Hospital cyber attacks and gdpr what can my company learn

Page 1

HOSPITAL CYBER ATTACKS AND GDPR: WHAT CAN MY COMPANY LEARN?

In January this year Norway’s South-East Regional Health Authority admitted a data breach, and it was serious. The Authority is responsible for managing all hospitals in the southeast of Norway. It conceded that the medical records of 2.9 million Norwegians had been potentially exposed to cyber attack. Significantly it took the organisation seven days from the date it became aware of the attack to publicise the breach. This is considerably in excess of the GDPR requirements that: 

Notification of a breach of data must occur within 72 hours of the organisation concerned becoming aware of it; and

Where the breach is going to adversely affect the rights of individuals they must be informed ‘without undue delay’


Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.
Hospital cyber attacks and gdpr what can my company learn by Vicky Carney - Issuu