Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
DSGVO Violation: Hospital must pay 105,000 EUR!
Security Awareness

DSGVO Violation: Hospital must pay 105,000 EUR!

GDPR violation example: a hospital paid a 105,000 EUR fine for patient data errors. Reduce your own risk of a similar fine.

Chris Wojzechowski Managing Director
Updated: October 9, 2024 2 min read read
IT-Grundschutz-Praktiker (TÜV) IT Risk Manager (DGI) § 8a BSIG Prüfverfahrenskompetenz Ausbilderprüfung (IHK) T.I.S.P. Board-Mitglied

TL;DR

A hospital in Rhineland-Palatinate was fined 105,000 EUR under GDPR (DSGVO) after a patient mix-up during admission led to a false invoice, revealing structural deficiencies in patient data management. The case coincided with other high-profile German fines: Deutsche Wohnen SE was fined 14.5 million EUR for improper personal data archiving, and 1&1 Telekom GmbH received a 9.95 million EUR fine for insufficient phone authentication. Both contested their fines. The cases signal that GDPR enforcement in Germany is intensifying.

Table of Contents (3 sections)

Since May 2018, the basic data protection regulation has been in force - now one DSGVO infringement after another is gradually being punished. Many of these decisions are intended to send a financial signal. A hospital in Rhineland-Palatinate has accepted the fine of 105,000 EUR.

The special sensitivity in dealing with health data is to be emphasized in this fine notice.

Dieter Kugelmann is the data protection officer of the state of Rhineland-Palatinate. An incident in the hospital, in which a patient mix-up took place during admission, causes the fine to be imposed. After this incident, a false invoice was also issued. What sounds banal, however, reveals structural technical and organisational deficits in patient management.

The latter is currently not taken for granted. The notices issued in the last few weeks are also often contested. The current incidents at 1&1 and the real estate company Deutsche Wohnen SE confirm this.

9.95 and 14.5 million high fines cause a lot of discussion

When the basic data protection regulation came into force in 2018, the EUR 10 million and EUR 20 million fines had ensured, among other things, full exhibition halls. After all, nobody wants a punishment that threatens their very existence. Now that nothing or very little has happened for a long time, things are now happening in quick succession. The discussion focuses primarily on 1&1 Telekom GmbH and the real estate company Deutsche Wohnen SE.

Latter has been fined EUR 14.5 million. This was about personal data in the archive. The telecommunications company was involved in a case in which information was divulged over the telephone. Here the authentication process is criticized. Both companies have not yet recognized the notifications.

It probably won't be the last DSGVO violation.

The handling of personal data can be expensive. Even today, the correct implementation of the DSGVO cannot be seen on numerous websites. The next warnings will certainly not be long in coming.

Next Step

Our certified security experts will advise you on the topics covered in this article — free and without obligation.

Free · 30 minutes · No obligation

Share this article

About the author

Chris Wojzechowski
Chris Wojzechowski

Managing Director

E-Mail

Managing Director of AWARE7 GmbH with many years of expertise in information security, penetration testing and IT risk management. Graduate of the Internet Security master's program at Westfälische Hochschule (if(is), Prof. Norbert Pohlmann). Bestselling author with Wiley-VCH and lecturer at the ASW-Akademie. His assessments of cybersecurity and digital sovereignty have appeared in Welt am Sonntag, WDR, Deutschlandfunk and Handelsblatt, among others.

10 Publikationen
  • Einsatz von elektronischer Verschlüsselung - Hemmnisse für die Wirtschaft (2018)
  • Kompass IT-Verschlüsselung - Orientierungshilfen für KMU (2018)
  • IT Security Day 2025 - Live Hacking: KI in der Cybersicherheit (2025)
  • Live Hacking - Credential Stuffing: Finanzrisiken jenseits Ransomware (2025)
  • Keynote: Live Hacking Show - Ein Blick in die Welt der Cyberkriminalität (2025)
  • Analyse von Angriffsflächen bei Shared-Hosting-Anbietern (2024)
  • Gänsehaut garantiert: Die schaurigsten Funde aus dem Leben eines Pentesters (2022)
  • IT Security Zertifizierungen - CISSP, T.I.S.P. & Co (Live-Webinar) (2023)
  • Sicherheitsforum Online-Banking - Live Hacking (2021)
  • Nipster im Netz und das Ende der Kreidezeit (2017)
IT-Grundschutz-Praktiker (TÜV) IT Risk Manager (DGI) § 8a BSIG Prüfverfahrenskompetenz Ausbilderprüfung (IHK) T.I.S.P. Board-Mitglied
Certified ISO 27001ISO 9001AZAV

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen