Real cases

171 published accounts of health record breaches from 87 countries and territories

A breach, as we file it: the record was stolen, leaked, hacked, or read by staff with no part in the person's care.

Published October 2024 to September 2026, found in sources in 39 languages: 171 of all 442 cases. By region, 7 in Africa, 28 in the Americas, 30 in Asia, 86 in Europe, 8 in the Middle East and 12 in Oceania. Of these, a regulator or court decided 61, the organization involved admitted 60 and 50 are allegations not decided. The sources: 35 decisions by regulators and ombudsmen, 4 court judgments and 132 reports by edited news outlets. 24 decisions are known to us from a news report of it. The list last changed on October 7, 2026.

Each case is filed under one kind of problem when it is written, by the rule above; the cases here are the ones filed under it. These cases are not a sample: they show what is published and findable, not how common breaches are.

Each case's id links its line on Real cases, the one address to cite. Every case, every kind of problem, by country: Real cases.

By month and region

all cases that month cases filed as breach a month not yet over every panel on the same scale, 0 to 15 cases a month

Africa 47 cases, 25 countries and territories
15Jan 2025Jan 2026to Oct 3
Americas 89 cases, 29 countries and territories
15Jan 2025Jan 2026to Oct 3
Asia 76 cases, 25 countries and territories
15Jan 2025Jan 2026to Oct 3
Europe 187 cases, 47 countries and territories
15Jan 2025Jan 2026to Oct 3
Middle East 25 cases, 13 countries and territories
15Jan 2025Jan 2026to Oct 3
Oceania 18 cases, 6 countries and territories
15Jan 2025Jan 2026to Oct 3

Each bar counts the cases whose source was published that month, October 2024 to October 2026, by region. Pick a kind of problem to see its share of each bar. Counts show what was published and what our searches found, not how often problems happen. October 2026 runs only to October 3, 2026, the newest source date, so its bars are drawn as outlines. Every case as a spreadsheet (CSV).

See the numbers
Cases filed as breach, by month of the source and by region
MonthAfricaAmericasAsiaEuropeMiddle EastOceaniaAll
October 20241012004
November 20240022004
December 20242103006
January 20250103105
February 20250026008
March 20250124029
April 20250133108
May 20250003003
June 20250221049
July 202502160110
August 20250022015
September 20250105006
October 20250022105
November 20251002014
December 20250104005
January 20260000011
February 20262111117
March 20260012104
April 202614070012
May 202605340012
June 20260314008
July 20260115108
August 20260224109
September 2026024111119
October 2026 (so far)0000000
All7283086812171
Cases filed as breach, by how settled they are and by region
How settledAfricaAmericasAsiaEuropeMiddle EastOceaniaAll
A regulator or court decided256423361
The organization admitted the problem11210311560
Alleged, not decided41114134450
All7283086812171
Cases filed as breach, by kind of source and by region
Kind of sourceAfricaAmericasAsiaEuropeMiddle EastOceaniaAll
Regulator and ombudsman decisions112300135
Court judgments0112004
News reports6262754811132
All7283086812171

The cases, newest first

· N1 Slovenija

Hospital confirms employee shared photos of patients and a document with personal data

A hospital employee photographed patients and a document holding sensitive personal data and shared the images outside the hospital. The hospital confirmed it, disciplined the worker and reported the case to the data protection authority and police.

From a Slovenian source; summary ours.

Breach The organization admitted the problem Case SVN-S001 on Real cases Slovenia: the country page

· Money Today (머니투데이)

Staff at public health agencies looked up personal data for private reasons, files show

Disciplinary files that the public health insurer and claims review agency gave a lawmaker show staff viewing relatives' and an ex-partner's data, querying colleagues, and emailing sensitive screening files home. Penalties ranged from reprimand to dismissal.

From a Korean source; summary ours.

Breach Alleged, not decided Case KOR-S005 on Real cases South Korea: the country page

· Kişisel Verileri Koruma Kurumu (KVKK)

Health services company tells regulator ransomware encrypted its systems; affected people still unknown

A health services company notified the data protection authority that a ransomware attack encrypted its data over two days. It could not yet say which people or data categories were affected. The board ordered the notice published.

From a Turkish source; summary ours.

Breach The organization admitted the problem Case TUR-S004 on Real cases Turkey: the country page

· Génération NT · archived copy

Regulator fines private hospital after attacker reached hundreds of thousands of patient records

France's data regulator fined a private hospital 500,000 euros after an attacker used one compromised account to reach data on 524,867 patients, some including health data. Access needed no multifactor login and suspicious activity went undetected.

From a French source; summary ours.

Breach A regulator decided Case FRA-S007 on Real cases France: the country page

· Infobae · archived copy

Ransomware locked a national hospital's clinical planning records, delaying sessions for 194 patients

Attackers encrypted the system holding a national specialist hospital's clinical plans and images and demanded payment. The hospital's leadership said it refused to negotiate, reported the attack to prosecutors and police, and rescheduled 194 patients.

From a Spanish source; summary ours.

Breach The organization admitted the problem Case GTM-S001 on Real cases Guatemala: the country page

· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)

Regulator reprimands sanatorium for opening a patient's unrelated national e-health documents

A patient saw in the national e-health log that a sanatorium's staff had opened a referral written for a different specialist. The regulator found no lawful basis for viewing it and reprimanded the sanatorium.

From a Lithuanian source; summary ours.

Breach A regulator decided Case LTU-S001 on Real cases Lithuania: the country page

· Insurance Business

Billing software vendor confirms theft of insurance and claims data for 3.8 million people

Hackers copied insurance policy numbers, claims and benefits data, medical record numbers and Social Security numbers from a health billing software vendor. The vendor reported 3.8 million people affected to federal regulators about nine months after discovering the intrusion.

Breach The organization admitted the problem Case USA-S014 on Real cases United States: the country page

· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy

Manager reprimanded for checking an employee's sick-leave record in the national health system

A health worker who supervised a colleague opened the colleague's national health record to check whether sick leave was open. The person had restricted access to their health data. The regulator still found the lookup unlawful and issued a reprimand.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S001 on Real cases Latvia: the country page

· Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 392/2026

Hospital admitted staff outside the care team opened a patient's record

A family member with power of attorney obtained the record's access log and found entries by staff outside the care team. The hospital admitted improper access but withheld names; the commission said the names must be given.

From a Portuguese source; summary ours.

Breach A regulator decided Case PRT-S001 on Real cases Portugal: the country page

· The Ferret · archived copy

Scottish health boards recorded over 5,000 patient data breaches in four years

Freedom of information requests found Scotland's health boards logged more than 5,000 data breaches over four years, including staff sharing confidential patient information and records wrongly accessed. At least 182 staff were disciplined and police were informed six times.

Breach The organization admitted the problem Case GBR-S007 on Real cases United Kingdom: the country page

· CNN Brasil · archived copy

Regulator opens case after attack on health operator affecting 500,000 patients' records

A ransomware attack on an organisation running public health units in several states affected records of about 500,000 patients. The data authority opened a sanction case, citing poor notice to those affected. The operator denies any data leaked.

From a Portuguese source; summary ours.

Breach Alleged, not decided Case BRA-S003 on Real cases Brazil: the country page

· Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)

Private clinic group fined 450,000 euros after two breaches of patient records

A leaked staff login let an outsider open 63 patients' files, and a later ransomware attack hit systems holding records of about 383,000 patients. The regulator found security was inadequate and fined the company 450,000 euros.

From a Lithuanian source; summary ours.

Breach A regulator decided Case LTU-S002 on Real cases Lithuania: the country page

· BBC News · archived copy

Hospital trust in England confirms thousands of patients' test results stolen in supplier hack

An NHS hospital trust confirmed that thousands of patient records, including test results, were stolen from a third-party testing provider's systems. The supplier said the data, possibly including names, NHS numbers and postcodes, was published on the dark web.

Breach The organization admitted the problem Case GBR-S008 on Real cases United Kingdom: the country page

· Hokkaido Cultural Broadcasting (UHB)

Hospital hard drives meant for shredding turned up for sale at online auction

Hard drives two public hospitals sent for destruction were listed on internet auctions, holding names, addresses, clinical notes and nursing records for up to 510,000 people. The disposal firm said destroyed and intact drives were kept in identical containers.

From a Japanese source; summary ours.

Breach The organization admitted the problem Case JPN-S004 on Real cases Japan: the country page

· Jujuygráfico · archived copy

Retirees' insurer posted members' clinical records on its public purchasing site

A fact-checking investigation found at least 40 purchase files on the insurer's public procurement search showing members' clinical histories, test results and ID copies. The insurer called it a serious anomaly, removed the files and opened internal inquiries.

From a Spanish source; summary ours.

Breach The organization admitted the problem Case ARG-S004 on Real cases Argentina: the country page

· Moldova 1 (Teleradio-Moldova) · archived copy

National health insurer confirms cyberattack that may have taken patient data

The national health insurer said attackers hit one of its information systems and technical checks pointed to a possible data exfiltration. Its director later said no leak had yet appeared online and the investigation was continuing.

From a Romanian source; summary ours.

Breach The organization admitted the problem Case MDA-S002 on Real cases Moldova: the country page

· Supreme People's Court of China (typical cases) · archived copy

Hospital booking contractor secretly copied millions of patients' details, court rules

A software firm that ran a hospital's online appointment system copied registration details of about 2.88 million patients into its own database over several years. A court convicted the firm and its managers, with fines and prison terms.

From a Chinese source; summary ours.

Breach A court decided Case CHN-S001 on Real cases China: the country page

· BioBioChile (BBCL Investiga) · archived copy

Lookup website showed patients' diagnoses to anyone who typed in their ID number

For about 48 hours, a people-search website let anyone enter a Chilean ID number and see that person's diagnoses under the national guaranteed-care scheme, alongside address and contact details. Police and the cybersecurity agency are investigating.

From a Spanish source; summary ours.

Breach Alleged, not decided Case CHL-S002 on Real cases Chile: the country page

· Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 13/2026

Public hospital left its surgery waiting list, with patients' phone numbers, open online

A member of the public found, through a search engine, a hospital file listing about 2,820 patients' phone numbers and planned operations, online for months. The hospital reported late, never told patients, and was fined 25,000 euros.

From a Greek source; summary ours.

Breach A regulator decided Case GRC-S001 on Real cases Greece: the country page

· Cybernews

Software supplier admits hackers stole patient records from several Dutch care providers

A maker of electronic patient record software confirmed that ransomware attackers stole patients' personal data, including medical records, from several Dutch healthcare institutions. It first said theft was unlikely. Sixty-six institutions reported a breach to the data protection authority.

Breach The organization admitted the problem Case NLD-S006 on Real cases Netherlands: the country page

· Агенција за заштита на личните податоци (AZLP), Annual Report 2025 · archived copy

Regulator finds public health body unprepared when ransomware locked patient data

A ransomware attack encrypted personal data held by a public health institution. On inspection the data protection regulator found the institution lacked proper technical and organisational safeguards and was poorly prepared to handle security incidents.

From a Macedonian source; summary ours.

Breach A regulator decided Case MKD-S003 on Real cases North Macedonia: the country page

· Le Moniteur des pharmacies · archived copy

Lab network says attackers reached patient analysis reports and social security numbers

A national lab network reported unauthorised access, through a server run by an outside IT supplier, to patient names, emails, encrypted passwords, analysis reports and social security numbers. It was the network's second attack in about a year.

From a French source; summary ours.

Breach The organization admitted the problem Case FRA-S006 on Real cases France: the country page

· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), decision NAIH-273-7/2026

Former family doctor opened an ex-patient's national health record 47 times

A patient checked the access log in the national health record system and found a doctor they had left kept viewing their results and prescriptions for 19 months. The doctor also ignored their access request. The regulator imposed a fine.

From a Hungarian source; summary ours.

Breach A regulator decided Case HUN-S001 on Real cases Hungary: the country page

· franceinfo · archived copy

Doctors' private notes on patients exposed in attack on medical software

Attackers reached files of 1,500 doctors using one practice software. Administrative data on 15 million patients leaked, and the health minister said sensitive doctor annotations on 164,000 patients were exposed. The vendor said structured medical records were intact.

From a French source; summary ours.

Breach The organization admitted the problem Case FRA-S005 on Real cases France: the country page

· Il Post

Prescriptions of about 90,000 Lombardy patients offered for sale after software breach

Data stolen in March from the company running a portal family doctors use to send prescriptions went on sale online: prescriptions, sick notes, exemption certificates, emails, phones and addresses. The company reported it to police and warned patients of phishing.

From an Italian source; summary ours.

Breach The organization admitted the problem Case ITA-S005 on Real cases Italy: the country page

· BioBioChile · archived copy

Consumer agency demands answers after 250 GB of patient records stolen from private clinic

A ransomware group reportedly took about 250 GB from a private clinic, including clinical records, test results and identity card copies. Chile's consumer agency ordered the clinic to report how many patients were affected and how they were told.

From a Spanish source; summary ours.

Breach Alleged, not decided Case CHL-S003 on Real cases Chile: the country page

· Gegevensbeschermingsautoriteit (Belgian Data Protection Authority), Litigation Chamber decision 209/2025 · archived copy

Access list showed a therapist opened a patient's test results without a care reason

A patient asked her hospital group who had opened her electronic record. The list showed a therapist working there had viewed her test results three times. The regulator reprimanded the hospital for weak access controls; an appeal is pending.

From a Dutch source; summary ours.

Breach A regulator decided Case BEL-S001 on Real cases Belgium: the country page

· Sigmalive · archived copy

Specialist hospital confirms hackers stole patient and staff data and threatened publication

The hospital said attackers took personal data of patients and staff from its systems and threatened to publish it in the media and online. It reported the attack to police, the data regulator and the digital security authority.

From a Greek source; summary ours.

Breach The organization admitted the problem Case CYP-S005 on Real cases Cyprus: the country page

· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy

Health worker fined for reading a family member's national health record

A health worker used work access to read an adult family member's national health record for personal reasons. The person said the information reached a third party. The regulator found no lawful basis and fined the worker 250 euros.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S002 on Real cases Latvia: the country page

· China Women's News (via Tencent News) · archived copy

Hospital apps let anyone with a patient's name and ID number download her records

Several large hospitals' online services released test reports and records to anyone with a patient's name and ID number. Someone a woman knew used this for two years to obtain and circulate her records. Some hospitals then added identity checks.

From a Chinese source; summary ours.

Breach The organization admitted the problem Case CHN-S006 on Real cases China: the country page

· Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Ετήσια Έκθεση 2024)

State hospitals fined after ten patients' medical files went missing

The state hospital body reported losing ten patients' medical files and three emergency registration forms. The regulator found no safeguards against loss, fined it 46,500 euros in total and ordered it to tell seven patients.

From a Greek source; summary ours.

Breach A regulator decided Case CYP-S002 on Real cases Cyprus: the country page

· Datu valsts inspekcija (Data State Inspectorate of Latvia)

Hospital reprimanded after a software supplier's breach exposed patient and staff data

Attackers reached a municipal system the hospital used, taking names, personal codes and addresses of its staff and clients. The regulator found the hospital had not supervised the supplier or reported on time, and reprimanded it. The hospital appealed.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S003 on Real cases Latvia: the country page

· Datenschutzbehörde (Austrian Data Protection Authority), penal decision 2025-0.625.944

Doctor opened a person's national e-health record without consent; regulator fined her

A woman found through the ELGA access log that a doctor had opened her stored results and medication data without consent and unconnected to any treatment by that doctor. The regulator found a violation and imposed a 1,000 euro fine.

From a German source; summary ours.

Breach A regulator decided Case AUT-S002 on Real cases Austria: the country page

· NOS · archived copy

Hackers took screening results and addresses of 485,000 women from a lab

A lab running part of a national screening programme confirmed it was hacked. Test results, names, addresses, provider names and GP referrals of about 485,000 women, going back years, were stolen. The screening organisation said several years were involved.

From a Dutch source; summary ours.

Breach The organization admitted the problem Case NLD-S004 on Real cases Netherlands: the country page

· Office of the Personal Data Protection Committee, via Government Public Relations Department

Hospital fined after patient record pages sent for destruction leaked as snack bags

A large private hospital hired a small contractor to destroy patient records but did not oversee the work. Over 1,000 record pages leaked and were reused as snack bags. The regulator fined the hospital and the contractor.

From a Thai source; summary ours.

Breach A regulator decided Case THA-S001 on Real cases Thailand: the country page

· oPojištění.cz (reporting a Supreme Administrative Court ruling of 21 May 2025) · archived copy

Court upholds fine on clinic that failed to report a patient data breach

A cyberattack left a private clinic's patient records unreachable for a week. The clinic, holding data on about 250,000 patients, did not report it in time and could not prove it told patients. The court confirmed a 309,000 crown fine.

From a Czech source; summary ours.

Breach A regulator decided Case CZE-S001 on Real cases Czechia: the country page

· ČT24 (Česká televize) · archived copy

Hospital warns patients a ransomware attack may have exposed their record data

After ransomware shut down its systems, a hospital told patients that personal data linked to their medical records may have been stolen. It could not yet confirm whether or how much was taken, and notified the data protection office.

From a Czech source; summary ours.

Breach The organization admitted the problem Case CZE-S002 on Real cases Czechia: the country page

· Agencija za zaštitu osobnih podataka (AZOP), anonymised decision 567-UP/I-034-01/24-01/31 · archived copy

Hospital worker photographed a patient's test result on screen and it reached the media

An unknown hospital employee photographed a patient's result in the hospital system and it was published by the media. The hospital neither reported the breach nor told the patient until their lawyer wrote. The regulator fined it.

From a Croatian source; summary ours.

Breach A regulator decided Case HRV-S002 on Real cases Croatia: the country page

· Agencija za zaštitu osobnih podataka (AZOP), anonymised decision 567-UP/I-034-01/24-01/34 · archived copy

Ransomware attacker spent a week inside a hospital network and copied data out

After a ransomware attack, the regulator found a hospital's weak technical safeguards let an attacker roam its systems unnoticed for about seven days and copy at least 3 GB out. The hospital was fined 20,000 euros.

From a Croatian source; summary ours.

Breach A regulator decided Case HRV-S003 on Real cases Croatia: the country page

· Office of the Privacy Commissioner (New Zealand), Case Note 329225 [2025] NZ Priv Cmr 1

Agency mailed a person's health information to the wrong house

A government agency sent a person's health information to the wrong address because a staff member recorded the house number incorrectly. The agency at first denied a mistake; after the regulator stepped in, it apologised and agreed to pay compensation.

Breach The organization admitted the problem Case NZL-S001 on Real cases New Zealand: the country page

· Persónuvernd (Icelandic Data Protection Authority), on Reykjavík District Court case E-2571/2024 · archived copy

Court upholds fine over patient portal flaw that exposed other people's health files

A district court confirmed the data protection authority's finding that the national patient portal had a serious security weakness letting users open others' health files and messages. It cut the fine on the Directorate of Health to ISK 8 million.

Breach A court decided Case ISL-S004 on Real cases Iceland: the country page

· Seznam Zprávy · archived copy

Hospital lost control of a computer holding examination images of about 1,900 patients

A clinic computer storing images and data from nearly two thousand examinations disappeared for four days, then reappeared. The hospital's internal review called it a data incident, its director confirmed it, and it was reported to the data protection office.

From a Czech source; summary ours.

Breach The organization admitted the problem Case CZE-S004 on Real cases Czechia: the country page

· Hessian Commissioner for Data Protection and Freedom of Information (HBDI) · archived copy

Practice manager took patient files home where guests could read them

The state regulator reported a practice manager who took patient records home and left them unsecured, where party guests could see them, and who also sent photos of patient files to a partner by messaging app.

From a German source; summary ours.

Breach A regulator decided Case DEU-S002 on Real cases Germany: the country page

· The Paper (澎湃新闻) · archived copy

Shanghai regulator penalises online medical firms after patient data was stolen and left unencrypted

Shanghai's cyberspace regulator penalised several online medical service firms. One had unpatched flaws and suspicious foreign access that led to data theft; another stored over 6.5 million patient records, including conditions and prescriptions, without encryption.

From a Chinese source; summary ours.

Breach A regulator decided Case CHN-S004 on Real cases China: the country page

· Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 11/2025 · archived copy

Private doctor looked up a patient's national health record without permission

A patient asked a private doctor for her full file and complained the doctor had also searched her electronic health record. The regulator found the lookup unlawful, done without her knowledge, and fined the doctor 5,000 euros.

From a Greek source; summary ours.

Breach A regulator decided Case GRC-S002 on Real cases Greece: the country page

· Office of the Saskatchewan Information and Privacy Commissioner (Investigation Report 266-2024, 031-2025) · archived copy

Health worker looked into 70 people's records; patients not properly told

An employee opened the electronic health records of 70 people in Saskatchewan 210 times without a work reason. The commissioner found the health authority did not contain the breach properly or tell those affected enough.

Breach A regulator decided Case CAN-S003 on Real cases Canada: the country page

· National Human Rights Commission of Mongolia, 24th report on human rights · archived copy

Rights commission finds Intermed hospital failed to protect patient data before a cyberattack

After hackers took and posted names, ID and phone numbers of about 200,000 patients, a patient complained. The commission found weak cyber security, no rules for handling personal data and no breach plan, and ordered an audit and fixes.

From a Mongolian source; summary ours.

Breach A regulator decided Case MNG-S001 on Real cases Mongolia: the country page

· Knews (知新聞)

Mackay Memorial Hospital apologises after ransomware attack that may have taken patient data

After a ransomware attack, the hospital issued statements apologising and saying hackers may have stolen data while encrypting its systems. Millions of patient records were reportedly offered for sale; the ministry said the source still needed checking.

From a Chinese source; summary ours.

Breach The organization admitted the problem Case TWN-S001 on Real cases Taiwan: the country page

· Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2024, case NAIH-295/2024

Patient files left in a closed health building after repeated break-ins

A health institution left large volumes of patient records in a closed building that intruders kept entering, scattering files inside. It did not remove them or tell patients for over nine months. The regulator fined it two million forints.

From a Hungarian source; summary ours.

Breach A regulator decided Case HUN-S004 on Real cases Hungary: the country page

· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy

Regulator rejects mistyped-code excuse after a person's health record was opened

A person complained that staff at a family practice they did not use had opened their record and prescriptions. The practice blamed a mistyped personal code. The regulator found the lookup unrelated to care and issued a reprimand.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S004 on Real cases Latvia: the country page

· ANSPDCP (National Supervisory Authority for Personal Data Processing)

Clinic emailed one patient's test results to another patient, regulator finds

A clinic sent a patient's identity number, contact details and test results to another patient by unsecured email, and sent that patient's data back the other way. It told neither patient nor the regulator, which fined it.

From a Romanian source; summary ours.

Breach A regulator decided Case ROU-S003 on Real cases Romania: the country page

· Läkartidningen

Patient identity numbers, some linked to diagnosis codes, offered for sale after hack

A ransomware attack hit a private hospital's administrative systems. The clinical record system was not affected, but personal identity numbers, in some cases linked to diagnosis codes, were stolen and put up for sale. The hospital refused to pay.

From a Swedish source; summary ours.

Breach The organization admitted the problem Case SWE-S003 on Real cases Sweden: the country page

· Salud y Medicina · archived copy

Doctor convicted for opening another person's clinical record three times without a care reason

A primary care doctor used her own login to open a person's clinical record three times, though the person was not her patient. A provincial court gave her a suspended prison term, six years' disqualification and 50,000 euros in damages.

From a Spanish source; summary ours.

Breach A regulator decided Case ESP-S004 on Real cases Spain: the country page

· Tribunal Regional do Trabalho da 4ª Região (Rio Grande do Sul) · archived copy

Nurse technician fired for opening someone's medical record 18 times without a care reason

A hospital nursing technician opened another person's record 18 times, though she was not caring for her, over a personal dispute. A labour court in Rio Grande do Sul upheld her dismissal for cause.

From a Portuguese source; summary ours.

Breach A court decided Case BRA-S006 on Real cases Brazil: the country page

· Gegevensbeschermingsautoriteit (Belgian Data Protection Authority), Litigation Chamber decision 166/2024 · archived copy

Ransomware hit a hospital whose patient record system had weak password protection

An attacker locked a hospital's servers and exported about 5 gigabytes of data. The regulator found security failings, including weak protection of access to the electronic patient record, and fined the hospital 390,000 euros. An appeal court later reduced it.

From a Dutch source; summary ours.

Breach A regulator decided Case BEL-S002 on Real cases Belgium: the country page

· Datu valsts inspekcija (Data State Inspectorate of Latvia) · archived copy

Hospital physician assistant fined for repeatedly viewing three people's health records

Over several years a physician assistant used work logins to the national health system and two hospital systems to view three people's health data for personal reasons. The regulator found no care purpose and fined him 500 euros.

From a Latvian source; summary ours.

Breach A regulator decided Case LVA-S005 on Real cases Latvia: the country page

· Clubic · archived copy

Hospital records of about 750,000 people posted online after stolen login used

A hacker posted a database of about 758,000 people taken from hospital management software, including contact details, treating doctor, prescriptions and death declarations. The software maker said a privileged account at a client hospital was misused.

From a French source; summary ours.

Breach The organization admitted the problem Case FRA-S004 on Real cases France: the country page

· Mass.mn · archived copy

Intermed apologises after hackers took patient data; one patient says nobody called

Hackers demanded $50,000 for data said to include patients' names, ID numbers, phone numbers and medical histories. The hospital publicly apologised for the risk of leaked data. One patient said they reported it to police; the promised call never came.

From a Mongolian source; summary ours.

Breach The organization admitted the problem Case MNG-S003 on Real cases Mongolia: the country page

· Žurnal24

Clinic confirms a nurse repeatedly opened a former patient's record without authorisation

A former patient complained that a staff member had viewed her health record while she was not in care there. The clinic confirmed repeated unauthorised access and misuse of login details, and notified police and the data protection authority.

From a Slovenian source; summary ours.

Breach The organization admitted the problem Case SVN-S002 on Real cases Slovenia: the country page

Cases as of . Our summaries are free to reuse with credit to SuperTruth (CC BY 4.0).

Built by SuperTruth, which checks whether a record can be trusted before an AI acts on it. About SuperTruth · How we used AI · Follow changes