for one patient, before the Health Insurance Board spotted and rejected them.
Prosecutors charged 32 people, including hospital operators and doctors, accused of fabricating records and issuing separate bills for patients on one flight to support inflated insurance claims for foreign trekkers.
A guest editorial reports that Nepal's national health insurance information system failed, making months of claims inaccessible overnight; hospitals struggled to recover the data, while some with their own electronic records resubmitted claims.
Residents told a news outlet that hospitals now post charges at reception, including a fee for a diagnosis certificate, so patients must pay to get a written record of their own diagnosis.
Staff recorded patients during procedures and the video spread online. The provincial health department, which runs the hospital, suspended senior staff and said the recording breached medical ethics and undermined patient privacy.
BreachThe organization admitted the problemCase PAK-S001
Police finished an inquiry into medical reports allegedly faked to justify a procedure on a woman at a private hospital in Sindh. The provincial healthcare commission will have experts review all records and hear both sides.
Attendants told the newspaper that public, private and charitable hospitals often refuse a short clinical summary while treatment continues, saying it comes only after formal discharge, leaving families unable to arrange transfers or second opinions.
Lost between providersAlleged, not decidedCase PAK-S002
A ransomware group said it took about 2.44 terabytes of hospital data, including patient records and scans, and demanded payment. The hospital in Mindanao said its first checks found no sign of a breach and it was still investigating.
The national health insurer said it was investigating about 1,000 suspected ghost patient claims in the Cordillera region, where members were recorded as treated when they were not. Members spotted them after receiving text alerts.
A patient complained that a hospital researcher, given the patient's name by their doctor, approached them in a waiting area to join a study. The regulator found implied consent sufficed but said express consent would have been better practice.
A hospital staff member opened a former patient's record on the hospital system for personal reasons and filmed the screen showing their ID number, address and contacts. The patient complained; she pleaded guilty and was fined.
A public specialist centre emailed an invitation to a patient event using CC instead of BCC, so all 467 recipients could see each other's addresses. The centre apologised and reported the incident to the health ministry and the privacy regulator.
BreachThe organization admitted the problemCase SGP-S004
A former public specialist centre employee was charged with accessing personal data of 18 patients without authorisation and downloading photos of 42 patients from its systems. The centre said it began an internal probe and filed a police report.
A doctor deliberately took 3,976 patients' personal data while preparing to open a practice. The privacy regulator fined the hospital for late notification and weak supervision of staff, but found no breach of security duties.
A court fined a dentist one million won for writing a smaller medication amount in a patient's record than was actually given, and for recording health checks that were never carried out.
After a patient died in hospital, the commission found staff had, as a routine practice, recorded a doctor as giving orders that the doctor never gave. It referred hospital staff to prosecutors and recommended changes to the law.
Three senior doctors at a Seoul hospital gave drug company staff patients' prescription records, more than 17,000 entries, at the company's request. A court fined the doctors and the hospital's operator for failing to prevent it.
Disciplinary files that the public health insurer and claims review agency gave a lawmaker show staff viewing relatives' and an ex-partner's data, querying colleagues, and emailing sensitive screening files home. Penalties ranged from reprimand to dismissal.
A seller on a breach forum offered about 398,000 records said to include patients' national ID numbers, phone numbers, addresses and medical appointment details. The report said no official statement had been issued.
A public search page on an appointment booking platform reportedly showed patients' names, national ID numbers, phone numbers and appointment history. It came down only after a public post, and users were not told.
After a ransomware attack, the hospital issued statements apologising and saying hackers may have stolen data while encrypting its systems. Millions of patient records were reportedly offered for sale; the ministry said the source still needed checking.
From a Chinese source; summary ours.
BreachThe organization admitted the problemCase TWN-S001
Prosecutors charged a hospital doctor with opening the records and contact details of three patients under other doctors' care, then texting them to criticise their doctors and urge them to switch to him. He has not been convicted.
Prosecutors charged two men with paying cryptocurrency for a file of about 20,000 hospital patients' visit and health records stolen by hackers, then advertising hospital data for sale on a messaging app. Prosecutors asked for heavy sentences.
A large private hospital hired a small contractor to destroy patient records but did not oversee the work. Over 1,000 record pages leaked and were reused as snack bags. The regulator fined the hospital and the contractor.
Over 9,000 people flagged more than 24,000 entries in their national health app history as wrong. The ministry told a parliamentary committee about a quarter of checked entries were staff data-entry errors and others reflected performance targets, not care given.
From a Thai source; summary ours.
Record wrongThe organization admitted the problemCase THA-S002
The city's medical service department announced that a cloud infrastructure failure stopped the patient database, appointment and dispensing systems at 14 of its hospitals. Hospitals stayed open and switched to paper records, but services were delayed.
From a Thai source; summary ours.
OtherThe organization admitted the problemCase THA-S005
Affected people said their national health app history listed treatments they never had, one with 16 false entries. One said an insurance claim could not proceed. They want false entries deleted in writing and those responsible identified.
After a private hospital stopped public scheme outpatients, transferred patients waited up to seven days for their medical history. The national insurer said it could not reach their data because the hospital was not linked to the national records exchange.
Lost between providersAlleged, not decidedCase THA-S004
Since 2024 a municipal health service has screened every patient's blood sample for an extra test without telling them. Its director confirmed patients are not informed. Lawyers called the practice illegal and a breach of privacy and consent.
From a Portuguese source; summary ours.
OtherThe organization admitted the problemCase TLS-S001
Patients seeking approval for treatment abroad say officials asked for 5,000 dollars before signing the final medical conclusion they need, and that people who do not pay can wait years for the document.
From a Russian source; summary ours.
Delay or costAlleged, not decidedCase TKM-S001
· Chronicles of Turkmenistan (Хроника Туркменистана)
Teachers describe paying a bribe to have their required medical record books filled in, and one says a clinic doctor took samples but issued a certificate of normal results two hours later without checking them.
A provincial health department official reported common record faults found across facilities: diagnoses not updated, test results not assessed, sections that contradict each other and orders with no clear link to the patient's condition. No facility was named.
A police cybersecurity official said attackers hit hospital or health ministry data twice in one month, threatening to expose details of thousands of doctors and patients, including diagnostic imaging, and warned that health sector security is weak.
The report lists several attacks on major hospitals, including encrypted servers, ransom demands and patient and staff records advertised for sale on cybercrime forums. It reports no statement from the hospitals and no penalty.
Patients described being phoned with sales offers soon after hospital discharge. A security expert found patient names, phone numbers and medical history sold cheaply on a messaging app. Some hospitals stayed silent about attacks, the report says.
Two adult patients said clinics posted images or livestreamed their consultations for promotion without clear consent; one learned colleagues had seen the video. A city health department head condemned the practice, citing confidentiality rules.
From a Vietnamese source; summary ours.
Sold or sharedAlleged, not decidedCase VNM-S004
Europe: 187 cases from 47 countries and territories
A patient asked a private clinic for all the records it held on them and got no reply. After a complaint, inspectors visited, the clinic produced the file and undertook to supply it, and the regulator ordered fixes.
From an Albanian source; summary ours.
Access refusedA regulator decidedCase ALB-S001
· Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale (IDP)
Months after a regulator recommendation, a medical laboratory still had no data protection terms with firms handling patient data for it and an incomplete security system. The regulator fined it ALL 2.8 million.
Ransomware encrypted all of a regional public hospital's data, stopping imaging and blood testing until services returned within 72 hours. The report says some patient data was deleted. The hospital confirmed the attack.
From an Albanian source; summary ours.
BreachThe organization admitted the problemCase ALB-S003
Acting on one person's complaint, the data protection authority found that a closing clinic handed clinical files to another clinic without consent or notice, and that both lacked safeguards. It warned both and ordered proof of compliance.
Several doctors told the newspaper that after a software update to the national shared record, some patients' files could not be found and some entries did not match earlier data, lengthening waits. The operator said the system worked normally.
Former doctors told investigative reporters that hospital management entered names of people who were not ill as state-funded patients, inflating patient numbers. The health ministry referred the claims to anti-corruption investigators; management called them absurd.
A patient asked a therapy centre for all data held about them. The centre left out notes a staff member kept by hand. The regulator found this breached the right of access and ordered full disclosure within four weeks.
From a German source; summary ours.
Access refusedA regulator decidedCase AUT-S003
· Federal Administrative Court (Bundesverwaltungsgericht), W108 2276075-1, upholding a Datenschutzbehörde decision · archived copy
A patient learned during a court case that a hospital report about them had reached third parties. The regulator found the hospital's security manager had copied the electronic record and emailed it to police. The court upheld that finding.
From a German source; summary ours.
Sold or sharedA court decidedCase AUT-S001
· Datenschutzbehörde (Austrian Data Protection Authority), penal decision 2025-0.625.944
A woman found through the ELGA access log that a doctor had opened her stored results and medication data without consent and unconnected to any treatment by that doctor. The regulator found a violation and imposed a 1,000 euro fine.
A clinic emailed a patient a lab report with a serious finding that was false. The city health committee confirmed a template error and reprimanded the doctor; the clinic apologised and a court awarded damages.
From a Russian source; summary ours.
Record wrongA regulator decidedCase BLR-S001
· Current Time (Nastoyashchee Vremya) · archived copy
A patient released from detention came home with no discharge summary or extract from his records. His family said this made it hard to arrange prompt follow-up care.
From a Russian source; summary ours.
Lost between providersAlleged, not decidedCase BLR-S003
A patient in a damages case says a private clinic refused her copies of her medical and anaesthesia records. A video of the procedure turned out to be deleted, and its documents gave conflicting figures.
A patient asked her hospital group who had opened her electronic record. The list showed a therapist working there had viewed her test results three times. The regulator reprimanded the hospital for weak access controls; an appeal is pending.
An attacker locked a hospital's servers and exported about 5 gigabytes of data. The regulator found security failings, including weak protection of access to the electronic patient record, and fined the hospital 390,000 euros. An appeal court later reduced it.
A company that runs employer-requested sick-leave checks said hackers had taken 53,900 files, including names, addresses, incapacity levels and examining doctors' comments, and published them a week later. It warned of phishing using the data.
From a French source; summary ours.
BreachThe organization admitted the problemCase BEL-S004
A private clinic shut without telling patients. Health inspectors reported faults in how it kept patient files, and a patient trying to move to another clinic was refused because no one was left to sign the paperwork.
From a Bosnian source; summary ours.
Lost between providersA regulator decidedCase BIH-S003
· Institucija ombudsmena za ljudska prava Bosne i Hercegovine · archived copy
A patient asked a public health centre to amend her health record and heard nothing for two years. The ombudsman found no formal decision had been made and told the centre to decide at once.
From a Bosnian source; summary ours.
Record wrongA regulator decidedCase BIH-S001
· Institucija ombudsmena za ljudska prava Bosne i Hercegovine · archived copy
A patient asked a public health centre to transfer his file to another clinic. Two months later he was told he had no file there. The ombudsman told the centre to open one and explain his options.
From a Bosnian source; summary ours.
Lost between providersA regulator decidedCase BIH-S002
A patient said on television that her discharge record was wrong. A hospital director responded on air with her health details. The data protection commission fined the hospital 10,000 leva, rejecting its consent argument.
Insured people using the eZdrave app found medical activities in their electronic records that had never been carried out. After checks, the national health fund imposed fines, partly ended contracts and recovered money paid.
Complaints that electronic records list care patients never received rose 68.75 percent in July and August 2026 over a year earlier. The health fund links the rise to wider use of the eZdrave app.
A new eZdrave feature asks patients whether they attended each recorded visit. Within weeks they had sent 1,760 reports of exams, test results and hospital stays they did not recognise, and 560 checks had begun.
Several patients complained that a private hospital never sent copies of their records. The regulator found imaging files had been irretrievably lost, no backups existed, the loss was never reported, and fined the hospital 190,000 euros.
From a Croatian source; summary ours.
Access refusedA regulator decidedCase HRV-S001
· Agencija za zaštitu osobnih podataka (AZOP), anonymised decision 567-UP/I-034-01/24-01/31 · archived copy
An unknown hospital employee photographed a patient's result in the hospital system and it was published by the media. The hospital neither reported the breach nor told the patient until their lawyer wrote. The regulator fined it.
From a Croatian source; summary ours.
BreachA regulator decidedCase HRV-S002
· Agencija za zaštitu osobnih podataka (AZOP), anonymised decision 567-UP/I-034-01/24-01/34 · archived copy
After a ransomware attack, the regulator found a hospital's weak technical safeguards let an attacker roam its systems unnoticed for about seven days and copy at least 3 GB out. The hospital was fined 20,000 euros.
A hacking group claimed it broke into a private medical practice and posted about 9,400 records for free download, including names, national ID numbers, addresses, medicines, doctors' notes and scanned medical documents. The practice was not named.
A patient asked the ombudsman for help after a former state hospital could not locate his medical file. After the ombudsman stepped in, the file was found and he regained access to his key health data.
The state hospital body reported losing ten patients' medical files and three emergency registration forms. The regulator found no safeguards against loss, fined it 46,500 euros in total and ordered it to tell seven patients.
A man complained that two doctors issued certificates about his past care to his former wife without his knowledge or consent. The regulator found they processed his health data with no legal basis and reprimanded both.
A doctor's secretary looked up a patient's GeSY account and phoned his father, listed as next of kin, to confirm a booking. The regulator ruled that number was not an alternative contact and reprimanded the doctor.
The hospital said attackers took personal data of patients and staff from its systems and threatened to publish it in the media and online. It reported the attack to police, the data regulator and the digital security authority.
From a Greek source; summary ours.
BreachThe organization admitted the problemCase CYP-S005
A cyberattack left a private clinic's patient records unreachable for a week. The clinic, holding data on about 250,000 patients, did not report it in time and could not prove it told patients. The court confirmed a 309,000 crown fine.
After ransomware shut down its systems, a hospital told patients that personal data linked to their medical records may have been stolen. It could not yet confirm whether or how much was taken, and notified the data protection office.
From a Czech source; summary ours.
BreachThe organization admitted the problemCase CZE-S002
A clinic computer storing images and data from nearly two thousand examinations disappeared for four days, then reappeared. The hospital's internal review called it a data incident, its director confirmed it, and it was reported to the data protection office.
From a Czech source; summary ours.
BreachThe organization admitted the problemCase CZE-S004
A security firm reported that a hacking group stole a database from an unnamed Czech health facility and offered it for sale. It reportedly held patient contacts with health records, booking details with payment and insurance data, and staff profiles.
A patient living outside Denmark asked a general practice for an electronic copy of their record. The clinic said it could only hand it over on a new USB stick the patient brought in person. The board criticised the clinic.
After inspecting eight research projects using health information, the data protection authority gave serious criticism: the university had several times passed personal data on without the required permission and supervised partners poorly. The university said it takes the criticism seriously.
Women checked the access log for their records on sundhed.dk and saw that a doctor with no part in their care had looked them up. The regions found many more unauthorised lookups and reported him to police.
From a Danish source; summary ours.
BreachThe organization admitted the problemCase DNK-S002
After a cyberattack on a nationwide chain of GP practices, hackers posted patient information including illness history, hospital referrals and medication. The chain had confirmed personal data on an unknown number of patients was compromised.
From a Danish source; summary ours.
BreachThe organization admitted the problemCase DNK-S004
Experts said two regions gave a research project access to 3.65 million people's hospital records without first assessing data protection risks. A regional director said the analysis perhaps should have been done. The regulator opened an inquiry.
A patient asked a provider to correct data it had sent to the national health system. The provider said the entries were right and would not discuss it. The audit office said this broke the provider's complaints rules.
From an Estonian source; summary ours.
Record wrongA regulator decidedCase EST-S002
· Riigikontroll (National Audit Office of Estonia), report to the Riigikogu · archived copy
Checking the national patient portal, a patient found that a family doctor whose list they were not on had recorded a diagnosis and treatment for them. The audit office warned that a misleading history can affect later care decisions.
From an Estonian source; summary ours.
Record wrongA regulator decidedCase EST-S003
· Riigikontroll (National Audit Office of Estonia), report to the Riigikogu · archived copy
For years, documents sent to the national system carried a diagnosis code one letter away from the right one, recording an unrelated finding. The audit office noted such errors can mislead treatment and harm a person's reputation and job prospects.
Someone repeatedly entered a records system used by over 300 Estonian dental and health providers and downloaded patients' ID codes, emails and health data. Police arrested a suspect; prosecutors said the data appears not to have been shared.
An attacker broke into a private health provider's system, downloaded its patient database and published the data of about 33,000 people online. The Supreme Court refused his appeal, so the appeal court's sentence of six years and 11 months stands.
From a Finnish source; summary ours.
BreachA regulator decidedCase FIN-S002
· Tietosuojavaltuutettu (Office of the Data Protection Ombudsman), decision TSV/1507/2024 · archived copy
A patient asked a health provider for log data showing who had viewed their records over two years, with times and reasons. The provider said its system could not produce usable logs. The deputy ombudsman ordered it to supply them.
A patient obtained the log of who had opened their record and reported it to police. The wellbeing region found two employees had viewed nearly 150 people's records without a care relationship, and its chief medical officer apologised.
From a Finnish source; summary ours.
BreachThe organization admitted the problemCase FIN-S003
About 50 nurses and doctors are charged with unlawfully reading one patient's record with no part in his care. He learned of it when a staff member mentioned details of his care. He said he lost faith in healthcare.
In interviews for a university study, 25 doctors said the region's patient record system makes information hard to find, slows their work and endangers patient safety, and that their correction requests often go unanswered.
France's data regulator fined a private hospital 500,000 euros after an attacker used one compromised account to reach data on 524,867 patients, some including health data. Access needed no multifactor login and suspicious activity went undetected.
Doctors' software gathered patients' health data, such as prescriptions and sick leave, with identifiers that allowed care pathways to be traced. The court agreed the data were not anonymous and rejected the company's challenge to an 800,000 euro fine.
A hospital refused to give a relative the serious adverse-event report it filed after a patient died. The courts ordered release of the parts about his health and care, and the hospital's appeal was rejected.
A national lab network reported unauthorised access, through a server run by an outside IT supplier, to patient names, emails, encrypted passwords, analysis reports and social security numbers. It was the network's second attack in about a year.
From a French source; summary ours.
BreachThe organization admitted the problemCase FRA-S006
Attackers reached files of 1,500 doctors using one practice software. Administrative data on 15 million patients leaked, and the health minister said sensitive doctor annotations on 164,000 patients were exposed. The vendor said structured medical records were intact.
From a French source; summary ours.
BreachThe organization admitted the problemCase FRA-S005
A hacker posted a database of about 758,000 people taken from hospital management software, including contact details, treating doctor, prescriptions and death declarations. The software maker said a privileged account at a client hospital was misused.
From a French source; summary ours.
BreachThe organization admitted the problemCase FRA-S004
The clinic's director published a patient's X-ray image on her personal social media page. On the patient's complaint, the data protection regulator found the clinic processed health data unlawfully, issued a warning and ordered the post removed.
From a Georgian source; summary ours.
Sold or sharedA regulator decidedCase GEO-S001
· Public Defender (Ombudsman) of Georgia, National Preventive Mechanism · archived copy
On a monitoring visit, the Public Defender's team found the clinic's patient files held almost no entries and often lacked lab results and specialist notes. It tied the gaps to overworked doctors and staff shortages.
Patients left anonymous negative reviews online. Medical practices replied in public, naming the patients and disclosing details from their records. The state regulator listed these among cases where it imposed fines in 2024.
From a German source; summary ours.
Sold or sharedA regulator decidedCase DEU-S001
· Hessian Commissioner for Data Protection and Freedom of Information (HBDI) · archived copy
The state regulator reported a practice manager who took patient records home and left them unsecured, where party guests could see them, and who also sent photos of patient files to a partner by messaging app.
After an attack disrupted all its German facilities, a hospital group said data on patients, staff and partners may have been accessed without authorisation and could be misused or passed to others.
From a German source; summary ours.
BreachThe organization admitted the problemCase DEU-S004
A former patient noticed a rehabilitation provider's app talked to its servers unencrypted, and that patient files, including medical reports, could be opened without authentication. The provider said the gap was closed and it saw no sign of data outflow.
Seeking private insurance, a man opened his electronic patient record and found three diagnoses he says do not apply to him, billed during routine visits. Insurers saw him as high risk. Only the treating doctor can correct them.
A member of the public found, through a search engine, a hospital file listing about 2,820 patients' phone numbers and planned operations, online for months. The hospital reported late, never told patients, and was fined 25,000 euros.
A patient asked a private doctor for her full file and complained the doctor had also searched her electronic health record. The regulator found the lookup unlawful, done without her knowledge, and fined the doctor 5,000 euros.
A patient complained that her doctor posted photos taken during her care on his social media page. The regulator ruled that keeping them up after she withdrew consent was unlawful and ordered his consent forms rewritten.
People who had been treated at a public hospital received election text messages from a doctor there who was a candidate. He could not show how he got their numbers; the regulator fined him 15,000 euros.
A relative asked a university hospital for copies of a patient's earlier test results. The hospital replied it had no access to its electronic system because of a cyberattack; the outlet reports other patients got the same answer.
The health service said its electronic patient record was down. While it lasted, patients could not book consultations, make appointments or have prescriptions renewed, and the service said it was working on a fix.
From a Danish source; summary ours.
Delay or costThe organization admitted the problemCase GRL-S001
Decisions in a government compensation scheme for care given without consent were postponed. The responsible minister said officials must travel around the country to find records, and that records were not always correctly kept.
From a Danish source; summary ours.
Record wrongThe organization admitted the problemCase GRL-S002
A patient checked the access log in the national health record system and found a doctor they had left kept viewing their results and prescriptions for 19 months. The doctor also ignored their access request. The regulator imposed a fine.
From a Hungarian source; summary ours.
BreachA regulator decidedCase HUN-S001
· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2025, case NAIH-2306-1/2025
A patient asked a health institution to email all their outpatient records. It demanded a per-page fee and said records could only be collected in person. It sent them free months later, after the regulator opened a case.
From a Hungarian source; summary ours.
Delay or costA regulator decidedCase HUN-S002
· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2025, case NAIH-9859/2025
A health institution uploaded another person's outpatient visit sheet into a patient's national record because they shared a name. The regulator found the record inaccurate and faulted the institution for not reporting the resulting breach.
From a Hungarian source; summary ours.
Record wrongA regulator decidedCase HUN-S003
· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2024, case NAIH-295/2024
A health institution left large volumes of patient records in a closed building that intruders kept entering, scattering files inside. It did not remove them or tell patients for over nine months. The regulator fined it two million forints.
A ransomware group said it took about 178,000 files from a private clinic, including invoices and treatment reports, and threatened to publish them. The clinic had not answered press questions when the report appeared.
A widow was refused access to her late husband's health record by a health institution, and the Directorate of Health upheld the refusal. The Parliamentary Ombudsman found no grounds to object, noting the request was not supported by documents.
From an Icelandic source; summary ours.
Access refusedA regulator decidedCase ISL-S006
· Persónuvernd (Icelandic Data Protection Authority)
A specialist doctor opened an adult's health record six times over several years without a treatment relationship or consent. The data protection authority ruled those look-ups unlawful but imposed no fine.
From an Icelandic source; summary ours.
BreachA regulator decidedCase ISL-S001
· Persónuvernd (Icelandic Data Protection Authority)
The national hospital sent an adult patient's sensitive health information to a primary care clinic she was not registered with. The data protection authority ruled the disclosure unlawful; the hospital said it regretted the mistake.
From an Icelandic source; summary ours.
Sold or sharedA regulator decidedCase ISL-S002
· Persónuvernd (Icelandic Data Protection Authority) · archived copy
A hospital employee opened an adult patient's health record twice with no work reason. The data protection authority held the employee personally responsible and ruled the look-ups unlawful.
From an Icelandic source; summary ours.
BreachA regulator decidedCase ISL-S003
· Persónuvernd (Icelandic Data Protection Authority), on Reykjavík District Court case E-2571/2024 · archived copy
A district court confirmed the data protection authority's finding that the national patient portal had a serious security weakness letting users open others' health files and messages. It cut the fine on the Directorate of Health to ISK 8 million.
A patient told the parliamentary ombudsman that two doctors entered false information in their health record and that access requests were mishandled. A complaint to the Directorate of Health had been pending for more than three years.
Intruders reached paper patient records in disused health service storage and filmed them. The data protection regulator found records insecure and damaged, breaches reported late, and affected people not told, and imposed a fine.
BreachA regulator decidedCase IRL-S006
· Data Protection Commission (Annual Report 2025 case studies)
A patient asked a former GP surgery to correct entries they believed were wrong and heard nothing. After the regulator stepped in, the surgery apologised, kept the entries as clinical opinion, and offered to add the patient's disagreement.
Delay or costA regulator decidedCase IRL-S002
· Data Protection Commission (Annual Report 2025 case studies)
A small GP surgery recorded a mistyped email address without checking it, then sent the patient's personal data, unencrypted, from a free email account to a stranger. After the regulator engaged, it moved to secure email and a patient portal.
BreachA regulator decidedCase IRL-S003
· Data Protection Commission (Annual Report 2024 case studies) · archived copy
A patient asked a public hospital for all the personal data it held. More than a month later there was still no answer, though the matter was urgent. The records were provided only after the regulator contacted the hospital group.
Delay or costA regulator decidedCase IRL-S004
· Data Protection Commission (Annual Report 2024 case studies) · archived copy
A worker was sent by their employer to a medical facility. The facility gave the employer, including the HR department, full consultation notes with past medical history, assuming consent. The regulator found the disclosure unlawful.
Italy's data protection authority found a health data company treated records of about one million GP patients as anonymous when they were personal, processing them without legal basis or patient notice; identifiers of 3,370 patients also slipped through.
Sold or sharedA regulator decidedCase ITA-S006
· Garante per la protezione dei dati personali · archived copy
A patient learned his report had gone to an address one letter different from his, carrying his name, birth date and tax code. The regulator found no address check was in place and issued a formal warning.
From an Italian source; summary ours.
BreachA regulator decidedCase ITA-S002
· Garante per la protezione dei dati personali · archived copy
A clinic could not produce a patient's medical file when investigators asked for it; the archive company said it never received the file. The regulator found the clinic failed to report the loss in time and issued a warning.
From an Italian source; summary ours.
OtherA regulator decidedCase ITA-S003
· Garante per la protezione dei dati personali · archived copy
A patient said a hospital put a report in her electronic health record without telling her. When she asked for it to be hidden, the system created a replacement dated the day of the change. The regulator issued a warning.
Data stolen in March from the company running a portal family doctors use to send prescriptions went on sale online: prescriptions, sick notes, exemption certificates, emails, phones and addresses. The company reported it to police and warned patients of phishing.
From an Italian source; summary ours.
BreachThe organization admitted the problemCase ITA-S005
A health worker who supervised a colleague opened the colleague's national health record to check whether sick leave was open. The person had restricted access to their health data. The regulator still found the lookup unlawful and issued a reprimand.
From a Latvian source; summary ours.
BreachA regulator decidedCase LVA-S001
· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy
A health worker used work access to read an adult family member's national health record for personal reasons. The person said the information reached a third party. The regulator found no lawful basis and fined the worker 250 euros.
From a Latvian source; summary ours.
BreachA regulator decidedCase LVA-S002
· Datu valsts inspekcija (Data State Inspectorate of Latvia)
Attackers reached a municipal system the hospital used, taking names, personal codes and addresses of its staff and clients. The regulator found the hospital had not supervised the supplier or reported on time, and reprimanded it. The hospital appealed.
From a Latvian source; summary ours.
BreachA regulator decidedCase LVA-S003
· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy
A person complained that staff at a family practice they did not use had opened their record and prescriptions. The practice blamed a mistyped personal code. The regulator found the lookup unrelated to care and issued a reprimand.
From a Latvian source; summary ours.
BreachA regulator decidedCase LVA-S004
· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy
Over several years a physician assistant used work logins to the national health system and two hospital systems to view three people's health data for personal reasons. The regulator found no care purpose and fined him 500 euros.
A patient saw in the national e-health log that a sanatorium's staff had opened a referral written for a different specialist. The regulator found no lawful basis for viewing it and reprimanded the sanatorium.
From a Lithuanian source; summary ours.
BreachA regulator decidedCase LTU-S001
· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)
A leaked staff login let an outsider open 63 patients' files, and a later ransomware attack hit systems holding records of about 383,000 patients. The regulator found security was inadequate and fined the company 450,000 euros.
From a Lithuanian source; summary ours.
BreachA regulator decidedCase LTU-S002
· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)
While on sick leave and about to leave a public primary care centre, a doctor viewed 1,231 patients' files in its records system and used their contacts to email and text them. The regulator fined the doctor 1,153 euros.
From a Lithuanian source; summary ours.
Sold or sharedA regulator decidedCase LTU-S003
· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)
While handling a records transfer, a nurse at a health centre registered a visit the patient never made, then deleted it. The regulator accepted the centre's fixes and rejected the complaint as posing no real risk.
Women received text invitations from a clinic they had never used. The clinic blamed a backend fault in an information system shared with other providers, could not say how many people were reached, and said no data left the system.
From a Lithuanian source; summary ours.
Record wrongThe organization admitted the problemCase LTU-S005
An IT company serving medical practices said a cyberattack affected 40 practices. It filed a police complaint, notified the data protection authority and said experts found no data leak. Services were later restored.
From a French source; summary ours.
BreachThe organization admitted the problemCase LUX-S001
A staff member with no role in the patient's care opened their record for personal reasons. The regulator found the access unauthorised. The provider had dismissed the employee and told the patient, so no further action followed.
BreachA regulator decidedCase MLT-S001
· Information and Data Protection Commissioner (Malta) · archived copy
A private provider filled in a patient's file with an address taken from the electoral register, years out of date. Despite repeated requests it did not correct it, and medical reports reached the current occupants. Fines totalled €20,000.
A patient complained to the data protection regulator that a doctor kept accessing her medical records after she left his care. He sued her for libel. A court dismissed the suit, ruling her complaints were privileged.
A patient found that other people's test results on a large private laboratory's website could be opened by changing digits in a link. The data protection regulator found the laboratory failed to secure them and opened an administrative case.
The national health insurer said attackers hit one of its information systems and technical checks pointed to a possible data exfiltration. Its director later said no leak had yet appeared online and the investigation was continuing.
From a Romanian source; summary ours.
BreachThe organization admitted the problemCase MDA-S002
A mass email inviting donors to a blood drive showed every recipient's address. Hundreds of donors were affected. The hospital apologised the next day and said no health or donation history was shared.
From a French source; summary ours.
BreachThe organization admitted the problemCase MCO-S001
After an anonymous complaint, the data protection agency inspected a hospital and found cameras covering areas where patients wait. It ordered one camera redirected or masked and the unlawful recordings deleted; the hospital reported compliance.
A specialist's report on a patient was printed from the hospital system using an absent doctor's login and read aloud in a public trial. The ombudsman found the hospital responsible for failing to protect the data.
Patients reported that the national health information system and the eHealth portal were unavailable for several days, so results could not be checked online and prescriptions were issued on paper. The ministry confirmed temporary technical problems.
From a Serbian source; summary ours.
Delay or costThe organization admitted the problemCase MNE-S003
Asked by a newspaper, the hospital said no employee had been held responsible for recent leaks of patients' health information. It said all staff must now sign confidentiality contracts to stop disclosures to third parties.
From a Serbian source; summary ours.
BreachThe organization admitted the problemCase MNE-S005
A patient complained that an outsider obtained exact details of her care from a public health centre. The data protection agency could not confirm a leak because staff denied it; she received no sign of an internal inquiry.
A hospital's log checks showed a nurse had opened the electronic files of several patients he was not treating, more than once and over a long period. He admitted it, citing curiosity and boredom. The tribunal reprimanded him.
From a Dutch source; summary ours.
BreachA court decidedCase NLD-S001
· Centraal Tuchtcollege voor de Gezondheidszorg · archived copy
A patient complained that her surgeon refused to provide her medical file, among other complaints. On appeal, the national disciplinary tribunal found the complaint about the file partly justified, and the reprimand stayed in place.
From a Dutch source; summary ours.
Access refusedA court decidedCase NLD-S002
· Regionaal Tuchtcollege voor de Gezondheidszorg 's-Hertogenbosch · archived copy
During a civil case he brought against a patient, a doctor passed her medical data to an outside expert without asking her. The tribunal found confidentiality was breached and reprimanded him.
A maker of electronic patient record software confirmed that ransomware attackers stole patients' personal data, including medical records, from several Dutch healthcare institutions. It first said theft was unlikely. Sixty-six institutions reported a breach to the data protection authority.
BreachThe organization admitted the problemCase NLD-S006
A lab running part of a national screening programme confirmed it was hacked. Test results, names, addresses, provider names and GP referrals of about 485,000 women, going back years, were stolen. The screening organisation said several years were involved.
From a Dutch source; summary ours.
BreachThe organization admitted the problemCase NLD-S004
A patient survey found more than one in ten people treated in hospital in 2024 experienced something going, or nearly going, wrong because a provider lacked their medical information. Reported harms included repeat scans and medication errors.
From a Dutch source; summary ours.
Lost between providersThe person's own accountCase NLD-S005
A referral was issued in a patient's name on a day she received no care, carrying someone else's health data. Further referrals and reports followed. The regulator fined the hospital, its director and the doctor; a court upheld it.
From a Macedonian source; summary ours.
Record wrongA regulator decidedCase MKD-S001
· Агенција за заштита на личните податоци (AZLP), Annual Report 2025 · archived copy
A ransomware attack encrypted personal data held by a public health institution. On inspection the data protection regulator found the institution lacked proper technical and organisational safeguards and was poorly prepared to handle security incidents.
A patient seeking urgent treatment saw a clinician who looked in the national electronic record, learned of a sensitive entry and refused even a basic exam. The patient has sued for discrimination; advocates say any doctor can see everything.
A patient saw in the national health portal that a hospital worker had opened their record on several dates without reason. The county governor found clear breaches of confidentiality but closed the case without sanction.
After complaints and breach reports, the data protection authority inspected the record system used by hospitals and municipalities in central Norway. It found significant deficiencies, privacy breaches and unclear responsibilities, and gave notice of a correction order.
A random audit found an employee had looked into municipal care records without a work reason for around 15 years, affecting about 2,100 residents. The municipality reported it to police and said it saw no sign of onward sharing.
From a Norwegian source; summary ours.
BreachThe organization admitted the problemCase NOR-S004
A record-system change made in 2023 failed to flag certain messages about discharge reports from other hospitals and specialists. Hospitals identified 3,445 cases needing review. The hospital said an early check found some needed follow-up.
From a Norwegian source; summary ours.
Lost between providersThe organization admitted the problemCase NOR-S003
Doctors said moving 25 years of patient records into a new system produced missing documents, absent operation notes and wrong dates. The regional health authority confirmed only about half of 200 million documents had been moved.
From a Norwegian source; summary ours.
Record wrongThe organization admitted the problemCase NOR-S002
After a medical practice closed, the former partner holding its records stopped releasing them to patients during a dispute with the other partner. The ombudsman ordered the practice to stop, and an administrative court rejected the appeal.
From a Polish source; summary ours.
Lost between providersA regulator decidedCase POL-S001
A patient saw patient record cards in a clear box on the front seat of a doctor's parked car, with one card's name, address, birth date and ID number readable. The regulator reprimanded the doctor and ordered the patient notified.
A patient received someone else's medical records, including name, birth date, national ID number and health data. The hospital did not report the breach or tell the affected person in time. The regulator fined it 29,648 zloty.
Attackers used a flaw in practice software used by hundreds of clinics to take names, national ID numbers, contacts and discharge documents. It went unnoticed for over two weeks. The vendor said it fixed the flaw and forced password changes.
From a Polish source; summary ours.
BreachThe organization admitted the problemCase POL-S004
A user found that changing a web address in the national patient account showed other patients' documents, with names, national ID numbers, ID card numbers and health data. The ministry confirmed the flaw but would not name the facility.
From a Polish source; summary ours.
BreachThe organization admitted the problemCase POL-S005
A family member with power of attorney obtained the record's access log and found entries by staff outside the care team. The hospital admitted improper access but withheld names; the commission said the names must be given.
From a Portuguese source; summary ours.
BreachA regulator decidedCase PRT-S001
· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 406/2026
A patient's lawyer asked for certified copies of the full record with a signed special power of attorney. The hospital insisted on a copy of the patient's ID card and ignored the commission; it ruled the demand unjustified.
From a Portuguese source; summary ours.
Access refusedA regulator decidedCase PRT-S002
· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 48/2026
A patient in the Algarve asked for a clinical report needed for care abroad. The patient says the hospital then resent an earlier report with only the date changed; the commission told it to check and supply what was missing.
From a Portuguese source; summary ours.
Record wrongA regulator decidedCase PRT-S003
· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 481/2025
A patient asked a public hospital group several times for her own clinical records without success. The hospital did not answer the commission either; it ruled the records must be released, or their absence explained.
From a Portuguese source; summary ours.
Access refusedA regulator decidedCase PRT-S004
· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 437/2025
A patient in Madeira received some records but, after repeated requests, a key part of the file was still missing. The health service did not reply to the commission, which ruled it must provide the records or justify refusal.
A former employee copied every patient's contact details and medical file and used them to invite patients to a competing clinic. The clinic then failed to answer the regulator, which fined it.
From a Romanian source; summary ours.
Sold or sharedA regulator decidedCase ROU-S001
· ANSPDCP (National Supervisory Authority for Personal Data Processing)
A patient asked a clinic twice for their medical data and file documents and got no answer. The regulator found no evidence of any reply, fined the clinic and ordered full responses and staff training.
From a Romanian source; summary ours.
Access refusedA regulator decidedCase ROU-S002
· ANSPDCP (National Supervisory Authority for Personal Data Processing)
A clinic sent a patient's identity number, contact details and test results to another patient by unsecured email, and sent that patient's data back the other way. It told neither patient nor the regulator, which fined it.
Patients trying to use the new national health record portal report waiting about two weeks for identity validation. Those who get in often see only a few prescriptions, not their full medical history.
A patient complained that a private clinic kept their health insurance card. When it was returned, the discharge papers recorded treatment sessions the national insurer says were fictitious. The insurer applied a contractual penalty to the clinic.
A patient in the Bashkortostan region learned people outside her care knew details from her medical file. The regional health ministry confirmed a worker at another hospital had accessed it unlawfully and dismissed him, but refused her the inspection file.
An unplanned inspection by the Vologda regional health ministry found that the head of an ambulance service had passed data on patients it carried to third parties. He was dismissed and the material was sent to oversight bodies.
A man in the Astrakhan region found his record held a relative's history, entered when the relative was treated under his documents. Another hospital refused him care. The cassation court overturned his damages award, finding the error his own.
In a review of court practice, a clinic could not produce a patient's record for expert review because it was not transferred when two clinics merged. Courts held the successor clinic responsible for keeping it and ordered compensation.
From a Russian source; summary ours.
Lost between providersA regulator decidedCase RUS-S004
Hackers broke into a private clinic network owned by an insurer, the company confirmed, alongside attacks on two pharmacy chains. Services were disrupted; the clinic said patient data leakage had not been confirmed.
From a Russian source; summary ours.
BreachThe organization admitted the problemCase RUS-S005
The state health service said a technical fault outside its control blocked lab results from loading into the electronic health record for days. It mailed paper copies meanwhile, apologised, and offered help to anyone still missing results.
From an Italian source; summary ours.
Delay or costThe organization admitted the problemCase SMR-S001
A forum poster claimed to have breached the national health insurer's database and offered data for sale, posting a sample of over 342,000 records linking insured people's identity numbers to their chosen doctors. The insurer is reviewing but cannot confirm.
Records of about 6,500 patients of a private clinic, with names, addresses, phone numbers and doctors' reports, were posted online. The data protection commissioner opened an inspection and said the clinic had not yet reported the breach.
The government said attackers targeted the state health insurer seeking patients' personal and treatment data. The health minister said the attack was repelled, and the insurer stated policyholders' data were safe and had not leaked.
From a Slovak source; summary ours.
BreachThe organization admitted the problemCase SVK-S003
The dentists' chamber says dental charts and image files do not reach the national electronic record, so other doctors cannot see them. It warns patients may get duplicate prescriptions or repeat imaging as a result.
From a Slovak source; summary ours.
Lost between providersAlleged, not decidedCase SVK-S002
A patient who changed general practitioner says the former doctor did not pass his records to the new one for over six months. Other former patients report the same, and a regional complaint is under review.
From a Slovak source; summary ours.
Lost between providersAlleged, not decidedCase SVK-S001
A hospital employee photographed patients and a document holding sensitive personal data and shared the images outside the hospital. The hospital confirmed it, disciplined the worker and reported the case to the data protection authority and police.
From a Slovenian source; summary ours.
BreachThe organization admitted the problemCase SVN-S001
A former patient complained that a staff member had viewed her health record while she was not in care there. The clinic confirmed repeated unauthorised access and misuse of login details, and notified police and the data protection authority.
From a Slovenian source; summary ours.
BreachThe organization admitted the problemCase SVN-S002
A patient received a test report carrying another person's name and findings, and only learned of the mistake when his doctor pointed it out. The Ministry of Health called this kind of mix-up a serious safety incident.
A patient says his first imaging report described the wrong part of the body and a corrected report mentioned a procedure that was never done, suggesting a mix-up with another patient. He says staff told him mistakes happen.
A TV programme received a bag of patients' results, operation lists and doctors' notes said to have been thrown out by a hospital. The hospital disputed where the bag came from; the data protection authority opened an inspection.
Spain's data protection authority fined 23andMe 2.4 million euros after a hacker used stolen passwords to reach sensitive health and genetic data of about 2,600 Spanish residents. The regulator found its safeguards insufficient.
BreachA regulator decidedCase ESP-S005
· Agencia Española de Protección de Datos (AEPD) · archived copy
An employee asked their employer's medical service twice for their full record and got no answer; copies came only after a complaint. The regulator upheld it, citing the right to know who holds the data.
From a Spanish source; summary ours.
Access refusedA regulator decidedCase ESP-S002
· Agencia Española de Protección de Datos (AEPD), PS-00560-2025 (EXP202503617) · archived copy
After leaving her private insurer, a patient had to request her record in person and pay 30 euros in cash for a one-page copy. The regulator found the charge unlawful; the clinic accepted responsibility and paid a reduced fine.
A primary care doctor used her own login to open a person's clinical record three times, though the person was not her patient. A provincial court gave her a suspended prison term, six years' disqualification and 50,000 euros in damages.
From a Spanish source; summary ours.
BreachA regulator decidedCase ESP-S004
· Síndic de Greuges de la Comunitat Valenciana (regional ombudsman), complaint 2403790
After a long wait for an appointment, a patient was told the specialist could not see a report held at another public hospital and was asked to fetch it herself. The ombudsman recommended records be reachable from every public centre.
From a Spanish source; summary ours.
Lost between providersA regulator decidedCase ESP-S003
A district court convicted a former nurse of data intrusion for unauthorised record lookups over several years, ordering a conditional sentence and 115,000 kronor in damages. Nineteen cases were tried; about 60 people had reported her to police.
A health declaration belonging to one patient was placed in another patient's record ahead of planned care. The error was found later. The region reported it under the serious-incident law, saying the wrong information could have affected safety.
From a Swedish source; summary ours.
Record wrongThe organization admitted the problemCase SWE-S005
A region's 90-page internal report found unclear saving of notes, wrong sample labels, medication lists that could not be printed and prescriptions failing to send. The region had filed ten serious-incident reports and the review recommended dropping the system.
From a Swedish source; summary ours.
OtherThe organization admitted the problemCase SWE-S004
A ransomware attack hit a private hospital's administrative systems. The clinical record system was not affected, but personal identity numbers, in some cases linked to diagnosis codes, were stolen and put up for sale. The hospital refused to pay.
From a Swedish source; summary ours.
BreachThe organization admitted the problemCase SWE-S003
Within days of a large region switching record systems, staff reported record information that was missing or disappeared, plus failures registering and finding patients. The region reported the system to the medical products regulator and paused it.
From a Swedish source; summary ours.
Record wrongThe organization admitted the problemCase SWE-S002
Patients asked a practitioner for their records and did not get them. Before police questioning he created a new electronic file showing one treatment where the original showed three. The court upheld his forgery conviction.
From a German source; summary ours.
Record wrongA court decidedCase CHE-S001
· Swiss Federal Supreme Court (Bundesgericht), 2C_567/2024 · archived copy
After a patient died in hospital, his relatives sought access to his record. Cantonal authorities refused to release the doctor from secrecy, and the federal court agreed, saying confidentiality outlasts death and applies to relatives too.
A cyberattack on a medical group left more than 100 affiliated doctors without access to patient files, schedules and billing for over a month. Its medical director said doctors had to rebuild files and no data had appeared online.
From a French source; summary ours.
OtherThe organization admitted the problemCase CHE-S004
A radiology network operating in seven cantons was attacked again in April 2026 and postponed some examinations. It could not yet say whether data was taken. In an attack a year earlier, patient data was stolen and a ransom demanded.
Staff at a public hospital copied patients' identity and contact details from the hospital information system and passed them to unlicensed insurance claims firms for commission. Health Ministry inspectors dismissed staff and suspended a doctor; a criminal investigation continues.
A health services company notified the data protection authority that a ransomware attack encrypted its data over two days. It could not yet say which people or data categories were affected. The board ordered the notice published.
From a Turkish source; summary ours.
BreachThe organization admitted the problemCase TUR-S004
Attackers encrypted servers at a private hospital. The breach notice published by the data protection authority lists patients, staff and visitors among those affected, with data including sexual life and biometric details. The number affected was not yet known.
From a Turkish source; summary ours.
BreachThe organization admitted the problemCase TUR-S002
A user claiming to hold a private hospital's database reportedly posted patients' identity numbers, addresses, diagnoses, prescriptions and insurance details online. The leak was unconfirmed and neither the hospital nor authorities had commented when reported.
A man said he was never examined, yet a military medical commission certified him fit for service. Asked by the court for the examination file and doctors' findings, the commission produced only the certificate, so the court annulled it.
The national health service said some clinics put inflated or invented entries into patients' electronic records to raise payments, and it ended contracts with several. Patients have reported finding visits in their records that never happened.
From a Ukrainian source; summary ours.
Record wrongA regulator decidedCase UKR-S002
· Уповноважений Верховної Ради України з прав людини (Ukrainian Parliament Commissioner for Human Rights)
A man asked a health facility for copies of medical records about his mother's death and says he received only some. After the human rights ombudsman wrote to the facility, it sent the requested documents electronically.
Investigators say a family doctor registered 1,731 patient declarations in the national e-health system without people's knowledge, using altered names, birth dates and addresses, to claim state payments for care never given.
Prosecutors named a doctor as a suspect for entering at least 22 false appointment records over two years for women who had never met him. The women discovered the entries themselves and went to police.
An insurer asked for five years of records, to go to the patient first for review. The surgery emailed 23 years straight to the insurer. The patient said their payout was cut. The ICO issued a reprimand.
Hackers entered a supplier's health systems through an account without multi-factor authentication. Data on 79,404 people was taken, including how to enter the homes of 890 people receiving care at home. The ICO fined the supplier £3.07m.
Over a year, a large hospital trust failed to answer 32% of people's requests for their own personal data within one month. It could not say how many requests were in its backlog. The ICO issued a reprimand.
Freedom of information requests found Scotland's health boards logged more than 5,000 data breaches over four years, including staff sharing confidential patient information and records wrongly accessed. At least 182 staff were disciplined and police were informed six times.
BreachThe organization admitted the problemCase GBR-S007
An NHS hospital trust confirmed that thousands of patient records, including test results, were stolen from a third-party testing provider's systems. The supplier said the data, possibly including names, NHS numbers and postcodes, was published on the dark web.
BreachThe organization admitted the problemCase GBR-S008
A clinician at a London hospital trust said its new electronic record system sent referrals to the wrong place, held missing or unreliable information and left patients lost to follow-up. The trust said the rollout caused a number of issues.
Lost between providersAlleged, not decidedCase GBR-S006
A survey of 1,800 adults for the patient watchdog found 23% had noticed mistakes or gaps in their NHS records, including wrong personal details, wrong medication and conditions they never had. Most said the errors caused problems.
Record wrongThe person's own accountCase GBR-S005
Middle East: 25 cases from 13 countries and territories
After a citizen complained, the Personal Data Protection Authority found a medical centre had emailed information and a document about his medical tests to his employer without valid prior consent or legal basis, and fined it 1,000 dinars.
A ransomware group listed a private hospital on its leak site, claimed to hold 110 GB of its data, posted images of systems it said it had accessed, and threatened to publish the data unless paid.
A disciplinary court suspended a public hospital doctor for six months. Prosecutors found she disclosed confidential medical information about patients online without their or the hospital's permission, and used patient information to promote clinics.
A member of parliament told the health minister that patients at some public hospitals leave with only a final summary, not detailed reports and test results, and some are stopped from photographing their own records.
In a formal request to the health minister, a member of parliament cited press reports that some laboratories had used patients' data unlawfully, and asked for regular oversight to stop misuse of patient data. No finding was reported.
Doctors and clinics posted patients' photos, videos and record details on social media pages. The health ministry referred 333 pages to prosecutors, who blocked them, and cases went to courts and the medical council.
A member of parliament's health committee confirmed a security council letter asking medical universities for patients' records after the January protests. He said the health ministry objected in confidential correspondence, citing patient confidentiality.
Reports cited by the outlet say security officers checked hospital records of discharged patients and pressed medical staff to report certain patients, and many people avoided hospitals for fear of arrest.
Pharmacists say drugs dropped from a prescription are often not recorded, so the national e-prescription system shows a complete prescription while the patient received only part of it.
An investigation into teaching hospitals quoted a trainee who said students filmed a procedure on their phones and the patient's name appeared in the footage. No one told the patient. The health ministry did not reply.
A member reported he could open a relative's medical file because of a system fault. The regulator found the fund knew in November 2025 but reported only in January, and fined it 256,000 shekels. The fund plans to appeal.
The health ministry said initial checks showed emails sent to and from the hospital on one day had leaked, including medical information in them. It said there was no sign so far of a leak from the central record system.
From a Hebrew source; summary ours.
BreachThe organization admitted the problemCase ISR-S002
A hacker group claimed to have stolen and posted documents of more than 10,000 patients, including referrals and sick-leave notes. The fund said it was checking the claim with national cyber authorities and had reported to the privacy regulator.
Health insurers and their industry union told insured people not to use a non-insurer claims platform, saying its access to patients' medical data breaks the personal data protection law and delays approvals for treatment.
A doctor published a patient's photograph, taken in connection with her care, on social media and advertising platforms without her consent. The Court of Appeals found this disclosed confidential medical information and imposed a fine.
A patient sought damages after a doctor published before-and-after photos in a hospital magazine. The appeal court found a confidentiality breach; the Court of Cassation held that patient consent, including implied consent, can lift the duty of secrecy.
A report citing a dark web forum post said patient files from four hospitals, from 2010 to 2021, leaked with names, birth dates, passport numbers and plain-text passwords that reportedly still opened lab results.
Gaza's director general of hospitals said over 70% of the medical archive at three hospitals was damaged or lost in the war. A ministry spokesman said staff cannot trace thousands of injured people's medical histories without the records.
From an Arabic source; summary ours.
OtherThe organization admitted the problemCase PSE-S001
Patients told the newspaper that government offices reject medical reports older than six months, so they must request new ones, wait about 14 working days and pay 50 riyals each time, though nothing has changed.
From an Arabic source; summary ours.
Delay or costThe person's own accountCase QAT-S001
The paper reported cases documented by the health ministry in which practitioners photographed patients during care and published the images online. In one case the ministry cancelled a licence and imposed a fine.
Callers told the paper that hospital booking lines, staffed from outside the kingdom, asked for ID numbers, birth dates and full patient details before sending them to an app. Security specialists warned of leak and misuse risks.
The emirate's health regulator closed five facilities and suspended staff pending referral to prosecutors. Inspections found sick notes issued without examining patients and manipulation of medical data, among other licensing violations.
The health regulator closed four facilities that sold sick leave over a messaging app, collecting ID photos and health details, then recorded visits that never happened in people's medical files and forged consent signatures.
Security sources told the outlet that hospitals and clinics in Houthi-held areas were linked to a new security unit and pressed to hand over daily details of patients and cases, building a health database on residents.
A relative says a hospital lab recorded a test value far outside the normal range. A doctor doubted it and ordered a retest elsewhere, which came back normal, pointing to a broken machine.
From an Arabic source; summary ours.
Record wrongAlleged, not decidedCase YEM-S002
Oceania: 18 cases from 6 countries and territories
A doctor in Western Australia repeatedly opened a patient's records and passed details to a person the patient had a restraining order against. The State Administrative Tribunal found misconduct and the doctor was deregistered.
Another woman's appointments and tests were added to a patient's health record. When the other woman died, police wrongly told the patient's family that the patient had died. Mercy Health apologised.
Record wrongThe organization admitted the problemCase AUS-S002
A patient agreed to have a specialist appointment transcribed by an AI tool. She later found a letter to her GP claimed something she says she never said. After she complained, the specialist apologised and corrected it.
A general practice in regional Victoria closed without warning. More than five months later its former patients still could not get their medical records, which remained under the closed practice's control while health agencies sought a fix.
Lost between providersAlleged, not decidedCase AUS-S004
After a South Australian patient spoke publicly about her care, the state health minister's office shared confidential details about her with journalists, the opposition claimed. She says she did not consent.
The outlet reports indications that several staff at a public hospital opened a patient's medical records without a care reason. The hospital operator said patient confidentiality is of the utmost importance.
Ransomware hit the Yap State health department's network. The department shut down every computer and its digital health systems, said so in a public notice, and kept serving patients more slowly while systems were rebuilt.
BreachThe organization admitted the problemCase FSM-S001
After a cyberattack exposed health documents belonging to 99,416 people, a review found gaps in protection, weak oversight of tech suppliers and late notice to those affected. The portal operator and Health NZ were ordered to strengthen safeguards.
An audit two patients requested showed a health worker they knew had opened both their medical records, over a personal matter, using a colleague's login. She lost her job, and a court found her guilty.
Health NZ acknowledged that two people with near-identical details can be linked to one National Health Index number, and that some may have received the wrong care as a result. It said it keeps no central record of such cases.
Record wrongThe organization admitted the problemCase NZL-S004
After a ransomware attack on a patient portal, a woman told her records were affected could not log in, and the helpline cut her off. Another was told both that her data was and was not affected.
BreachThe organization admitted the problemCase NZL-S003
· Office of the Privacy Commissioner (New Zealand), Case Note 329225 [2025] NZ Priv Cmr 1
A government agency sent a person's health information to the wrong address because a staff member recorded the house number incorrectly. The agency at first denied a mistake; after the regulator stepped in, it apologised and agreed to pay compensation.
BreachThe organization admitted the problemCase NZL-S001
The health ministry said attackers accessed hospital patient data, including names, addresses, phone numbers, birth dates and medical details. It advised everyone in Palau to watch for fraud and phishing messages.
BreachThe organization admitted the problemCase PLW-S001
After a ransomware attack the ministry shut its systems, and staff retrieved patient records manually. Services were delayed, and patients were asked to bring medicine containers and written prescriptions for refills.
Delay or costThe organization admitted the problemCase PLW-S002
The health minister said a ransomware attack took down the national health information system, which holds patients' medical records and prescriptions. The ministry told people to bring their prescription cards because doctors could not open records.
BreachThe organization admitted the problemCase TON-S001
The outlet reports that confidential information from the national health system was copied and leaked by the criminals who encrypted it and demanded a ransom, which the government refused to pay.
Another government minister told the outlet that protective software licences on the health records system had expired and backup procedures were not followed properly before hackers broke in, leaving the records exposed.
The outlet reports growing concern about illegal access to health records after hackers breached the national system, while patients were told to bring any medical records they hold to hospital because staff were working from manual data.
BreachAlleged, not decidedCase TON-S002
How we find and check cases
Each case is a published account of a real problem with a person's health record: 101 decisions by regulators and ombudsmen, 15 court judgments, 2 accounts on a parliament's official record and 324 reports by edited news outlets. We never use social media or forums, and never a story about a child.
We search in each country's own languages as well as English. The 442 cases here come from sources in 50 languages; 122 are in English. Only accounts published in the last two years are shown, and the window moves every month.
AI agents find each case, open the page it cites and write the summary in our own words, and every case is checked against our rules by code before it is published. Cases found by the weekly search, which began in October 2026, also pass automated checks: a copy of the page is kept, the passages behind the summary and the date are found word for word in that copy, and a second agent tries to show the case is wrong. A case that fails any check is not published.
We never name or identify the person. We name a hospital, company or other organization only when a regulator or court decided against it, or it admitted the problem. A summary is ours, not anyone's words, and never says a diagnosis, a care date or a place smaller than a region. The cases never change a country's score.
Each case gets one of four labels from what its source shows: a regulator or court decided it, the organization admitted the problem, it is alleged and not decided, or it is the person's own account with nothing else to back it. A decision can reach us through a news report of it, so a case can be decided and still come from the news.
To ask us to take a case down, write to privacy@supertruth.ai. A case taken down leaves this page, the country pages, the feeds, the downloads and the data API. Only its id, the date and a short reason stay on the list below, and the id is never used again.
Cite a case
Every case has an id: the country's three-letter code and a number, like FIN-S001. It never changes and never passes to another case. Cite the case with its id and its address on this page, and link the original account. For example:
Health Record Rights Index, real case ITA-S006 (our summary of a report by PPC Land, October 3, 2026), https://healthrecordrights.com/real-cases/#ITA-S006, cases as of October 7, 2026. Original: https://ppc.land/italy-fines-iqvia-eur7m-over-health-data-of-1m-patients-it-called-anonymous/
Two rules when you use them: a summary is ours, so never put it in quotation marks or call it anyone's words; and never use these cases to say how common a problem is.
Cases taken down
32 cases were taken down. Each id stays listed here with only the date and a short reason, so a citation that points to it lands on this line. Its headline, summary and link are gone from the site.
Case
Why it was taken down
Taken down
ARE-S001
withdrawn
BEL-S003
withdrawn
BEL-S005
withdrawn
BRA-S001
withdrawn
CAN-S005
withdrawn
CHN-S002
withdrawn
CHN-S003
withdrawn
CUB-S002
withdrawn
ECU-S002
withdrawn
EST-S001
withdrawn
GHA-S001
withdrawn
HTI-S003
withdrawn
IRL-S001
withdrawn
ITA-S001
withdrawn
JPN-S005
withdrawn
KAZ-S001
withdrawn
KAZ-S002
withdrawn
KEN-S001
withdrawn
KEN-S007
withdrawn
NOR-S001
withdrawn
PAN-S002
withdrawn
SAU-S002
withdrawn
STP-S001
withdrawn
SWE-S006
withdrawn
TLS-S002
withdrawn
TON-S003
withdrawn
URY-S001
withdrawn
URY-S003
withdrawn
USA-S001
withdrawn
UZB-S001
withdrawn
UZB-S002
withdrawn
UZB-S003
withdrawn
Cases as of . Our summaries are free to reuse with credit to SuperTruth (CC BY 4.0).