Real cases

442 published accounts of health record problems from 145 countries and territories

Our own short summaries of reports from regulators, courts, parliaments and the news, published October 2024 to October 2026, found in sources in 50 languages. The kind of problem written up most often: breach (171 of 442 cases). A regulator or court decided 175 of them. In 100 more, the organization involved admitted the problem; the rest are allegations or a person's own account. The list last changed on October 7, 2026, when a case was added or taken down. These cases are not a sample: they show what is published and findable, not how common a problem is.

The Health Record Rights Index, by SuperTruth, scores how much say a person has over their own health record in 198 countries and territories. These cases illustrate the scores and never change them. We searched every one of the 198; for the other 53 we found no published account from the last two years.

Pick a kind of problem to see its share of each bar. Hover, tap or use the arrow keys on a bar for its count.

all cases that month the kind of problem you picked a month not yet over every panel on the same scale, 0 to 15 cases a month

Africa 47 cases, 25 countries and territories
15Jan 2025Jan 2026to Oct 3
Americas 89 cases, 29 countries and territories
15Jan 2025Jan 2026to Oct 3
Asia 76 cases, 25 countries and territories
15Jan 2025Jan 2026to Oct 3
Europe 187 cases, 47 countries and territories
15Jan 2025Jan 2026to Oct 3
Middle East 25 cases, 13 countries and territories
15Jan 2025Jan 2026to Oct 3
Oceania 18 cases, 6 countries and territories
15Jan 2025Jan 2026to Oct 3

Each bar counts the cases whose source was published that month, October 2024 to October 2026, by region. Pick a kind of problem to see its share of each bar. Counts show what was published and what our searches found, not how often problems happen. October 2026 runs only to October 3, 2026, the newest source date, so its bars are drawn as outlines. Every case as a spreadsheet (CSV).

See the numbers
Cases by month of the source and by region
MonthAfricaAmericasAsiaEuropeMiddle EastOceaniaAll
October 202412161011
November 20240225009
December 202433160013
January 202534052014
February 2025022121118
March 202503560216
April 202503871019
May 202501271011
June 202523450418
July 202534160115
August 202505450115
September 2025051120018
October 202542441015
November 202532071114
December 2025532130023
January 202612141110
February 2026632104126
March 202631462218
April 20262103100025
May 202626362019
June 2026185112128
July 2026275111127
August 202635663124
September 2026339152133
October 2026 (so far)0012003
All4789761872518442
Cases by kind of problem and by region
Kind of problemAfricaAmericasAsiaEuropeMiddle EastOceaniaAll
Access refused1153151035
Delay or cost6135121138
Record wrong4915334368
Breach7283086812171
Sold or shared91413229168
Lost between providers743110126
Other136782036
All4789761872518442
Cases by how settled they are and by region
How settledAfricaAmericasAsiaEuropeMiddle EastOceaniaAll
A regulator or court decided8272010893175
The organization admitted the problem1119184228100
Alleged, not decided24423834137158
The person's own account4103109
All4789761872518442
Cases by kind of source and by region
Kind of sourceAfricaAmericasAsiaEuropeMiddle EastOceaniaAll
Regulator and ombudsman decisions41397401101
Court judgments14190015
Parliament records2000002
News reports4072661042517324
All4789761872518442

Newest cases worldwide

The 24 with the most recent source dates. Each links to its full entry below.

  1. · Italy · Sold or shared

    Italian regulator fines analytics firm over GP patient records it wrongly called anonymous
  2. · Ukraine · Access refused

    Man says health facility withheld some of late mother's records until ombudsman intervened
  3. · Vietnam · Record wrong

    Provincial health department finds recurring errors and gaps in hospital medical records
  4. · Finland · Breach

    About 50 health workers charged with unlawfully reading one patient's record
  5. · Indonesia · Lost between providers

    Patient says referral records sent to a hospital abroad were incomplete
  6. · Bulgaria · Record wrong

    Complaints about wrong entries in electronic health records rise by two thirds
  7. · Poland · Breach

    Clinic software flaw exposed patient ID numbers and hospital discharge papers
  8. · Indonesia · Access refused

    Patient's lawyer says a public hospital gave only partial copies of her records
  9. · Montenegro · Other

    Regulator orders hospital to stop filming patients in waiting areas and delete footage
  10. · Dominican Republic · Breach

    Insured woman says her file was taken and her signature forged for fake claims
  11. · New Zealand · Breach

    Portal and Health NZ ordered to fix security after 99,416 patients' data exposed
  12. · Romania · Delay or cost

    Weeks after launch, patients still cannot open their online medical record
  13. · Bahrain · Sold or shared

    Data protection authority fines medical centre for emailing patient test results to employer
  14. · Taiwan · Other

    Doctor charged with looking up other doctors' patients' records to win their business
  15. · Singapore · Breach

    Specialist centre's email error let 467 invitees see each other's addresses
  16. · Dominican Republic · Record wrong

    Prosecutors say ex-insurer staff used members' real data to file thousands of false claims
  17. · Saudi Arabia · Breach

    Ministry penalised practitioners who filmed patients during care and posted the clips
  18. · Slovenia · Breach

    Hospital confirms employee shared photos of patients and a document with personal data
  19. · Czechia · Breach

    Hackers offer a Czech health facility's patient records for sale
  20. · South Korea · Breach

    Doctor took thousands of patients' details; hospital fined for late notice, not the leak
  21. · South Korea · Breach

    Staff at public health agencies looked up personal data for private reasons, files show
  22. · Mozambique · Sold or shared

    Rights activist asks whether patients' clinical data will be sent abroad under US deal
  23. · Philippines · Breach

    Ransomware group claims it stole millions of files from a private hospital
  24. · Monaco · Breach

    Monaco hospital apologises after exposing hundreds of blood donors' email addresses

Cases by theme

Six kinds of problem have a page of their own, with the rule we file by and their own counts. A case fits one kind, chosen when it is written.

Breach 171 cases
A breach, as we file it: the record was stolen, leaked, hacked, or read by staff with no part in the person's care.
Record wrong 68 cases
A wrong record, as we file it: the record was wrong, and correcting it was hard or refused.
Sold or shared 68 cases
Sold or shared, as we file it: the record or health data was sold, shared with marketers or other parties, or published without consent.
Delay or cost 38 cases
Slow or costly access, as we file it: the person got their record, but late, or only after paying too much.
Access refused 35 cases
Access refused, as we file it: the person asked for their record, or the log of who viewed it, and was refused or ignored.
Lost between providers 26 cases
Lost between providers, as we file it: the record did not follow the person between providers, systems or countries.

Other: a real problem with a health record that fits none of the six. 36 cases are filed this way; they stay on this page.

Within each country, cases a regulator or court decided come first, then those the organization admitted, then allegations, then a person's own account; newest first within each.

Africa: 47 cases from 25 countries and territories

Algeria 1 case

Angola 1 case

· Correio da Kianda · archived copy

Hospital chiefs say unlinked systems make patients repeat registrations and tests between hospitals

Hospital directors and the national hospitals director said there is no single health information system, so a patient may be registered several times, exams are repeated, and transfers between hospitals happen without the patient's information reaching the receiving team.

From a Portuguese source; summary ours.

Lost between providers The organization admitted the problem Case AGO-S001

Cameroon 1 case

· Cameroon News Agency

Fire at a public hospital destroyed its medical records unit

A June 2026 fire at a public hospital in the North-West Region destroyed its medical records unit, along with its drug store and computer equipment, while the health ministry planned reconstruction.

Other Alleged, not decided Case CMR-S001

Cape Verde 1 case

· ERIS (Entidade Reguladora Independente da Saúde)

Health regulator warns providers after complaint over patient data sent abroad

Following a complaint, the regulator learned that several health facilities sent patient samples abroad for lab work, sharing sensitive personal data. It issued an alert reminding providers that patient consent is required.

From a Portuguese source; summary ours.

Sold or shared A regulator decided Case CPV-S001

Central African Republic 1 case

Democratic Republic of the Congo 1 case

· Mbote · archived copy

Congo signs US health deal amid concern over who controls health data

A Kinshasa outlet reports that Congo joined 14 African countries in US health deals that tie funding to expanded health data systems and fast reporting, while critics warn of lost control over health data and public trust.

From a French source; summary ours.

Sold or shared Alleged, not decided Case COD-S001

Equatorial Guinea 1 case

Eswatini 2 cases

· APAnews (African Press Agency)

Eswatini signs US health funding deal amid concern over sharing health data

Eswatini signed a US health funding agreement that, under the wider scheme, trades funding for access to pathogen samples and surveillance data. Critics warned the deal could expose the country's health data to abuse.

Sold or shared Alleged, not decided Case SWZ-S002

Ghana 4 cases

· Adom Online (Multimedia Group) · archived copy

Record system vendor blames unrenewed contract for hospital disruptions

The system's project manager said the contract expired in 2024 and an extension never came, leaving the project uncertain. Hospitals reverted to manual records and patients reported longer waits; the insurer told facilities to use a phone-based workaround.

Other Alleged, not decided Case GHA-S002

Guinea 1 case

Kenya 4 cases

· Business Daily (reporting a Data Protection Commissioner decision)

Hospital ordered to pay patient after using secretly filmed footage in its adverts

The regulator found a staff member recorded a patient during treatment and the hospital showed the footage on its screens as promotion. It could not prove consent, so it must pay Sh500,000 and delete the adverts.

Sold or shared A regulator decided Case KEN-S005

· Office of the Data Protection Commissioner (Kenya) · archived copy

Regulator finds hospital had no way for patients to see or correct records

An investigation the regulator opened itself found the hospital had no process for patients' access or correction requests, shared data with third parties without agreements, and was unregistered. An enforcement notice was issued.

Other A regulator decided Case KEN-S002

· The Star (Kenya)

National health insurer apologises as system failure halts approvals at hospitals

The insurer issued a notice that a critical failure at its digital platform since 1 March had stopped pre-authorisation and eligibility checks at contracted facilities nationwide. It apologised for the disruption to patient care.

Delay or cost The organization admitted the problem Case KEN-S006

Lesotho 2 cases

· Lesotho Times

Former miners say missing cross-border records leave them unable to prove claims

Former mineworkers home in Lesotho say incomplete mine records and poor coordination between South African and Lesotho authorities leave them without the proof a compensation fund requires. Some say they were refused with no reason given.

Lost between providers Alleged, not decided Case LSO-S001

Liberia 1 case

Malawi 1 case

Mauritius 3 cases

· L'Express (Maurice), via allAfrica

Health minister tells parliament patient files went missing in public hospitals

The health minister said 19 patient files had been reported missing in public hospitals since November 2024, and 349 files and 24 consultation cards were not available when needed because they sat in other departments. All were later found.

From a French source; summary ours.

Lost between providers The organization admitted the problem Case MUS-S001

· Le Defi Media Group

Hospital records staff say half-empty offices make patients return for their cards

Health records clerks in public hospitals say their departments run with about half the staff they should have. Some counters close, so patients must come back the next day to collect their card and learn their follow-up date.

From a French source; summary ours.

Delay or cost Alleged, not decided Case MUS-S003

Mozambique 2 cases

· Carta de Moçambique

Government confirms new US health deal includes sharing health data and samples

Reporting a health ministry statement, the outlet says a five-year US funding memorandum includes an agreement to share national health data and biological samples, which the government says will follow national data protection rules.

From a Portuguese source; summary ours.

Sold or shared The organization admitted the problem Case MOZ-S001

Namibia 2 cases

· The Namibian

State hospital admits patient files sat on floors and old beds

Photos showed patient files on a hospital floor, some soaked. Hospital management said it ran out of storage space, kept files on unusable beds, and acknowledged the store did not comply with archives law.

Other The organization admitted the problem Case NAM-S001

Nigeria 2 cases

· Sahara Reporters (republishing a Daily Trust report)

Patient paid repeatedly for the same tests because records did not follow her

A patient told reporters that each new hospital, private then public, made her repeat and pay for routine tests she had already done, because results were not transferable. A records officer said each hospital keeps its own unlinked system.

Lost between providers The person's own account Case NGA-S001

Senegal 4 cases

· Commission de Protection des Données Personnelles (CDP), Avis trimestriel N°04-2025

Regulator orders a private clinic to remove cameras filming its treatment rooms

After an anonymous report and an inspection, the national data protection commission ordered the clinic to take down cameras in its treatment rooms, switch off sound recording and declare its system properly.

From a French source; summary ours.

Other A regulator decided Case SEN-S001

· Le Quotidien

Public health council warns that publicising detainees' health status breaks the law

A national public health council said wide media coverage of arrests had exposed people's health status, noted that unauthorised disclosure is punished under a 2010 law and may engage state liability, and warned people may avoid testing.

From a French source; summary ours.

Breach Alleged, not decided Case SEN-S003

South Africa 2 cases

· Juta MedicalBrief (reporting an Information Regulator decision)

Pathology lab fined after failing to tell patients their data was exposed

The regulator found the lab had suffered breaches and not notified affected people within a reasonable time. It ordered better security and notification processes, then fined the lab R100,000 for not complying. The lab paid.

Breach A regulator decided Case ZAF-S002

Sudan 1 case

· Independent Arabia

Patient files left behind when a specialist hospital closed in the war

A hospital official said staff left and patient files and data stayed inside after the building was taken over. Displaced patients lost the link to their records and doctors, and some now carry their own papers between centres.

From an Arabic source; summary ours.

Lost between providers The organization admitted the problem Case SDN-S001

Tunisia 3 cases

· Nawaat

Official website lists disabled taxi licence holders, exposing their health status

An investigative outlet found that a regional authority published online a named list of disabled people holding taxi licences, revealing health information about each person, while the national data protection regulator remains frozen.

From an Arabic source; summary ours.

Sold or shared Alleged, not decided Case TUN-S001

· Inkyfada

Former detainee says his medical file was ignored after a prison transfer

A man held in several prisons says that after he was moved to a new prison, staff ignored his medical file, and care arrangements agreed at earlier prisons were dropped.

From a French source; summary ours.

Lost between providers The person's own account Case TUN-S002

· Ultra Tunisia

Patients carry paper files between hospitals whose computer systems do not connect

A reporter found patients from inland regions carrying bags of scans and test results between hospitals, because regional and university hospital systems do not share data. An older patient said nothing moves unless he hands over paper in person.

From an Arabic source; summary ours.

Lost between providers The person's own account Case TUN-S003

Uganda 2 cases

Zambia 3 cases

· National Assembly of Zambia, Public Accounts Committee (report on the Auditor General's 2024 accounts)

Health ministry staff shared passwords to the national patient record system

Auditors found clinic staff with full system rights and 528 shared administrator accounts in the national electronic patient record. The ministry told Parliament that staff going on leave handed their passwords to colleagues.

Other The organization admitted the problem Case ZMB-S002

· National Assembly of Zambia, Committee on Health, Community Development and Social Services

Insurance claims rejected because members' records listed the wrong sex

Evidence summarised by a parliamentary committee said the national health insurer's own database still held inaccurate patient records, so some hospital claims were rejected because patients' sex was wrongly recorded as male.

Record wrong Alleged, not decided Case ZMB-S003

Zimbabwe 1 case

Americas: 89 cases from 29 countries and territories

Antigua and Barbuda 3 cases

· Antigua.news (statement of the Medical Association of Antigua and Barbuda) · archived copy

Fire at a medical building destroys years of patient records at six practices

The national medical association said a fire at a shared medical building destroyed the offices, equipment and years of patient records of six doctors' practices, a loss it called a blow to the patients who rely on them.

Other Alleged, not decided Case ATG-S003

Argentina 4 cases

· Jujuygráfico · archived copy

Retirees' insurer posted members' clinical records on its public purchasing site

A fact-checking investigation found at least 40 purchase files on the insurer's public procurement search showing members' clinical histories, test results and ID copies. The insurer called it a serious anomaly, removed the files and opened internal inquiries.

From a Spanish source; summary ours.

Breach The organization admitted the problem Case ARG-S004

Bahamas 1 case

Belize 2 cases

· 7 News Belize

Patient says private hospital has refused for months to release her records

A patient said a private hospital refused to release her records despite letters from her lawyer since the previous year. She wanted them to understand her past care. Her lawyer said he would go to court to obtain them.

Access refused Alleged, not decided Case BLZ-S001

· 7 News Belize

Patient told hospital policy bars her from seeing her own medical records

A friend acting for a patient said a private hospital denied their request for the patient's medical records, citing hospital policy, after something went wrong in the patient's care. No one from the hospital had met them to explain.

Access refused Alleged, not decided Case BLZ-S002

Bolivia 1 case

· Tribunal Constitucional Plurinacional (SCP 0923/2025-S1)

Family says hospital left a patient's record request unanswered; court declines to rule

Relatives of an adult patient said in a constitutional claim that a written request for his clinical record went unanswered. His lawyer later acknowledged obtaining copies. The Constitutional Court denied protection without examining the merits.

From a Spanish source; summary ours.

Delay or cost Alleged, not decided Case BOL-S001

Brazil 4 cases

· Hoje em Dia · archived copy

Pharmacy chain fined R$8.4 million for demanding customers' tax ID at checkout

Minas Gerais consumer authority Procon fined a pharmacy chain over stores requiring customers' CPF at the counter. The decision warned hidden profiling of purchases could expose medicine records, for example to insurers refusing cover.

From a Portuguese source; summary ours.

Sold or shared A regulator decided Case BRA-S005

Canada 4 cases

· Information and Privacy Commissioner of Ontario (PHIPA Decision 332) · archived copy

Doctor did not answer a patient's request for their own health record

A patient in Ontario asked their doctor for access to their health information and got no reply within the legal time limit. The commissioner treated the silence as a refusal and ordered the doctor to respond.

Access refused A regulator decided Case CAN-S001

· Office of the Saskatchewan Information and Privacy Commissioner (Investigation Report 266-2024, 031-2025) · archived copy

Health worker looked into 70 people's records; patients not properly told

An employee opened the electronic health records of 70 people in Saskatchewan 210 times without a work reason. The commissioner found the health authority did not contain the breach properly or tell those affected enough.

Breach A regulator decided Case CAN-S003

Chile 4 cases

· Poder Judicial de Chile, Corte de Apelaciones de Santiago (rol 24.909-2025)

Court orders clinic to give a deceased patient's record to his children

A clinic refused to give a deceased patient's record to some of his children, saying all heirs had to ask together. The appeals court called the refusal illegal and arbitrary and ordered a full copy delivered within three working days.

From a Spanish source; summary ours.

Access refused A court decided Case CHL-S001

· BioBioChile (BBCL Investiga) · archived copy

Lookup website showed patients' diagnoses to anyone who typed in their ID number

For about 48 hours, a people-search website let anyone enter a Chilean ID number and see that person's diagnoses under the national guaranteed-care scheme, alongside address and contact details. Police and the cybersecurity agency are investigating.

From a Spanish source; summary ours.

Breach Alleged, not decided Case CHL-S002

Colombia 4 cases

· La FM

Regulator orders hospital and insurer to fix data handling after a patient's record leaked

Sensitive details from a woman's health record reached third parties without her consent. The data protection regulator found the hospital and her health insurer at fault and ordered five corrective measures, including staff training and stronger confidentiality.

From a Spanish source; summary ours.

Sold or shared A regulator decided Case COL-S001

· El Tiempo · archived copy

Insurer sanctioned for sending a patient's full record to the patient's employer

During a workplace illness review, a health insurer sent a patient's complete record, including sensitive test results, to four managers at the patient's employer. The data protection regulator sanctioned the insurer, saying the disclosure had no necessity or relevance.

From a Spanish source; summary ours.

Sold or shared A regulator decided Case COL-S002

· El Colombiano

Court orders clinic to apologise after staff passed patient data to an outside group

Clinic staff shared a woman's personal and medical details with an outside organisation, which then called and messaged her. The Constitutional Court ruled her privacy was violated and ordered the clinic to apologise publicly and investigate its staff.

From a Spanish source; summary ours.

Sold or shared A regulator decided Case COL-S003

Costa Rica 5 cases

Cuba 4 cases

· Árbol Invertido

Families pursuing medical harm claims say full records are hard to obtain

A reported feature on complaints about medical errors finds that patients and families struggle to get the complete record, which stays with the institution, and that access can be limited or delayed.

From a Spanish source; summary ours.

Delay or cost Alleged, not decided Case CUB-S005

· CubaNet

Prisoner says he has no access to his medical record or prescriptions

An adult prisoner told the outlet that after a hospital stay he was given no medicines in prison and could not learn what the specialist had prescribed, because he had never been given access to his medical record.

From a Spanish source; summary ours.

Access refused Alleged, not decided Case CUB-S003

Dominica 1 case

Dominican Republic 3 cases

· Diario Libre

Insurer added a stranger as a patient's spouse to move her policy without consent

A woman found her health insurance file listed an unknown man as her husband. The regulator fined the insurer, which moved 1,708 people onto its books without consent between 2023 and 2025 using invented family records.

From a Spanish source; summary ours.

Record wrong A regulator decided Case DOM-S001

Ecuador 2 cases

· Corte Constitucional del Ecuador · archived copy

Court finds clinic ignored order to hand a patient copies of her own record

A patient won a data access case ordering a dental clinic to give her certified copies of her record. The clinic did not comply. The Constitutional Court found it in breach, ordered delivery, a public apology and possible fines.

From a Spanish source; summary ours.

Access refused A court decided Case ECU-S001

El Salvador 5 cases

· Diario Co Latino

Health coalition says paper records from a rebuilt public hospital cannot be found

A health rights coalition said the paper records of patients treated before a national hospital was rebuilt and moved to a new hospital network have disappeared, so earlier test results are unavailable and some studies may need repeating.

From a Spanish source; summary ours.

Lost between providers Alleged, not decided Case SLV-S003

· BBC News Mundo

Unclear terms for a tech firm's use of patient data in state health app

Reporting on the state's AI telemedicine app found no public agreement setting out how the cloud technology partner may use patients' data. The company said the data belong to the client and did not say whether it is paid.

From a Spanish source; summary ours.

Other Alleged, not decided Case SLV-S004

· El Diario de Hoy (elsalvador.com)

Doctors report failures as ministry and social security merge patient records

As the health ministry's new information system was joined to the social security institute's electronic record, a doctors' union said the rollout came without training or coordination and the new system had shown multiple failures.

From a Spanish source; summary ours.

Other Alleged, not decided Case SLV-S005

Guatemala 2 cases

· Prensa Libre

Health ministry confirms attack encrypted files at its national laboratory

The health ministry confirmed an attack that encrypted internal files at its national laboratory. It said backups restored the files and it found no evidence that patient data was accessed, but some processes and its web platform were interrupted.

From a Spanish source; summary ours.

Breach The organization admitted the problem Case GTM-S002

Guyana 1 case

Haiti 2 cases

Honduras 2 cases

· La Prensa (Honduras)

Social security server failure leaves doctors unable to open patients' records

A patient arrived for a booked consultation and was sent away because staff could not open her medical history. The institute's board said 14 of 24 storage disks failed, forcing staff to record visits by hand for weeks.

From a Spanish source; summary ours.

Access refused The organization admitted the problem Case HND-S001

Jamaica 1 case

· The Gleaner

Hackers claim to hold medication data on National Health Fund clients

The National Health Fund confirmed a cyber incident after a hacker group said it held clients' medication data. The fund reported it to the Information Commissioner and police investigators and said affected stakeholders were contacted.

Breach The organization admitted the problem Case JAM-S001

Mexico 5 cases

· La Silla Rota

Court says judges can act at once when a clinic withholds a patient's record

A federal appeals court ruled that when a person says a health institution is denying access to their clinical record, judges may grant immediate protection, treating record access as part of the right to health.

From a Spanish source; summary ours.

Access refused A regulator decided Case MEX-S003

· Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI/013/2025)

Public insurer answered late and incompletely when a patient asked for scans

A person asked a public health insurer for copies of their imaging studies and the reports on them. The insurer missed the legal deadline and only found the files after a complaint. The regulator ordered delivery free of charge.

From a Spanish source; summary ours.

Delay or cost A regulator decided Case MEX-S001

· Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI/142/2024) · archived copy

Asked for a late father's record, a person was given someone else's

A person paid a public insurer for certified copies of their deceased father's record but was handed a relative's record instead. After a complaint, the insurer found the father's file. The regulator ordered free certified copies.

From a Spanish source; summary ours.

Access refused A regulator decided Case MEX-S002

· Publimetro México · archived copy

Records of a private hospital group's patients offered for sale online

A seller claimed to offer 400,000 lines of data from a private hospital group: patients' names, national ID and tax numbers, phones, emails, insurance policies, diagnoses and medical notes. The report carried no response from the hospital.

From a Spanish source; summary ours.

Breach Alleged, not decided Case MEX-S004

Nicaragua 4 cases

· Divergentes

Patient told her hospital file could not be found and had to repeat tests

A woman says two appointments were cancelled for lack of doctors, then staff said they could not locate her file. She repeated her tests and waited more than a year for follow-up.

From a Spanish source; summary ours.

Delay or cost Alleged, not decided Case NIC-S002

· Darío Medios · archived copy

Photos of patients during medical exams appeared in official propaganda posts

The outlet reports that a public hospital published photos of patients undergoing scans, some partly undressed and recognisable, in political messaging. Lawyers and health workers say this breaks the health law's confidentiality rules; no explanation was given.

From a Spanish source; summary ours.

Sold or shared Alleged, not decided Case NIC-S003

Panama 1 case

Paraguay 3 cases

· ABC Color

Health regulator finds a patient's digital record was rewritten minutes after the event

An audit by the Superintendencia de Salud found that the original entry in a patient's digital clinical record at the social security hospital was deleted and replaced six minutes later with a different account. The regulator identified the user responsible.

From a Spanish source; summary ours.

Record wrong A regulator decided Case PRY-S001

· ABC Color

Government cyber team confirms attack on Ministry of Health systems

The national incident response team CERT-PY said a cyber incident hit the Ministry of Health and was contained. A security expert warned that data taken in such attacks usually ends up exposed on dark web forums.

From a Spanish source; summary ours.

Breach The organization admitted the problem Case PRY-S002

· El Nacional

Ransomware locks electronic clinical records at several private hospitals

A reported ransomware attack on a private hospital group encrypted electronic clinical records and booking systems, forcing staff back to paper and delaying admissions, tests and appointments while attackers reportedly demanded payment.

From a Spanish source; summary ours.

Breach Alleged, not decided Case PRY-S003

Peru 4 cases

· La República

Regulator fines clinic for sending a patient's full record to prosecutors without consent

A clinic emailed a patient's complete record, covering about fifteen years, to prosecutors without her consent, her representative's approval or a court order. The national health regulator found this broke health law and fined the clinic.

From a Spanish source; summary ours.

Sold or shared A regulator decided Case PER-S001

· RPP Noticias

Clinic fined after staff leaked an image of a patient's record online

A photo of a computer screen showing a hospitalised patient's record spread online. The national health regulator ruled the disclosure a grave breach of confidentiality and fined the clinic more than 668,000 soles; the clinic said it would appeal.

From a Spanish source; summary ours.

Breach A regulator decided Case PER-S002

· La República

Social security health service opens audit after a patient's record reached television

Details from a patient's record were broadcast on a television programme. The public health insurer issued a statement rejecting the leak and opened an internal audit to identify the people who breached its system and supplied the information.

From a Spanish source; summary ours.

Breach The organization admitted the problem Case PER-S003

· OjoPúblico

Investigation finds clinics and insurers using patients' health data without consent

Reporters found private clinics and health insurers collecting sensitive health and personal data without consent and using it beyond care. Misuse led to one patient's suspension from work and to marketing harassment; regulators fined the sector over four million soles.

From a Spanish source; summary ours.

Sold or shared Alleged, not decided Case PER-S004

Trinidad and Tobago 2 cases

· Trinidad and Tobago Guardian

Health authority tells court it cannot find parts of a patient's records

A man suing a public health authority over his hospital care was allowed to go ahead despite filing late. The authority told the High Court it could not locate some of his medical records.

Other The organization admitted the problem Case TTO-S001

United States 11 cases

· U.S. Department of Health and Human Services, Office for Civil Rights

Six requests and more than a year before a patient got his records

A patient made six requests for his health information and waited more than a year to receive it. The regulator proposed a penalty; the provider settled before a hearing and paid $112,500.

Delay or cost A regulator decided Case USA-S002

· U.S. Department of Health and Human Services, Office for Civil Rights

Care provider posted patient stories online without written permission

A complaint said a group of care facilities put a patient's name, photo and care details on its website as a success story. The regulator found the same had happened to 150 patients without valid written authorization.

Sold or shared A regulator decided Case USA-S003

· California Department of Justice, Office of the Attorney General

Health website shared article titles that could reveal a reader's diagnosis

The state found a health information website sent identifiers and the titles of articles readers viewed to advertisers, ignored opt-out requests, and ran a consent banner that did not stop tracking. It paid $1.55 million.

Sold or shared A regulator decided Case USA-S009

· U.S. Department of Health and Human Services, Office for Civil Rights

Patient's full records arrived more than two years after her representative first asked

A patient's representative asked an academic health center for her records. Part came quickly; the rest arrived more than two years later, after two complaints to the regulator. The center did not contest a $200,000 penalty.

Delay or cost A regulator decided Case USA-S007

· U.S. Department of Health and Human Services, Office for Civil Rights

Patient asked by mail, phone and portal, then waited about nine months

A patient asked a health system for his medical records by mail, telephone and its patient portal. He received them about nine months later, only after the regulator opened an investigation. The system paid $60,000.

Delay or cost A regulator decided Case USA-S004

· U.S. Department of Health and Human Services, Office for Civil Rights

Patient asked for her records in writing and waited seven months for them

A patient made a written request for her records, went to collect them, then phoned many times. A county clinic sent them seven months later, after the regulator opened an investigation. The regulator imposed a $100,000 penalty.

Delay or cost A regulator decided Case USA-S006

· Yahoo News (TechCrunch)

Health records company confirms data of 3.75 million patients stolen in breach

A company storing electronic medical records for healthcare providers told federal regulators hackers stole personal information and medical records of more than 3.75 million people, including Social Security numbers, health information, ID numbers and banking details.

Breach The organization admitted the problem Case USA-S012

· Insurance Business

Billing software vendor confirms theft of insurance and claims data for 3.8 million people

Hackers copied insurance policy numbers, claims and benefits data, medical record numbers and Social Security numbers from a health billing software vendor. The vendor reported 3.8 million people affected to federal regulators about nine months after discovering the intrusion.

Breach The organization admitted the problem Case USA-S014

· TechCrunch

Insurer confirms health data of about 190 million Americans hit in one attack

A ransomware attack on a claims-processing company exposed names, ID numbers, insurance details and medical information such as test results and medications. Its parent company raised the count to about 190 million people. Attackers used a stolen credential.

Breach The organization admitted the problem Case USA-S005

Uruguay 1 case

Venezuela 3 cases

Asia: 76 cases from 25 countries and territories

Azerbaijan 3 cases

Bangladesh 4 cases

· Ajker Patrika · archived copy

Diagnostic centre admits an X-ray report wrongly said normal

A patient's X-ray report described the image as normal although a specialist saw clear signs of injury on the film. The diagnostic centre admitted the error, saying it happened while reports were obtained remotely by email.

From a Bangla source; summary ours.

Record wrong The organization admitted the problem Case BGD-S002

· Sangbad Sarabela · archived copy

Diagnostic centre apologises after scan report carried contradictory entries

A patient's scan report from a diagnostic centre contained entries that contradicted each other, and a doctor reading it gave alarming advice. A repeat test elsewhere found nothing wrong. The centre apologised in writing.

From a Bangla source; summary ours.

Record wrong The organization admitted the problem Case BGD-S001

Brunei 2 cases

· The Star (Borneo Bulletin/ANN) · archived copy

Record system outage halted services at a national health screening centre

A network failure made the Bru-HIMS record system unavailable at a government screening centre. Worker screening, vaccination and occupational health services were affected and people with appointments were told to reschedule. The ministry apologised.

Delay or cost The organization admitted the problem Case BRN-S002

· Borneo Bulletin

Network fault cut a public health centre off from patient records

An internet fault left a government health centre unable to reach the national Bru-HIMS record system. Test result reviews, sample collection and medicine pickups stopped there, and patients were sent to other centres. The ministry apologised.

Delay or cost The organization admitted the problem Case BRN-S001

China 5 cases

· 21st Century Business Herald (21经济网) · archived copy

National notice lists health apps that shared users' data with third parties without consent

A national cybersecurity notice listed 71 apps breaking personal data rules, including several medical and health apps. Violations included giving personal data to third parties without separate consent, no way to withdraw consent, and missing encryption.

From a Chinese source; summary ours.

Sold or shared A regulator decided Case CHN-S005

· The Paper (澎湃新闻) · archived copy

Shanghai regulator penalises online medical firms after patient data was stolen and left unencrypted

Shanghai's cyberspace regulator penalised several online medical service firms. One had unpatched flaws and suspicious foreign access that led to data theft; another stored over 6.5 million patient records, including conditions and prescriptions, without encryption.

From a Chinese source; summary ours.

Breach A regulator decided Case CHN-S004

· China Women's News (via Tencent News) · archived copy

Hospital apps let anyone with a patient's name and ID number download her records

Several large hospitals' online services released test reports and records to anyone with a patient's name and ID number. Someone a woman knew used this for two years to obtain and circulate her records. Some hospitals then added identity checks.

From a Chinese source; summary ours.

Breach The organization admitted the problem Case CHN-S006

· Legal Daily (via Hunan Daily / voc.com.cn) · archived copy

Investigation finds hospital staff selling patients' contact details for about 50 yuan each

Reporters found some hospital staff and outside contractors selling patients' names, addresses and phone numbers to private companies, about 50 yuan per record. A patient described being contacted by a company that already knew her private details.

From a Chinese source; summary ours.

Sold or shared Alleged, not decided Case CHN-S007

India 5 cases

· The Register

Health insurer confirms illegal access to customer records offered through chatbots

Records of more than 30 million customers, including ID images and claim documents, were offered through chatbots and later a website. The insurer acknowledged unauthorized and illegal access to certain data and obtained a court injunction.

Breach The organization admitted the problem Case IND-S001

Indonesia 2 cases

· Swarakaltim.com · archived copy

Patient says referral records sent to a hospital abroad were incomplete

A patient in East Kalimantan alleges that the records a public hospital sent with his referral abroad were incomplete, including a video of his care cut at crucial moments, and that the referral letter misstated his state of health.

From an Indonesian source; summary ours.

Lost between providers Alleged, not decided Case IDN-S002

Japan 4 cases

· Hokkaido Cultural Broadcasting (UHB)

Hospital hard drives meant for shredding turned up for sale at online auction

Hard drives two public hospitals sent for destruction were listed on internet auctions, holding names, addresses, clinical notes and nursing records for up to 510,000 people. The disposal firm said destroyed and intact drives were kept in identical containers.

From a Japanese source; summary ours.

Breach The organization admitted the problem Case JPN-S004

· Too Nippo (東奥日報)

Hospital worker suspended for reading a person's record and telling others what it showed

A public hospital's administrative support worker opened another person's electronic record several times with no work reason and told others what it showed. The prefectural hospital bureau suspended her for three months.

From a Japanese source; summary ours.

Breach The organization admitted the problem Case JPN-S003

· INTERNET Watch (Impress)

Hospital confirms attackers stole patient details through a maintenance VPN

A university hospital announced that a ransomware attack, entering through a VPN device used for medical equipment maintenance, led to the theft of names, addresses, birth dates and patient IDs of about 10,000 patients.

From a Japanese source; summary ours.

Breach The organization admitted the problem Case JPN-S002

· Nikkei xTECH

Clinic says ransomware attack may have exposed up to 300,000 people's records

A clinic announced that ransomware hit its servers, possibly exposing about 300,000 patient and staff records, including contact details, medical history and checkup results. It paused new outpatient bookings and said it had consulted police.

From a Japanese source; summary ours.

Breach The organization admitted the problem Case JPN-S001

Kazakhstan 3 cases

· Tengrinews.kz

Clinic notice about an adult patient's care went to a family member's phone

An adult patient says an automatic clinic notice about her care went to a family member. The health ministry said the clinic had likely never updated a relative's number added years earlier, and it is reviewing the SMS system.

From a Russian source; summary ours.

Breach Alleged, not decided Case KAZ-S003

Kyrgyzstan 2 cases

· 24.kg · archived copy

Bishkek patients told to take paper records home or risk losing them

Readers said clinics urged them to collect paper outpatient records quickly or they might not be found in the archive. The health ministry confirmed it, saying uncollected cards stay archived and can be signed out.

From a Russian source; summary ours.

Other The organization admitted the problem Case KGZ-S002

Malaysia 4 cases

Maldives 2 cases

Mongolia 3 cases

· National Human Rights Commission of Mongolia, 24th report on human rights · archived copy

Rights commission finds Intermed hospital failed to protect patient data before a cyberattack

After hackers took and posted names, ID and phone numbers of about 200,000 patients, a patient complained. The commission found weak cyber security, no rules for handling personal data and no breach plan, and ordered an audit and fixes.

From a Mongolian source; summary ours.

Breach A regulator decided Case MNG-S001

· National Human Rights Commission of Mongolia, 24th report on human rights · archived copy

Rights commission finds a hospital head gave a patient's health details to a reporter

A relative complained that a hospital head described a patient's health in a live interview with a news site. The commission found this broke the personal data law; the hospital head was warned and the press council asked to review.

From a Mongolian source; summary ours.

Sold or shared A regulator decided Case MNG-S002

· Mass.mn · archived copy

Intermed apologises after hackers took patient data; one patient says nobody called

Hackers demanded $50,000 for data said to include patients' names, ID numbers, phone numbers and medical histories. The hospital publicly apologised for the risk of leaked data. One patient said they reported it to police; the promised call never came.

From a Mongolian source; summary ours.

Breach The organization admitted the problem Case MNG-S003

Myanmar 1 case

Nepal 3 cases

· Naya Patrika

Insurance claims filed in a patient's name for care that never took place

A newspaper reports that a hospital submitted a claim with false bills for care it never gave an insured patient, and repeat claims for one patient, before the Health Insurance Board spotted and rejected them.

From a Nepali source; summary ours.

Record wrong Alleged, not decided Case NPL-S001

· Nepali Times

National health insurance system failure left months of claims data out of reach

A guest editorial reports that Nepal's national health insurance information system failed, making months of claims inaccessible overnight; hospitals struggled to recover the data, while some with their own electronic records resubmitted claims.

Other Alleged, not decided Case NPL-S003

North Korea 1 case

· Radio Free Asia (Korean service)

North Korean hospitals post a fee for diagnosis certificates as free care fades

Residents told a news outlet that hospitals now post charges at reception, including a fee for a diagnosis certificate, so patients must pay to get a written record of their own diagnosis.

From a Korean source; summary ours.

Delay or cost Alleged, not decided Case PRK-S001

Pakistan 3 cases

· The News International

Health department disciplines hospital staff after patients were filmed during care

Staff recorded patients during procedures and the video spread online. The provincial health department, which runs the hospital, suspended senior staff and said the recording breached medical ethics and undermined patient privacy.

Breach The organization admitted the problem Case PAK-S001

· The Express Tribune

Police refer case of allegedly false medical reports to Sindh health regulator

Police finished an inquiry into medical reports allegedly faked to justify a procedure on a woman at a private hospital in Sindh. The provincial healthcare commission will have experts review all records and hear both sides.

Record wrong Alleged, not decided Case PAK-S003

· The News International

Families say hospitals withhold clinical summaries needed to move patients elsewhere

Attendants told the newspaper that public, private and charitable hospitals often refuse a short clinical summary while treatment continues, saying it comes only after formal discharge, leaving families unable to arrange transfers or second opinions.

Lost between providers Alleged, not decided Case PAK-S002

Philippines 2 cases

· The Mindanao Sentinel

Ransomware group claims it stole millions of files from a private hospital

A ransomware group said it took about 2.44 terabytes of hospital data, including patient records and scans, and demanded payment. The hospital in Mindanao said its first checks found no sign of a breach and it was still investigating.

Breach Alleged, not decided Case PHL-S001

· Philstar.com

Insurer finds about 1,000 paid claims for patients who were never treated

The national health insurer said it was investigating about 1,000 suspected ghost patient claims in the Cordillera region, where members were recorded as treated when they were not. Members spotted them after receiving text alerts.

Record wrong Alleged, not decided Case PHL-S002

Singapore 4 cases

· Personal Data Protection Commission Singapore

Patient's record used to approach them for research without express consent

A patient complained that a hospital researcher, given the patient's name by their doctor, approached them in a waiting area to join a study. The regulator found implied consent sufficed but said express consent would have been better practice.

Other A regulator decided Case SGP-S001

· HRD Asia (HCA Magazine)

Hospital worker fined for looking up a former patient's record without reason

A hospital staff member opened a former patient's record on the hospital system for personal reasons and filmed the screen showing their ID number, address and contacts. The patient complained; she pleaded guilty and was fined.

Breach A regulator decided Case SGP-S002

· AsiaOne

Specialist centre's email error let 467 invitees see each other's addresses

A public specialist centre emailed an invitation to a patient event using CC instead of BCC, so all 467 recipients could see each other's addresses. The centre apologised and reported the incident to the health ministry and the privacy regulator.

Breach The organization admitted the problem Case SGP-S004

South Korea 5 cases

· Hankyung (Korea Economic Daily)

Doctor took thousands of patients' details; hospital fined for late notice, not the leak

A doctor deliberately took 3,976 patients' personal data while preparing to open a practice. The privacy regulator fined the hospital for late notification and weak supervision of staff, but found no breach of security duties.

From a Korean source; summary ours.

Breach A regulator decided Case KOR-S002

· Law Issue (로이슈)

Court fines dentist for writing false entries in a patient's record

A court fined a dentist one million won for writing a smaller medication amount in a patient's record than was actually given, and for recording health checks that were never carried out.

From a Korean source; summary ours.

Record wrong A regulator decided Case KOR-S004

· National Human Rights Commission of Korea

Rights commission finds a hospital routinely wrote false entries in a patient's record

After a patient died in hospital, the commission found staff had, as a routine practice, recorded a doctor as giving orders that the doctor never gave. It referred hospital staff to prosecutors and recommended changes to the law.

From a Korean source; summary ours.

Record wrong A regulator decided Case KOR-S001

· Pharmnews

Hospital doctors passed patients' prescription records to a drug company, court rules

Three senior doctors at a Seoul hospital gave drug company staff patients' prescription records, more than 17,000 entries, at the company's request. A court fined the doctors and the hospital's operator for failing to prevent it.

From a Korean source; summary ours.

Sold or shared A regulator decided Case KOR-S003

· Money Today (머니투데이)

Staff at public health agencies looked up personal data for private reasons, files show

Disciplinary files that the public health insurer and claims review agency gave a lawmaker show staff viewing relatives' and an ex-partner's data, querying colleagues, and emailing sensitive screening files home. Penalties ranged from reprimand to dismissal.

From a Korean source; summary ours.

Breach Alleged, not decided Case KOR-S005

Sri Lanka 2 cases

· ReadMe

Doctor booking website let anyone look up patient details by name

A public search page on an appointment booking platform reportedly showed patients' names, national ID numbers, phone numbers and appointment history. It came down only after a public post, and users were not told.

Breach Alleged, not decided Case LKA-S002

Taiwan 3 cases

· Knews (知新聞)

Mackay Memorial Hospital apologises after ransomware attack that may have taken patient data

After a ransomware attack, the hospital issued statements apologising and saying hackers may have stolen data while encrypting its systems. Millions of patient records were reportedly offered for sale; the ministry said the source still needed checking.

From a Chinese source; summary ours.

Breach The organization admitted the problem Case TWN-S001

· Central News Agency (中央社)

Doctor charged with looking up other doctors' patients' records to win their business

Prosecutors charged a hospital doctor with opening the records and contact details of three patients under other doctors' care, then texting them to criticise their doctors and urge them to switch to him. He has not been convicted.

From a Chinese source; summary ours.

Other Alleged, not decided Case TWN-S003

· Central News Agency (中央社)

Two men charged with buying hacked hospital patient records to resell online

Prosecutors charged two men with paying cryptocurrency for a file of about 20,000 hospital patients' visit and health records stolen by hackers, then advertising hospital data for sale on a messaging app. Prosecutors asked for heavy sentences.

From a Chinese source; summary ours.

Sold or shared Alleged, not decided Case TWN-S002

Thailand 5 cases

· Office of the Personal Data Protection Committee, via Government Public Relations Department

Hospital fined after patient record pages sent for destruction leaked as snack bags

A large private hospital hired a small contractor to destroy patient records but did not oversee the work. Over 1,000 record pages leaked and were reused as snack bags. The regulator fined the hospital and the contractor.

From a Thai source; summary ours.

Breach A regulator decided Case THA-S001

· The Standard

Health ministry admits staff errors put false entries in citizens' national health app records

Over 9,000 people flagged more than 24,000 entries in their national health app history as wrong. The ministry told a parliamentary committee about a quarter of checked entries were staff data-entry errors and others reflected performance targets, not care given.

From a Thai source; summary ours.

Record wrong The organization admitted the problem Case THA-S002

· Thairath

Cloud failure took patient records offline at public city hospitals, authority says

The city's medical service department announced that a cloud infrastructure failure stopped the patient database, appointment and dispensing systems at 14 of its hospitals. Hospitals stayed open and switched to paper records, but services were delayed.

From a Thai source; summary ours.

Other The organization admitted the problem Case THA-S005

· The Active (Thai PBS)

People with wrong entries in national health app say claims were blocked

Affected people said their national health app history listed treatments they never had, one with 16 false entries. One said an insurance claim could not proceed. They want false entries deleted in writing and those responsible identified.

From a Thai source; summary ours.

Record wrong Alleged, not decided Case THA-S003

· Bangkok Post

Patients moved after a hospital stopped public scheme care waited days for records

After a private hospital stopped public scheme outpatients, transferred patients waited up to seven days for their medical history. The national insurer said it could not reach their data because the hospital was not linked to the national records exchange.

Lost between providers Alleged, not decided Case THA-S004

Timor-Leste 1 case

· Diligente

Municipal health service admits running blood tests patients are never told about

Since 2024 a municipal health service has screened every patient's blood sample for an extra test without telling them. Its director confirmed patients are not informed. Lawyers called the practice illegal and a breach of privacy and consent.

From a Portuguese source; summary ours.

Other The organization admitted the problem Case TLS-S001

Turkmenistan 2 cases

· Turkmen.news

Patients say state health officials demand bribes to sign final medical reports

Patients seeking approval for treatment abroad say officials asked for 5,000 dollars before signing the final medical conclusion they need, and that people who do not pay can wait years for the document.

From a Russian source; summary ours.

Delay or cost Alleged, not decided Case TKM-S001

· Chronicles of Turkmenistan (Хроника Туркменистана)

Teachers say medical check certificates are sold without anyone checking results

Teachers describe paying a bribe to have their required medical record books filled in, and one says a clinic doctor took samples but issued a certificate of normal results two hours later without checking them.

From a Russian source; summary ours.

Record wrong Alleged, not decided Case TKM-S002

Vietnam 5 cases

· Bao Dong Nai

Provincial health department finds recurring errors and gaps in hospital medical records

A provincial health department official reported common record faults found across facilities: diagnoses not updated, test results not assessed, sections that contradict each other and orders with no clear link to the patient's condition. No facility was named.

From a Vietnamese source; summary ours.

Record wrong A regulator decided Case VNM-S005

· Tuoi Tre

Police cybersecurity unit warns of two attacks on hospital data in one month

A police cybersecurity official said attackers hit hospital or health ministry data twice in one month, threatening to expose details of thousands of doctors and patients, including diagnostic imaging, and warned that health sector security is weak.

From a Vietnamese source; summary ours.

Breach Alleged, not decided Case VNM-S002

· VietTimes

Patients get sales calls after hospital visits as their data is sold online

Patients described being phoned with sales offers soon after hospital discharge. A security expert found patient names, phone numbers and medical history sold cheaply on a messaging app. Some hospitals stayed silent about attacks, the report says.

From a Vietnamese source; summary ours.

Sold or shared Alleged, not decided Case VNM-S003

· Sai Gon Giai Phong

Patients say doctors posted their consultations and procedures online without clear consent

Two adult patients said clinics posted images or livestreamed their consultations for promotion without clear consent; one learned colleagues had seen the video. A city health department head condemned the practice, citing confidentiality rules.

From a Vietnamese source; summary ours.

Sold or shared Alleged, not decided Case VNM-S004

Europe: 187 cases from 47 countries and territories

Albania 3 cases

· Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale (IDP) · archived copy

Regulator steps in after clinic ignores a patient's request for their file

A patient asked a private clinic for all the records it held on them and got no reply. After a complaint, inspectors visited, the clinic produced the file and undertook to supply it, and the regulator ordered fixes.

From an Albanian source; summary ours.

Access refused A regulator decided Case ALB-S001

· Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale (IDP)

Medical laboratory fined for weak safeguards on patient data

Months after a regulator recommendation, a medical laboratory still had no data protection terms with firms handling patient data for it and an incomplete security system. The regulator fined it ALL 2.8 million.

From an Albanian source; summary ours.

Other A regulator decided Case ALB-S002

· Faktoje.al · archived copy

Ransomware locks a public hospital's data and halts scans and lab tests

Ransomware encrypted all of a regional public hospital's data, stopping imaging and blood testing until services returned within 72 hours. The report says some patient data was deleted. The hospital confirmed the attack.

From an Albanian source; summary ours.

Breach The organization admitted the problem Case ALB-S003

Andorra 2 cases

Armenia 1 case

· Hetq · archived copy

Former doctors allege a regional hospital recorded patients who were never treated

Former doctors told investigative reporters that hospital management entered names of people who were not ill as state-funded patients, inflating patient numbers. The health ministry referred the claims to anti-corruption investigators; management called them absurd.

From an Armenian source; summary ours.

Record wrong Alleged, not decided Case ARM-S001

Austria 3 cases

· Datenschutzbehörde (Austrian Data Protection Authority), decision 2026-0.018.391 · archived copy

Therapy centre left handwritten notes out of a patient's access request

A patient asked a therapy centre for all data held about them. The centre left out notes a staff member kept by hand. The regulator found this breached the right of access and ordered full disclosure within four weeks.

From a German source; summary ours.

Access refused A regulator decided Case AUT-S003

· Federal Administrative Court (Bundesverwaltungsgericht), W108 2276075-1, upholding a Datenschutzbehörde decision · archived copy

Hospital security manager copied a patient's record and emailed it to police

A patient learned during a court case that a hospital report about them had reached third parties. The regulator found the hospital's security manager had copied the electronic record and emailed it to police. The court upheld that finding.

From a German source; summary ours.

Sold or shared A court decided Case AUT-S001

· Datenschutzbehörde (Austrian Data Protection Authority), penal decision 2025-0.625.944

Doctor opened a person's national e-health record without consent; regulator fined her

A woman found through the ELGA access log that a doctor had opened her stored results and medication data without consent and unconnected to any treatment by that doctor. The regulator found a violation and imposed a 1,000 euro fine.

From a German source; summary ours.

Breach A regulator decided Case AUT-S002

Belarus 3 cases

· Onliner (people.onliner.by)

Patient suing a private clinic says it would not hand over her records

A patient in a damages case says a private clinic refused her copies of her medical and anaesthesia records. A video of the procedure turned out to be deleted, and its documents gave conflicting figures.

From a Russian source; summary ours.

Access refused Alleged, not decided Case BLR-S002

Belgium 3 cases

· Gegevensbeschermingsautoriteit (Belgian Data Protection Authority), Litigation Chamber decision 209/2025 · archived copy

Access list showed a therapist opened a patient's test results without a care reason

A patient asked her hospital group who had opened her electronic record. The list showed a therapist working there had viewed her test results three times. The regulator reprimanded the hospital for weak access controls; an appeal is pending.

From a Dutch source; summary ours.

Breach A regulator decided Case BEL-S001

· Gegevensbeschermingsautoriteit (Belgian Data Protection Authority), Litigation Chamber decision 166/2024 · archived copy

Ransomware hit a hospital whose patient record system had weak password protection

An attacker locked a hospital's servers and exported about 5 gigabytes of data. The regulator found security failings, including weak protection of access to the electronic patient record, and fined the hospital 390,000 euros. An appeal court later reduced it.

From a Dutch source; summary ours.

Breach A regulator decided Case BEL-S002

· RTBF · archived copy

Hackers took 53,900 sick-leave check files including doctors' comments

A company that runs employer-requested sick-leave checks said hackers had taken 53,900 files, including names, addresses, incapacity levels and examining doctors' comments, and published them a week later. It warned of phishing using the data.

From a French source; summary ours.

Breach The organization admitted the problem Case BEL-S004

Bosnia and Herzegovina 3 cases

· Institucija ombudsmena za ljudska prava Bosne i Hercegovine · archived copy

Ombudsman tells health centre to answer a request to correct a record

A patient asked a public health centre to amend her health record and heard nothing for two years. The ombudsman found no formal decision had been made and told the centre to decide at once.

From a Bosnian source; summary ours.

Record wrong A regulator decided Case BIH-S001

· Institucija ombudsmena za ljudska prava Bosne i Hercegovine · archived copy

Patient asking to move a health file is told months later none exists

A patient asked a public health centre to transfer his file to another clinic. Two months later he was told he had no file there. The ombudsman told the centre to open one and explain his options.

From a Bosnian source; summary ours.

Lost between providers A regulator decided Case BIH-S002

Bulgaria 4 cases

· zdrave.net

Health fund sanctions providers after patients spot unperformed care in their records

Insured people using the eZdrave app found medical activities in their electronic records that had never been carried out. After checks, the national health fund imposed fines, partly ended contracts and recovered money paid.

From a Bulgarian source; summary ours.

Record wrong A regulator decided Case BGR-S001

· Gospodari.com · archived copy

Patients flag 1,760 record entries they say never happened

A new eZdrave feature asks patients whether they attended each recorded visit. Within weeks they had sent 1,760 reports of exams, test results and hospital stays they did not recognise, and 560 checks had begun.

From a Bulgarian source; summary ours.

Record wrong Alleged, not decided Case BGR-S002

Croatia 4 cases

· Agencija za zaštitu osobnih podataka (AZOP), final decision UP/I-034-01/24-01/23 · archived copy

Patients asked a private hospital for their scans; the images had been lost

Several patients complained that a private hospital never sent copies of their records. The regulator found imaging files had been irretrievably lost, no backups existed, the loss was never reported, and fined the hospital 190,000 euros.

From a Croatian source; summary ours.

Access refused A regulator decided Case HRV-S001

· Agencija za zaštitu osobnih podataka (AZOP), anonymised decision 567-UP/I-034-01/24-01/31 · archived copy

Hospital worker photographed a patient's test result on screen and it reached the media

An unknown hospital employee photographed a patient's result in the hospital system and it was published by the media. The hospital neither reported the breach nor told the patient until their lawyer wrote. The regulator fined it.

From a Croatian source; summary ours.

Breach A regulator decided Case HRV-S002

· Agencija za zaštitu osobnih podataka (AZOP), anonymised decision 567-UP/I-034-01/24-01/34 · archived copy

Ransomware attacker spent a week inside a hospital network and copied data out

After a ransomware attack, the regulator found a hospital's weak technical safeguards let an attacker roam its systems unnoticed for about seven days and copy at least 3 GB out. The hospital was fined 20,000 euros.

From a Croatian source; summary ours.

Breach A regulator decided Case HRV-S003

· Dnevnik.hr (Nova TV)

Hackers claim to have posted thousands of patient records from a Croatian practice

A hacking group claimed it broke into a private medical practice and posted about 9,400 records for free download, including names, national ID numbers, addresses, medicines, doctors' notes and scanned medical documents. The practice was not named.

From a Croatian source; summary ours.

Breach Alleged, not decided Case HRV-S004

Cyprus 5 cases

· Επίτροπος Διοικήσεως και Προστασίας Ανθρωπίνων Δικαιωμάτων (Ετήσια Έκθεση 2024)

Ombudsman's intervention recovers a patient's missing hospital file

A patient asked the ombudsman for help after a former state hospital could not locate his medical file. After the ombudsman stepped in, the file was found and he regained access to his key health data.

From a Greek source; summary ours.

Delay or cost A regulator decided Case CYP-S001

· Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Ετήσια Έκθεση 2024)

State hospitals fined after ten patients' medical files went missing

The state hospital body reported losing ten patients' medical files and three emergency registration forms. The regulator found no safeguards against loss, fined it 46,500 euros in total and ordered it to tell seven patients.

From a Greek source; summary ours.

Breach A regulator decided Case CYP-S002

· Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Ετήσια Έκθεση 2024)

Two doctors reprimanded for giving a patient's medical certificates to his former wife

A man complained that two doctors issued certificates about his past care to his former wife without his knowledge or consent. The regulator found they processed his health data with no legal basis and reprimanded both.

From a Greek source; summary ours.

Sold or shared A regulator decided Case CYP-S003

· Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Ετήσια Έκθεση 2024)

Doctor reprimanded after the secretary phoned a patient's next of kin about an appointment

A doctor's secretary looked up a patient's GeSY account and phoned his father, listed as next of kin, to confirm a booking. The regulator ruled that number was not an alternative contact and reprimanded the doctor.

From a Greek source; summary ours.

Sold or shared A regulator decided Case CYP-S004

Czechia 4 cases

· oPojištění.cz (reporting a Supreme Administrative Court ruling of 21 May 2025) · archived copy

Court upholds fine on clinic that failed to report a patient data breach

A cyberattack left a private clinic's patient records unreachable for a week. The clinic, holding data on about 250,000 patients, did not report it in time and could not prove it told patients. The court confirmed a 309,000 crown fine.

From a Czech source; summary ours.

Breach A regulator decided Case CZE-S001

· ČT24 (Česká televize) · archived copy

Hospital warns patients a ransomware attack may have exposed their record data

After ransomware shut down its systems, a hospital told patients that personal data linked to their medical records may have been stolen. It could not yet confirm whether or how much was taken, and notified the data protection office.

From a Czech source; summary ours.

Breach The organization admitted the problem Case CZE-S002

· Aktuálně.cz · archived copy

Hackers offer a Czech health facility's patient records for sale

A security firm reported that a hacking group stole a database from an unnamed Czech health facility and offered it for sale. It reportedly held patient contacts with health records, booking details with payment and insurance data, and staff profiles.

From a Czech source; summary ours.

Breach Alleged, not decided Case CZE-S003

Denmark 5 cases

· Styrelsen for Patientklager (Danish Patient Complaints Board), 26SFP21

Clinic told a patient abroad to fetch their record in person on USB

A patient living outside Denmark asked a general practice for an electronic copy of their record. The clinic said it could only hand it over on a new USB stick the patient brought in person. The board criticised the clinic.

From a Danish source; summary ours.

Delay or cost A regulator decided Case DNK-S001

· DR · archived copy

Regulator criticised a university for passing on research participants' health data without permission

After inspecting eight research projects using health information, the data protection authority gave serious criticism: the university had several times passed personal data on without the required permission and supervised partners poorly. The university said it takes the criticism seriously.

From a Danish source; summary ours.

Sold or shared A regulator decided Case DNK-S005

· DR · archived copy

Hackers posted patients' health details from a GP chain online

After a cyberattack on a nationwide chain of GP practices, hackers posted patient information including illness history, hospital referrals and medication. The chain had confirmed personal data on an unknown number of patients was compromised.

From a Danish source; summary ours.

Breach The organization admitted the problem Case DNK-S004

· DR · archived copy

Millions of hospital records used for AI research without a prior risk check

Experts said two regions gave a research project access to 3.65 million people's hospital records without first assessing data protection risks. A regional director said the analysis perhaps should have been done. The regulator opened an inquiry.

From a Danish source; summary ours.

Sold or shared Alleged, not decided Case DNK-S003

Estonia 4 cases

· Riigikontroll (National Audit Office of Estonia), report to the Riigikogu · archived copy

Provider ignored a patient's request to correct entries in the national health system

A patient asked a provider to correct data it had sent to the national health system. The provider said the entries were right and would not discuss it. The audit office said this broke the provider's complaints rules.

From an Estonian source; summary ours.

Record wrong A regulator decided Case EST-S002

· Riigikontroll (National Audit Office of Estonia), report to the Riigikogu · archived copy

Patient found portal entries from a doctor they were not registered with

Checking the national patient portal, a patient found that a family doctor whose list they were not on had recorded a diagnosis and treatment for them. The audit office warned that a misleading history can affect later care decisions.

From an Estonian source; summary ours.

Record wrong A regulator decided Case EST-S003

· Riigikontroll (National Audit Office of Estonia), report to the Riigikogu · archived copy

One wrong letter in a code put a false diagnosis on record

For years, documents sent to the national system carried a diagnosis code one letter away from the right one, recording an unrelated finding. The audit office noted such errors can mislead treatment and harm a person's reputation and job prospects.

From an Estonian source; summary ours.

Record wrong A regulator decided Case EST-S004

Finland 5 cases

· Tietosuojavaltuutettu (Office of the Data Protection Ombudsman), decision TSV/1507/2024 · archived copy

Provider said its system could not show who opened a patient's record and when

A patient asked a health provider for log data showing who had viewed their records over two years, with times and reasons. The provider said its system could not produce usable logs. The deputy ombudsman ordered it to supply them.

From a Finnish source; summary ours.

Access refused A regulator decided Case FIN-S001

· Yle · archived copy

Patient's log request revealed two staff had viewed about 150 people's records

A patient obtained the log of who had opened their record and reported it to police. The wellbeing region found two employees had viewed nearly 150 people's records without a care relationship, and its chief medical officer apologised.

From a Finnish source; summary ours.

Breach The organization admitted the problem Case FIN-S003

France 6 cases

· Conseil d'État · archived copy

Top court upholds fine over patient data passed on without true anonymisation

Doctors' software gathered patients' health data, such as prescriptions and sick leave, with identifiers that allowed care pathways to be traced. The court agreed the data were not anonymous and rejected the company's challenge to an 800,000 euro fine.

From a French source; summary ours.

Sold or shared A court decided Case FRA-S001

· franceinfo · archived copy

Doctors' private notes on patients exposed in attack on medical software

Attackers reached files of 1,500 doctors using one practice software. Administrative data on 15 million patients leaked, and the health minister said sensitive doctor annotations on 164,000 patients were exposed. The vendor said structured medical records were intact.

From a French source; summary ours.

Breach The organization admitted the problem Case FRA-S005

· Clubic · archived copy

Hospital records of about 750,000 people posted online after stolen login used

A hacker posted a database of about 758,000 people taken from hospital management software, including contact details, treating doctor, prescriptions and death declarations. The software maker said a privileged account at a client hospital was misused.

From a French source; summary ours.

Breach The organization admitted the problem Case FRA-S004

Georgia 2 cases

· Public Defender (Ombudsman) of Georgia, National Preventive Mechanism · archived copy

Ombudsman finds patients' medical files at an inpatient clinic nearly empty

On a monitoring visit, the Public Defender's team found the clinic's patient files held almost no entries and often lacked lab results and specialist notes. It tied the gaps to overworked doctors and staff shortages.

From a Georgian source; summary ours.

Record wrong A regulator decided Case GEO-S002

Germany 5 cases

· Hessian Commissioner for Data Protection and Freedom of Information (HBDI) · archived copy

Practices answered online reviews by publishing patients' names and record details

Patients left anonymous negative reviews online. Medical practices replied in public, naming the patients and disclosing details from their records. The state regulator listed these among cases where it imposed fines in 2024.

From a German source; summary ours.

Sold or shared A regulator decided Case DEU-S001

· Hessian Commissioner for Data Protection and Freedom of Information (HBDI) · archived copy

Practice manager took patient files home where guests could read them

The state regulator reported a practice manager who took patient records home and left them unsecured, where party guests could see them, and who also sent photos of patient files to a partner by messaging app.

From a German source; summary ours.

Breach A regulator decided Case DEU-S002

· heise online · archived copy

Hospital group says patient data may have been taken in a cyberattack

After an attack disrupted all its German facilities, a hospital group said data on patients, staff and partners may have been accessed without authorisation and could be misused or passed to others.

From a German source; summary ours.

Breach The organization admitted the problem Case DEU-S004

· c't (heise) · archived copy

Former patient found a rehab app exposed medical reports without a login

A former patient noticed a rehabilitation provider's app talked to its servers unencrypted, and that patient files, including medical reports, could be opened without authentication. The provider said the gap was closed and it saw no sign of data outflow.

From a German source; summary ours.

Breach Alleged, not decided Case DEU-S005

· t-online · archived copy

Man switching insurers found diagnoses in his ePA that he says he never had

Seeking private insurance, a man opened his electronic patient record and found three diagnoses he says do not apply to him, billed during routine visits. Insurers saw him as high risk. Only the treating doctor can correct them.

From a German source; summary ours.

Record wrong The person's own account Case DEU-S003

Greece 5 cases

· Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 13/2026

Public hospital left its surgery waiting list, with patients' phone numbers, open online

A member of the public found, through a search engine, a hospital file listing about 2,820 patients' phone numbers and planned operations, online for months. The hospital reported late, never told patients, and was fined 25,000 euros.

From a Greek source; summary ours.

Breach A regulator decided Case GRC-S001

· Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 11/2025 · archived copy

Private doctor looked up a patient's national health record without permission

A patient asked a private doctor for her full file and complained the doctor had also searched her electronic health record. The regulator found the lookup unlawful, done without her knowledge, and fined the doctor 5,000 euros.

From a Greek source; summary ours.

Breach A regulator decided Case GRC-S002

· Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 50/2024 · archived copy

Doctor kept patient's clinical photos online after she withdrew her consent

A patient complained that her doctor posted photos taken during her care on his social media page. The regulator ruled that keeping them up after she withdrew consent was unlawful and ordered his consent forms rewritten.

From a Greek source; summary ours.

Sold or shared A regulator decided Case GRC-S003

· Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 37/2024 · archived copy

Hospital doctor running for parliament texted campaign messages to former patients

People who had been treated at a public hospital received election text messages from a doctor there who was a candidate. He could not show how he got their numbers; the regulator fined him 15,000 euros.

From a Greek source; summary ours.

Sold or shared A regulator decided Case GRC-S004

· in.gr · archived copy

Hospital said it could not supply copies of past scans after a cyberattack

A relative asked a university hospital for copies of a patient's earlier test results. The hospital replied it had no access to its electronic system because of a cyberattack; the outlet reports other patients got the same answer.

From a Greek source; summary ours.

Access refused Alleged, not decided Case GRC-S005

Greenland 2 cases

Hungary 5 cases

· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), decision NAIH-273-7/2026

Former family doctor opened an ex-patient's national health record 47 times

A patient checked the access log in the national health record system and found a doctor they had left kept viewing their results and prescriptions for 19 months. The doctor also ignored their access request. The regulator imposed a fine.

From a Hungarian source; summary ours.

Breach A regulator decided Case HUN-S001

· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2025, case NAIH-2306-1/2025

Clinic charged per page for a patient's records, regulator rules access is free

A patient asked a health institution to email all their outpatient records. It demanded a per-page fee and said records could only be collected in person. It sent them free months later, after the regulator opened a case.

From a Hungarian source; summary ours.

Delay or cost A regulator decided Case HUN-S002

· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2025, case NAIH-9859/2025

Stranger's visit record filed in a patient's national health record by name mix-up

A health institution uploaded another person's outpatient visit sheet into a patient's national record because they shared a name. The regulator found the record inaccurate and faulted the institution for not reporting the resulting breach.

From a Hungarian source; summary ours.

Record wrong A regulator decided Case HUN-S003

· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2024, case NAIH-295/2024

Patient files left in a closed health building after repeated break-ins

A health institution left large volumes of patient records in a closed building that intruders kept entering, scattering files inside. It did not remove them or tell patients for over nine months. The regulator fined it two million forints.

From a Hungarian source; summary ours.

Breach A regulator decided Case HUN-S004

· Pénzcentrum (citing Telex) · archived copy

Ransomware group claims it stole a private clinic's patient files

A ransomware group said it took about 178,000 files from a private clinic, including invoices and treatment reports, and threatened to publish them. The clinic had not answered press questions when the report appeared.

From a Hungarian source; summary ours.

Breach Alleged, not decided Case HUN-S005

Iceland 6 cases

· Umboðsmaður Alþingis, mál nr. 185/2026

Ombudsman leaves in place refusal of widow's access to late husband's health record

A widow was refused access to her late husband's health record by a health institution, and the Directorate of Health upheld the refusal. The Parliamentary Ombudsman found no grounds to object, noting the request was not supported by documents.

From an Icelandic source; summary ours.

Access refused A regulator decided Case ISL-S006

· Persónuvernd (Icelandic Data Protection Authority)

Specialist doctor's repeated look-ups in a patient's record ruled unlawful

A specialist doctor opened an adult's health record six times over several years without a treatment relationship or consent. The data protection authority ruled those look-ups unlawful but imposed no fine.

From an Icelandic source; summary ours.

Breach A regulator decided Case ISL-S001

· Persónuvernd (Icelandic Data Protection Authority)

National hospital sent a patient's health data to the wrong primary care clinic

The national hospital sent an adult patient's sensitive health information to a primary care clinic she was not registered with. The data protection authority ruled the disclosure unlawful; the hospital said it regretted the mistake.

From an Icelandic source; summary ours.

Sold or shared A regulator decided Case ISL-S002

· Persónuvernd (Icelandic Data Protection Authority) · archived copy

Hospital employee's look-ups in a patient's record ruled unlawful

A hospital employee opened an adult patient's health record twice with no work reason. The data protection authority held the employee personally responsible and ruled the look-ups unlawful.

From an Icelandic source; summary ours.

Breach A regulator decided Case ISL-S003

· Persónuvernd (Icelandic Data Protection Authority), on Reykjavík District Court case E-2571/2024 · archived copy

Court upholds fine over patient portal flaw that exposed other people's health files

A district court confirmed the data protection authority's finding that the national patient portal had a serious security weakness letting users open others' health files and messages. It cut the fine on the Directorate of Health to ISK 8 million.

Breach A court decided Case ISL-S004

· DV

Patient alleges doctors falsified record entries as complaint waits over three years

A patient told the parliamentary ombudsman that two doctors entered false information in their health record and that access requests were mishandled. A complaint to the Directorate of Health had been pending for more than three years.

From an Icelandic source; summary ours.

Record wrong Alleged, not decided Case ISL-S005

Ireland 5 cases

· Data Protection Commission (Annual Report 2025 case studies)

Patient's request to correct GP record went unanswered until the regulator asked

A patient asked a former GP surgery to correct entries they believed were wrong and heard nothing. After the regulator stepped in, the surgery apologised, kept the entries as clinical opinion, and offered to add the patient's disagreement.

Delay or cost A regulator decided Case IRL-S002

· Data Protection Commission (Annual Report 2025 case studies)

GP surgery emailed a patient's details unencrypted to the wrong person

A small GP surgery recorded a mistyped email address without checking it, then sent the patient's personal data, unencrypted, from a free email account to a stranger. After the regulator engaged, it moved to secure email and a patient portal.

Breach A regulator decided Case IRL-S003

· Data Protection Commission (Annual Report 2024 case studies) · archived copy

Hospital released a patient's records only after the regulator stepped in

A patient asked a public hospital for all the personal data it held. More than a month later there was still no answer, though the matter was urgent. The records were provided only after the regulator contacted the hospital group.

Delay or cost A regulator decided Case IRL-S004

· Data Protection Commission (Annual Report 2024 case studies) · archived copy

Medical facility sent a worker's full consultation notes to their employer

A worker was sent by their employer to a medical facility. The facility gave the employer, including the HR department, full consultation notes with past medical history, assuming consent. The regulator found the disclosure unlawful.

Sold or shared A regulator decided Case IRL-S005

Italy 5 cases

· Garante per la protezione dei dati personali · archived copy

Private clinic warned after a patient's full medical file was lost in archiving

A clinic could not produce a patient's medical file when investigators asked for it; the archive company said it never received the file. The regulator found the clinic failed to report the loss in time and issued a warning.

From an Italian source; summary ours.

Other A regulator decided Case ITA-S003

· Garante per la protezione dei dati personali · archived copy

Hospital warned after hiding a report in a patient's e-record changed its date

A patient said a hospital put a report in her electronic health record without telling her. When she asked for it to be hidden, the system created a replacement dated the day of the change. The regulator issued a warning.

From an Italian source; summary ours.

Record wrong A regulator decided Case ITA-S004

· Il Post

Prescriptions of about 90,000 Lombardy patients offered for sale after software breach

Data stolen in March from the company running a portal family doctors use to send prescriptions went on sale online: prescriptions, sick notes, exemption certificates, emails, phones and addresses. The company reported it to police and warned patients of phishing.

From an Italian source; summary ours.

Breach The organization admitted the problem Case ITA-S005

Latvia 5 cases

· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy

Manager reprimanded for checking an employee's sick-leave record in the national health system

A health worker who supervised a colleague opened the colleague's national health record to check whether sick leave was open. The person had restricted access to their health data. The regulator still found the lookup unlawful and issued a reprimand.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S001

· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy

Health worker fined for reading a family member's national health record

A health worker used work access to read an adult family member's national health record for personal reasons. The person said the information reached a third party. The regulator found no lawful basis and fined the worker 250 euros.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S002

· Datu valsts inspekcija (Data State Inspectorate of Latvia)

Hospital reprimanded after a software supplier's breach exposed patient and staff data

Attackers reached a municipal system the hospital used, taking names, personal codes and addresses of its staff and clients. The regulator found the hospital had not supervised the supplier or reported on time, and reprimanded it. The hospital appealed.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S003

· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy

Regulator rejects mistyped-code excuse after a person's health record was opened

A person complained that staff at a family practice they did not use had opened their record and prescriptions. The practice blamed a mistyped personal code. The regulator found the lookup unrelated to care and issued a reprimand.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S004

Lithuania 5 cases

· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)

Regulator reprimands sanatorium for opening a patient's unrelated national e-health documents

A patient saw in the national e-health log that a sanatorium's staff had opened a referral written for a different specialist. The regulator found no lawful basis for viewing it and reprimanded the sanatorium.

From a Lithuanian source; summary ours.

Breach A regulator decided Case LTU-S001

· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)

Private clinic group fined 450,000 euros after two breaches of patient records

A leaked staff login let an outsider open 63 patients' files, and a later ransomware attack hit systems holding records of about 383,000 patients. The regulator found security was inadequate and fined the company 450,000 euros.

From a Lithuanian source; summary ours.

Breach A regulator decided Case LTU-S002

· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)

Doctor fined for opening 1,231 patients' files and contacting them without a lawful basis

While on sick leave and about to leave a public primary care centre, a doctor viewed 1,231 patients' files in its records system and used their contacts to email and text them. The regulator fined the doctor 1,153 euros.

From a Lithuanian source; summary ours.

Sold or shared A regulator decided Case LTU-S003

· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)

Nurse logged a visit that never happened in a patient's national e-health record

While handling a records transfer, a nurse at a health centre registered a visit the patient never made, then deleted it. The regulator accepted the centre's fixes and rejected the complaint as posing no real risk.

From a Lithuanian source; summary ours.

Record wrong A regulator decided Case LTU-S004

· Respublika.lt (Vakaro žinios)

Clinic's system error sent health check invitations to women registered with other providers

Women received text invitations from a clinic they had never used. The clinic blamed a backend fault in an information system shared with other providers, could not say how many people were reached, and said no data left the system.

From a Lithuanian source; summary ours.

Record wrong The organization admitted the problem Case LTU-S005

Luxembourg 1 case

· Le Quotidien

Cyberattack on an IT firm serving doctors hit 40 medical practices

An IT company serving medical practices said a cyberattack affected 40 practices. It filed a police complaint, notified the data protection authority and said experts found no data leak. Services were later restored.

From a French source; summary ours.

Breach The organization admitted the problem Case LUX-S001

Malta 3 cases

· Newsbook

Court protects patient's complaint that a former doctor kept reading her records

A patient complained to the data protection regulator that a doctor kept accessing her medical records after she left his care. He sued her for libel. A court dismissed the suit, ruling her complaints were privileged.

From a Maltese source; summary ours.

Breach Alleged, not decided Case MLT-S003

Moldova 2 cases

· NewsMaker

Regulator finds private laboratory left patients' test results open on its website

A patient found that other people's test results on a large private laboratory's website could be opened by changing digits in a link. The data protection regulator found the laboratory failed to secure them and opened an administrative case.

From a Russian source; summary ours.

Breach A regulator decided Case MDA-S001

· Moldova 1 (Teleradio-Moldova) · archived copy

National health insurer confirms cyberattack that may have taken patient data

The national health insurer said attackers hit one of its information systems and technical checks pointed to a possible data exfiltration. Its director later said no leak had yet appeared online and the investigation was continuing.

From a Romanian source; summary ours.

Breach The organization admitted the problem Case MDA-S002

Monaco 1 case

Montenegro 5 cases

· Portal 24kroz7 (from Dan) · archived copy

National health record system down for days, patients unable to view results online

Patients reported that the national health information system and the eHealth portal were unavailable for several days, so results could not be checked online and prescriptions were issued on paper. The ministry confirmed temporary technical problems.

From a Serbian source; summary ours.

Delay or cost The organization admitted the problem Case MNE-S003

· Standard (from Pobjeda)

Patient says a third party learned details of her treatment from a clinic

A patient complained that an outsider obtained exact details of her care from a public health centre. The data protection agency could not confirm a leak because staff denied it; she received no sign of an internal inquiry.

From a Serbian source; summary ours.

Breach Alleged, not decided Case MNE-S004

Netherlands 6 cases

· Regionaal Tuchtcollege voor de Gezondheidszorg Amsterdam

Nurse reprimanded for repeatedly opening patient files with no care reason

A hospital's log checks showed a nurse had opened the electronic files of several patients he was not treating, more than once and over a long period. He admitted it, citing curiosity and boredom. The tribunal reprimanded him.

From a Dutch source; summary ours.

Breach A court decided Case NLD-S001

· Cybernews

Software supplier admits hackers stole patient records from several Dutch care providers

A maker of electronic patient record software confirmed that ransomware attackers stole patients' personal data, including medical records, from several Dutch healthcare institutions. It first said theft was unlikely. Sixty-six institutions reported a breach to the data protection authority.

Breach The organization admitted the problem Case NLD-S006

· NOS · archived copy

Hackers took screening results and addresses of 485,000 women from a lab

A lab running part of a national screening programme confirmed it was hacked. Test results, names, addresses, provider names and GP referrals of about 485,000 women, going back years, were stolen. The screening organisation said several years were involved.

From a Dutch source; summary ours.

Breach The organization admitted the problem Case NLD-S004

· ICT&health · archived copy

One in ten hospital patients hit a near miss because records were missing

A patient survey found more than one in ten people treated in hospital in 2024 experienced something going, or nearly going, wrong because a provider lacked their medical information. Reported harms included repeat scans and medication errors.

From a Dutch source; summary ours.

Lost between providers The person's own account Case NLD-S005

North Macedonia 3 cases

· Агенција за заштита на личните податоци (AZLP), North Macedonia · archived copy

Hospital fined after another person's health details were put in a patient's record

A referral was issued in a patient's name on a day she received no care, carrying someone else's health data. Further referrals and reports followed. The regulator fined the hospital, its director and the doctor; a court upheld it.

From a Macedonian source; summary ours.

Record wrong A regulator decided Case MKD-S001

· Агенција за заштита на личните податоци (AZLP), Annual Report 2025 · archived copy

Regulator finds public health body unprepared when ransomware locked patient data

A ransomware attack encrypted personal data held by a public health institution. On inspection the data protection regulator found the institution lacked proper technical and organisational safeguards and was poorly prepared to handle security incidents.

From a Macedonian source; summary ours.

Breach A regulator decided Case MKD-S003

· Призма (BIRN North Macedonia) · archived copy

Patient refused care after a clinician read their electronic health record

A patient seeking urgent treatment saw a clinician who looked in the national electronic record, learned of a sensitive entry and refused even a basic exam. The patient has sued for discrimination; advocates say any doctor can see everything.

From a Macedonian source; summary ours.

Sold or shared Alleged, not decided Case MKD-S002

Norway 5 cases

· Dagens Medisin (NTB)

Regulator finds significant privacy failings in a regional patient record system

After complaints and breach reports, the data protection authority inspected the record system used by hospitals and municipalities in central Norway. It found significant deficiencies, privacy breaches and unclear responsibilities, and gave notice of a correction order.

From a Norwegian source; summary ours.

Other A regulator decided Case NOR-S006

· NRK · archived copy

Municipal employee read patient records without reason for about 15 years

A random audit found an employee had looked into municipal care records without a work reason for around 15 years, affecting about 2,100 residents. The municipality reported it to police and said it saw no sign of onward sharing.

From a Norwegian source; summary ours.

Breach The organization admitted the problem Case NOR-S004

· VG · archived copy

System change missed messages from outside hospitals in thousands of patient cases

A record-system change made in 2023 failed to flag certain messages about discharge reports from other hospitals and specialists. Hospitals identified 3,445 cases needing review. The hospital said an early check found some needed follow-up.

From a Norwegian source; summary ours.

Lost between providers The organization admitted the problem Case NOR-S003

Poland 5 cases

· Rzecznik Praw Pacjenta (Patient Rights Ombudsman)

Court backs ombudsman: closed clinic's records must still be released to patients

After a medical practice closed, the former partner holding its records stopped releasing them to patients during a dispute with the other partner. The ombudsman ordered the practice to stop, and an administrative court rejected the appeal.

From a Polish source; summary ours.

Lost between providers A regulator decided Case POL-S001

· Urząd Ochrony Danych Osobowych (UODO)

Doctor reprimanded for leaving patient cards readable in a parked car

A patient saw patient record cards in a clear box on the front seat of a doctor's parked car, with one card's name, address, birth date and ID number readable. The regulator reprimanded the doctor and ordered the patient notified.

From a Polish source; summary ours.

Breach A regulator decided Case POL-S002

· Urząd Ochrony Danych Osobowych (UODO)

Hospital fined after a patient was handed another person's medical records

A patient received someone else's medical records, including name, birth date, national ID number and health data. The hospital did not report the breach or tell the affected person in time. The regulator fined it 29,648 zloty.

From a Polish source; summary ours.

Breach A regulator decided Case POL-S003

· Wprost

Clinic software flaw exposed patient ID numbers and hospital discharge papers

Attackers used a flaw in practice software used by hundreds of clinics to take names, national ID numbers, contacts and discharge documents. It went unnoticed for over two weeks. The vendor said it fixed the flaw and forced password changes.

From a Polish source; summary ours.

Breach The organization admitted the problem Case POL-S004

· CyberDefence24

National patient portal flaw let a user open other people's medical documents

A user found that changing a web address in the national patient account showed other patients' documents, with names, national ID numbers, ID card numbers and health data. The ministry confirmed the flaw but would not name the facility.

From a Polish source; summary ours.

Breach The organization admitted the problem Case POL-S005

Portugal 5 cases

· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 392/2026

Hospital admitted staff outside the care team opened a patient's record

A family member with power of attorney obtained the record's access log and found entries by staff outside the care team. The hospital admitted improper access but withheld names; the commission said the names must be given.

From a Portuguese source; summary ours.

Breach A regulator decided Case PRT-S001

· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 406/2026

Hospital demanded an ID card copy before releasing a patient's records to their lawyer

A patient's lawyer asked for certified copies of the full record with a signed special power of attorney. The hospital insisted on a copy of the patient's ID card and ignored the commission; it ruled the demand unjustified.

From a Portuguese source; summary ours.

Access refused A regulator decided Case PRT-S002

· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 48/2026

Patient says hospital resent the same report with only a new date

A patient in the Algarve asked for a clinical report needed for care abroad. The patient says the hospital then resent an earlier report with only the date changed; the commission told it to check and supply what was missing.

From a Portuguese source; summary ours.

Record wrong A regulator decided Case PRT-S003

· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 481/2025

Hospital ignored repeated requests for a patient's own records and the regulator

A patient asked a public hospital group several times for her own clinical records without success. The hospital did not answer the commission either; it ruled the records must be released, or their absence explained.

From a Portuguese source; summary ours.

Access refused A regulator decided Case PRT-S004

· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 437/2025

Part of a patient's file stayed missing despite repeated requests

A patient in Madeira received some records but, after repeated requests, a key part of the file was still missing. The health service did not reply to the commission, which ruled it must provide the records or justify refusal.

From a Portuguese source; summary ours.

Delay or cost A regulator decided Case PRT-S005

Romania 5 cases

· ANSPDCP (National Supervisory Authority for Personal Data Processing)

Regulator fines dental clinic after ex-employee took patient files to a rival

A former employee copied every patient's contact details and medical file and used them to invite patients to a competing clinic. The clinic then failed to answer the regulator, which fined it.

From a Romanian source; summary ours.

Sold or shared A regulator decided Case ROU-S001

· ANSPDCP (National Supervisory Authority for Personal Data Processing)

Clinic fined for ignoring a patient's two requests for their own medical file

A patient asked a clinic twice for their medical data and file documents and got no answer. The regulator found no evidence of any reply, fined the clinic and ordered full responses and staff training.

From a Romanian source; summary ours.

Access refused A regulator decided Case ROU-S002

· ANSPDCP (National Supervisory Authority for Personal Data Processing)

Clinic emailed one patient's test results to another patient, regulator finds

A clinic sent a patient's identity number, contact details and test results to another patient by unsecured email, and sent that patient's data back the other way. It told neither patient nor the regulator, which fined it.

From a Romanian source; summary ours.

Breach A regulator decided Case ROU-S003

· DeFapt.ro

Weeks after launch, patients still cannot open their online medical record

Patients trying to use the new national health record portal report waiting about two weeks for identity validation. Those who get in often see only a few prescriptions, not their full medical history.

From a Romanian source; summary ours.

Delay or cost Alleged, not decided Case ROU-S005

· Stiripesurse.ro

Discharge papers listed treatment sessions that never happened, insurer says

A patient complained that a private clinic kept their health insurance card. When it was returned, the discharge papers recorded treatment sessions the national insurer says were fictitious. The insurer applied a contractual penalty to the clinic.

From a Romanian source; summary ours.

Record wrong Alleged, not decided Case ROU-S004

Russia 5 cases

· Медвестник

Inspection finds ambulance service head passed patients' data to outside parties

An unplanned inspection by the Vologda regional health ministry found that the head of an ambulance service had passed data on patients it carried to third parties. He was dismissed and the material was sent to oversight bodies.

From a Russian source; summary ours.

Sold or shared A regulator decided Case RUS-S002

· РАПСИ

Court rules a patient cannot claim damages for false entries in his record

A man in the Astrakhan region found his record held a relative's history, entered when the relative was treated under his documents. Another hospital refused him care. The cassation court overturned his damages award, finding the error his own.

From a Russian source; summary ours.

Record wrong A regulator decided Case RUS-S003

· КонсультантПлюс

Court upholds damages after a clinic lost a patient's record during a merger

In a review of court practice, a clinic could not produce a patient's record for expert review because it was not transferred when two clinics merged. Courts held the successor clinic responsible for keeping it and ordered compensation.

From a Russian source; summary ours.

Lost between providers A regulator decided Case RUS-S004

· Коммерсантъ

Clinic network confirms hacker attack disrupted services; says no leak confirmed

Hackers broke into a private clinic network owned by an insurer, the company confirmed, alongside attacks on two pharmacy chains. Services were disrupted; the clinic said patient data leakage had not been confirmed.

From a Russian source; summary ours.

Breach The organization admitted the problem Case RUS-S005

San Marino 1 case

· San Marino RTV

Lab results stopped reaching patients' online health records for several days

The state health service said a technical fault outside its control blocked lab results from loading into the electronic health record for days. It mailed paper copies meanwhile, apologised, and offered help to anyone still missing results.

From an Italian source; summary ours.

Delay or cost The organization admitted the problem Case SMR-S001

Serbia 2 cases

· Danas

Thousands of patients' medical reports from a private clinic appear on the dark web

Records of about 6,500 patients of a private clinic, with names, addresses, phone numbers and doctors' reports, were posted online. The data protection commissioner opened an inspection and said the clinic had not yet reported the breach.

From a Serbian source; summary ours.

Breach Alleged, not decided Case SRB-S001

Slovakia 3 cases

· Bratislavak.sk

Cyberattack tried to take patient data from the main state health insurer

The government said attackers targeted the state health insurer seeking patients' personal and treatment data. The health minister said the attack was repelled, and the insurer stated policyholders' data were safe and had not leaked.

From a Slovak source; summary ours.

Breach The organization admitted the problem Case SVK-S003

· Pravda

Dentists say national eHealth record lacks dental charts and images

The dentists' chamber says dental charts and image files do not reach the national electronic record, so other doctors cannot see them. It warns patients may get duplicate prescriptions or repeat imaging as a result.

From a Slovak source; summary ours.

Lost between providers Alleged, not decided Case SVK-S002

· STVR Správy (Slovak public broadcaster)

Patient waits over six months as former doctor holds records after a switch

A patient who changed general practitioner says the former doctor did not pass his records to the new one for over six months. Other former patients report the same, and a regional complaint is under review.

From a Slovak source; summary ours.

Lost between providers Alleged, not decided Case SVK-S001

Slovenia 5 cases

· N1 Slovenija

Hospital confirms employee shared photos of patients and a document with personal data

A hospital employee photographed patients and a document holding sensitive personal data and shared the images outside the hospital. The hospital confirmed it, disciplined the worker and reported the case to the data protection authority and police.

From a Slovenian source; summary ours.

Breach The organization admitted the problem Case SVN-S001

· Žurnal24

Clinic confirms a nurse repeatedly opened a former patient's record without authorisation

A former patient complained that a staff member had viewed her health record while she was not in care there. The clinic confirmed repeated unauthorised access and misuse of login details, and notified police and the data protection authority.

From a Slovenian source; summary ours.

Breach The organization admitted the problem Case SVN-S002

· Svet24

Patient handed another person's test result by mistake

A patient received a test report carrying another person's name and findings, and only learned of the mistake when his doctor pointed it out. The Ministry of Health called this kind of mix-up a serious safety incident.

From a Slovenian source; summary ours.

Record wrong Alleged, not decided Case SVN-S005

· Necenzurirano.si

Patient receives two wrong scan reports, one apparently belonging to someone else

A patient says his first imaging report described the wrong part of the body and a corrected report mentioned a procedure that was never done, suggesting a mix-up with another patient. He says staff told him mistakes happen.

From a Slovenian source; summary ours.

Record wrong Alleged, not decided Case SVN-S004

· RTV Slovenija

Patient test results and operation lists reported found in the rubbish

A TV programme received a bag of patients' results, operation lists and doctors' notes said to have been thrown out by a hospital. The hospital disputed where the bag came from; the data protection authority opened an inspection.

From a Slovenian source; summary ours.

Breach Alleged, not decided Case SVN-S003

Spain 5 cases

· Agencia Española de Protección de Datos (AEPD), PS-00560-2025 (EXP202503617) · archived copy

Clinic charged a patient 30 euros for a first copy of her record

After leaving her private insurer, a patient had to request her record in person and pay 30 euros in cash for a one-page copy. The regulator found the charge unlawful; the clinic accepted responsibility and paid a reduced fine.

From a Spanish source; summary ours.

Delay or cost A regulator decided Case ESP-S001

· Síndic de Greuges de la Comunitat Valenciana (regional ombudsman), complaint 2403790

Specialist could not see a report held by another public hospital

After a long wait for an appointment, a patient was told the specialist could not see a report held at another public hospital and was asked to fetch it herself. The ombudsman recommended records be reachable from every public centre.

From a Spanish source; summary ours.

Lost between providers A regulator decided Case ESP-S003

Sweden 5 cases

· SVT Nyheter

Nurse convicted for years of unauthorised lookups in patients' records

A district court convicted a former nurse of data intrusion for unauthorised record lookups over several years, ordering a conditional sentence and 115,000 kronor in damages. Nineteen cases were tried; about 60 people had reported her to police.

From a Swedish source; summary ours.

Breach A regulator decided Case SWE-S007

· Skillingaryd.nu

Another patient's health declaration was filed in the wrong patient's record

A health declaration belonging to one patient was placed in another patient's record ahead of planned care. The error was found later. The region reported it under the serious-incident law, saying the wrong information could have affected safety.

From a Swedish source; summary ours.

Record wrong The organization admitted the problem Case SWE-S005

· Vårdfokus

Region's own review recommends scrapping its troubled patient record system

A region's 90-page internal report found unclear saving of notes, wrong sample labels, medication lists that could not be printed and prescriptions failing to send. The region had filed ten serious-incident reports and the review recommended dropping the system.

From a Swedish source; summary ours.

Other The organization admitted the problem Case SWE-S004

· Läkartidningen

Patient identity numbers, some linked to diagnosis codes, offered for sale after hack

A ransomware attack hit a private hospital's administrative systems. The clinical record system was not affected, but personal identity numbers, in some cases linked to diagnosis codes, were stolen and put up for sale. The hospital refused to pay.

From a Swedish source; summary ours.

Breach The organization admitted the problem Case SWE-S003

· SVT Nyheter

Region reports new record system to regulator after patient notes went missing

Within days of a large region switching record systems, staff reported record information that was missing or disappeared, plus failures registering and finding patients. The region reported the system to the medical products regulator and paused it.

From a Swedish source; summary ours.

Record wrong The organization admitted the problem Case SWE-S002

Switzerland 4 cases

· Swiss Federal Supreme Court (Bundesgericht), 6B_310/2025

Practitioner rebuilt a patient file after the fact, leaving out treatments; conviction upheld

Patients asked a practitioner for their records and did not get them. Before police questioning he created a new electronic file showing one treatment where the original showed three. The court upheld his forgery conviction.

From a German source; summary ours.

Record wrong A court decided Case CHE-S001

· Swiss Federal Supreme Court (Bundesgericht), 2C_567/2024 · archived copy

Family refused a deceased relative's hospital record; top court upholds secrecy after death

After a patient died in hospital, his relatives sought access to his record. Cantonal authorities refused to release the doctor from secrecy, and the federal court agreed, saying confidentiality outlasts death and applies to relatives too.

From a German source; summary ours.

Access refused A court decided Case CHE-S002

Turkey 4 cases

· Bizim Sakarya

Ministry inspectors penalise hospital staff who sold patient details to claims firms

Staff at a public hospital copied patients' identity and contact details from the hospital information system and passed them to unlicensed insurance claims firms for commission. Health Ministry inspectors dismissed staff and suspended a doctor; a criminal investigation continues.

From a Turkish source; summary ours.

Sold or shared A regulator decided Case TUR-S001

· T24

Ransomware attack on a private hospital exposes highly sensitive patient data

Attackers encrypted servers at a private hospital. The breach notice published by the data protection authority lists patients, staff and visitors among those affected, with data including sexual life and biometric details. The number affected was not yet known.

From a Turkish source; summary ours.

Breach The organization admitted the problem Case TUR-S002

· Pamukkale Haber

Records of about 20,000 private hospital patients reportedly posted for free download

A user claiming to hold a private hospital's database reportedly posted patients' identity numbers, addresses, diagnoses, prescriptions and insurance details online. The leak was unconfirmed and neither the hospital nor authorities had commented when reported.

From a Turkish source; summary ours.

Breach Alleged, not decided Case TUR-S003

Ukraine 5 cases

· Sudovo-yurydychna hazeta (sud.ua)

Court voids military fitness ruling after commission could not produce examination records

A man said he was never examined, yet a military medical commission certified him fit for service. Asked by the court for the examination file and doctors' findings, the commission produced only the certificate, so the court annulled it.

From a Ukrainian source; summary ours.

Record wrong A regulator decided Case UKR-S001

· Уповноважений Верховної Ради України з прав людини (Ukrainian Parliament Commissioner for Human Rights)

Man says health facility withheld some of late mother's records until ombudsman intervened

A man asked a health facility for copies of medical records about his mother's death and says he received only some. After the human rights ombudsman wrote to the facility, it sent the requested documents electronically.

From a Ukrainian source; summary ours.

Access refused Alleged, not decided Case UKR-S005

· KP.UA

Women found clinic visits they never made written into their electronic records

Prosecutors named a doctor as a suspect for entering at least 22 false appointment records over two years for women who had never met him. The women discovered the entries themselves and went to police.

From a Ukrainian source; summary ours.

Record wrong Alleged, not decided Case UKR-S004

United Kingdom 7 cases

· The Ferret · archived copy

Scottish health boards recorded over 5,000 patient data breaches in four years

Freedom of information requests found Scotland's health boards logged more than 5,000 data breaches over four years, including staff sharing confidential patient information and records wrongly accessed. At least 182 staff were disciplined and police were informed six times.

Breach The organization admitted the problem Case GBR-S007

Middle East: 25 cases from 13 countries and territories

Bahrain 2 cases

Egypt 3 cases

· Darb · archived copy

Lawmaker raises claims that some medical labs misused patients' data

In a formal request to the health minister, a member of parliament cited press reports that some laboratories had used patients' data unlawfully, and asked for regular oversight to stop misuse of patient data. No finding was reported.

From an Arabic source; summary ours.

Other Alleged, not decided Case EGY-S002

Iran 4 cases

· Khabar Online · archived copy

Security council sought medical records of people hurt in protests, lawmaker says

A member of parliament's health committee confirmed a security council letter asking medical universities for patients' records after the January protests. He said the health ministry objected in confidential correspondence, citing patient confidentiality.

From a Persian source; summary ours.

Sold or shared Alleged, not decided Case IRN-S002

· Radio Zamaneh

Reports say security forces searched hospital files to identify treated protesters

Reports cited by the outlet say security officers checked hospital records of discharged patients and pressed medical staff to report certain patients, and many people avoided hospitals for fear of arrest.

From a Persian source; summary ours.

Sold or shared Alleged, not decided Case IRN-S003

Iraq 1 case

Israel 3 cases

· Calcalist (reporting a Privacy Protection Authority decision)

Health fund fined for slow reporting of a fault exposing members' medical files

A member reported he could open a relative's medical file because of a system fault. The regulator found the fund knew in November 2025 but reported only in January, and fined it 256,000 shekels. The fund plans to appeal.

From a Hebrew source; summary ours.

Breach A regulator decided Case ISR-S001

· Channel 14 (C14)

Hackers claim they published thousands of patient documents taken from a health fund

A hacker group claimed to have stolen and posted documents of more than 10,000 patients, including referrals and sick-leave notes. The fund said it was checking the claim with national cyber authorities and had reported to the privacy regulator.

From a Hebrew source; summary ours.

Breach Alleged, not decided Case ISR-S003

Jordan 1 case

Kuwait 2 cases

· Arab Times (Kuwait), citing Al-Seyassah · archived copy

Appeals court fines a doctor for posting a patient's photo without consent

A doctor published a patient's photograph, taken in connection with her care, on social media and advertising platforms without her consent. The Court of Appeals found this disclosed confidential medical information and imposed a fine.

Sold or shared A regulator decided Case KWT-S001

· Al-Jarida

Top court rules on a doctor publishing a patient's photos in a hospital magazine

A patient sought damages after a doctor published before-and-after photos in a hospital magazine. The appeal court found a confidentiality breach; the Court of Cassation held that patient consent, including implied consent, can lift the duty of secrecy.

From an Arabic source; summary ours.

Sold or shared A regulator decided Case KWT-S002

Lebanon 1 case

Palestine 1 case

· Al-Quds Al-Arabi

Gaza officials say over 70% of three hospitals' medical archives were damaged or lost

Gaza's director general of hospitals said over 70% of the medical archive at three hospitals was damaged or lost in the war. A ministry spokesman said staff cannot trace thousands of injured people's medical histories without the records.

From an Arabic source; summary ours.

Other The organization admitted the problem Case PSE-S001

Qatar 1 case

· Al-Sharq

Patients in Qatar pay and wait again for the same medical report

Patients told the newspaper that government offices reject medical reports older than six months, so they must request new ones, wait about 14 working days and pay 50 riyals each time, though nothing has changed.

From an Arabic source; summary ours.

Delay or cost The person's own account Case QAT-S001

Saudi Arabia 2 cases

· Al Watan (Saudi Arabia)

Ministry penalised practitioners who filmed patients during care and posted the clips

The paper reported cases documented by the health ministry in which practitioners photographed patients during care and published the images online. In one case the ministry cancelled a licence and imposed a fine.

From an Arabic source; summary ours.

Breach A regulator decided Case SAU-S001

· Al Watan

Patients say hospital call centres abroad asked for their full personal details

Callers told the paper that hospital booking lines, staffed from outside the kingdom, asked for ID numbers, birth dates and full patient details before sending them to an app. Security specialists warned of leak and misuse risks.

From an Arabic source; summary ours.

Sold or shared Alleged, not decided Case SAU-S003

United Arab Emirates 2 cases

· Emarat Al Youm · archived copy

Regulator shuts five health facilities after finding manipulated medical data

The emirate's health regulator closed five facilities and suspended staff pending referral to prosecutors. Inspections found sick notes issued without examining patients and manipulation of medical data, among other licensing violations.

From an Arabic source; summary ours.

Record wrong A regulator decided Case ARE-S003

Yemen 2 cases

· Al-Ain News

Report says Houthi security units collect daily patient data from hospitals

Security sources told the outlet that hospitals and clinics in Houthi-held areas were linked to a new security unit and pressed to hand over daily details of patients and cases, building a health database on residents.

From an Arabic source; summary ours.

Sold or shared Alleged, not decided Case YEM-S001

· Crater Sky, via Yemen Vibe

Faulty hospital lab machine gave a patient a dangerously wrong test result

A relative says a hospital lab recorded a test value far outside the normal range. A doctor doubted it and ordered a retest elsewhere, which came back normal, pointing to a broken machine.

From an Arabic source; summary ours.

Record wrong Alleged, not decided Case YEM-S002

Oceania: 18 cases from 6 countries and territories

Australia 5 cases

Fiji 1 case

Micronesia 1 case

New Zealand 5 cases

· Stuff

Portal and Health NZ ordered to fix security after 99,416 patients' data exposed

After a cyberattack exposed health documents belonging to 99,416 people, a review found gaps in protection, weak oversight of tech suppliers and late notice to those affected. The portal operator and Health NZ were ordered to strengthen safeguards.

Breach A regulator decided Case NZL-S002

· RNZ

Health worker used a colleague's login to open two people's records

An audit two patients requested showed a health worker they knew had opened both their medical records, over a personal matter, using a colleague's login. She lost her job, and a court found her guilty.

Breach A regulator decided Case NZL-S005

· RNZ

Health NZ says two people can be wrongly linked to one patient number

Health NZ acknowledged that two people with near-identical details can be linked to one National Health Index number, and that some may have received the wrong care as a result. It said it keeps no central record of such cases.

Record wrong The organization admitted the problem Case NZL-S004

· RNZ

Patients told their health records were stolen could not get answers

After a ransomware attack on a patient portal, a woman told her records were affected could not log in, and the helpline cut her off. Another was told both that her data was and was not affected.

Breach The organization admitted the problem Case NZL-S003

· Office of the Privacy Commissioner (New Zealand), Case Note 329225 [2025] NZ Priv Cmr 1

Agency mailed a person's health information to the wrong house

A government agency sent a person's health information to the wrong address because a staff member recorded the house number incorrectly. The agency at first denied a mistake; after the regulator stepped in, it apologised and agreed to pay compensation.

Breach The organization admitted the problem Case NZL-S001

Palau 2 cases

· Island Times

Cyberattack forced Palau hospital staff to pull patient records by hand

After a ransomware attack the ministry shut its systems, and staff retrieved patient records manually. Services were delayed, and patients were asked to bring medicine containers and written prescriptions for refills.

Delay or cost The organization admitted the problem Case PLW-S002

Tonga 4 cases

· The Record from Recorded Future News

Health ministry says ransomware locked the system holding every patient's history

The health minister said a ransomware attack took down the national health information system, which holds patients' medical records and prescriptions. The ministry told people to bring their prescription cards because doctors could not open records.

Breach The organization admitted the problem Case TON-S001

How we find and check cases

Each case is a published account of a real problem with a person's health record: 101 decisions by regulators and ombudsmen, 15 court judgments, 2 accounts on a parliament's official record and 324 reports by edited news outlets. We never use social media or forums, and never a story about a child.

We search in each country's own languages as well as English. The 442 cases here come from sources in 50 languages; 122 are in English. Only accounts published in the last two years are shown, and the window moves every month.

AI agents find each case, open the page it cites and write the summary in our own words, and every case is checked against our rules by code before it is published. Cases found by the weekly search, which began in October 2026, also pass automated checks: a copy of the page is kept, the passages behind the summary and the date are found word for word in that copy, and a second agent tries to show the case is wrong. A case that fails any check is not published.

We never name or identify the person. We name a hospital, company or other organization only when a regulator or court decided against it, or it admitted the problem. A summary is ours, not anyone's words, and never says a diagnosis, a care date or a place smaller than a region. The cases never change a country's score.

Each case gets one of four labels from what its source shows: a regulator or court decided it, the organization admitted the problem, it is alleged and not decided, or it is the person's own account with nothing else to back it. A decision can reach us through a news report of it, so a case can be decided and still come from the news.

To ask us to take a case down, write to privacy@supertruth.ai. A case taken down leaves this page, the country pages, the feeds, the downloads and the data API. Only its id, the date and a short reason stay on the list below, and the id is never used again.

Cite a case

Every case has an id: the country's three-letter code and a number, like FIN-S001. It never changes and never passes to another case. Cite the case with its id and its address on this page, and link the original account. For example:

Health Record Rights Index, real case ITA-S006 (our summary of a report by PPC Land, October 3, 2026), https://healthrecordrights.com/real-cases/#ITA-S006, cases as of October 7, 2026. Original: https://ppc.land/italy-fines-iqvia-eur7m-over-health-data-of-1m-patients-it-called-anonymous/

The same cases as data: https://healthrecordrights.com/api/v1/cases (one case: https://healthrecordrights.com/api/v1/cases/{id}), the spreadsheet (CSV) and the feed of new cases. They are free to reuse with credit to SuperTruth (CC BY 4.0); the titles and words of the original accounts stay with their owners.

Two rules when you use them: a summary is ours, so never put it in quotation marks or call it anyone's words; and never use these cases to say how common a problem is.

Cases taken down

32 cases were taken down. Each id stays listed here with only the date and a short reason, so a citation that points to it lands on this line. Its headline, summary and link are gone from the site.

CaseWhy it was taken downTaken down
ARE-S001withdrawn
BEL-S003withdrawn
BEL-S005withdrawn
BRA-S001withdrawn
CAN-S005withdrawn
CHN-S002withdrawn
CHN-S003withdrawn
CUB-S002withdrawn
ECU-S002withdrawn
EST-S001withdrawn
GHA-S001withdrawn
HTI-S003withdrawn
IRL-S001withdrawn
ITA-S001withdrawn
JPN-S005withdrawn
KAZ-S001withdrawn
KAZ-S002withdrawn
KEN-S001withdrawn
KEN-S007withdrawn
NOR-S001withdrawn
PAN-S002withdrawn
SAU-S002withdrawn
STP-S001withdrawn
SWE-S006withdrawn
TLS-S002withdrawn
TON-S003withdrawn
URY-S001withdrawn
URY-S003withdrawn
USA-S001withdrawn
UZB-S001withdrawn
UZB-S002withdrawn
UZB-S003withdrawn

Cases as of . Our summaries are free to reuse with credit to SuperTruth (CC BY 4.0).

Built by SuperTruth, which checks whether a record can be trusted before an AI acts on it. About SuperTruth · How we used AI · Follow changes