Live Archive|Investigative Journalism & Declassified Records
Digital Edition
Unclessify
Unclessify
Hospital Careggi Sanctioned for Cross-Departmental Patient File Access and Flawed Digital Dossier Consent Architecture
garanteprivacy.it

Hospital Careggi Sanctioned for Cross-Departmental Patient File Access and Flawed Digital Dossier Consent Architecture

garanteprivacy.itItalia2026public
#sanita-digitale#privacy#dossier-sanitario#garante-privacy#sicurezza-dati#ospedali

Verified Primary Investigative Source: garanteprivacy.itItalia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Executive Summary and Public Interest

The digitization of regional hospital networks frequently collides with the fundamental legal safeguards governing sensitive medical data. An extensive inspection into the digital infrastructure of one of Italy’s largest clinical facilities has exposed critical structural vulnerabilities in patient consent collection and internal access authorization protocols.

The administrative determination confirms that medical personnel could systematically query cross-departmental patient histories spanning nearly three decades without compartmentalized authorizations or specific, granular consent. This systematic failure directly compromised data protection safeguards for thousands of individuals receiving inpatient and outpatient treatments.

Regulatory Trajectory and the Digital Health Dossier

The Italian legal framework governing digital health records underwent a profound transformation following the direct application of European data protection standards and the subsequent enactment of Legislative Decree no. 101/2018. Prior to this structural reform, healthcare facilities routinely operated under single-consent models for general treatment purposes pursuant to earlier formulations of Article 75 of the national Privacy Code.

National regulatory directives issued in 2015 firmly established that an internal health dossier (dossier sanitario aziendale) constitutes a distinct, cumulative data processing operation separate from the immediate medical care provided by an individual practitioner during a single clinical event. Consolidating past and present clinical events into a single queryable profile requires heightened safeguards and explicit, unbundled choices by the patient.

Despite these clear regulatory demarcations, healthcare infrastructure across public hospitals frequently lagged behind required legal adaptations. In March 2019, supervisory guidelines further clarified that centralized patient dossiers fall squarely under the explicit consent requirements of Article 9, Paragraph 2, Letter (a) of the General Data Protection Regulation, precluding reliance on generic treatment exemptions.

The regulatory trajectory demonstrates that treating medical data under an all-encompassing clinical umbrella creates severe legal friction. When historical records are merged into unified electronic databases without granular access perimeters, the statutory guarantees of purpose limitation and data minimization under European frameworks are fundamentally nullified.

Involved Entities and Institutional Actors

The primary entity subject to regulatory intervention is the [[Azienda Ospedaliero-Universitaria Careggi|Q3631579]], a major public university hospital and tertiary referral center located in Florence, Tuscany. As the legal data controller, the enterprise is responsible for designing and maintaining technical access privileges, patient intake workflows, and electronic health record security.

Supervisory oversight and enforcement actions were executed by the [[Garante per la protezione dei dati personali|Q3758362]], the national independent authority tasked with monitoring compliance, auditing electronic processing architectures, and issuing administrative penalties across public and private administrative bodies.

The calculation of financial liabilities and sanction parameters adhered to the coordinated methodology established by the [[European Data Protection Board|Q54958066]]. Specifically, the calculation of administrative fines strictly followed Guidelines 04/2022 adopted on May 23, 2023, ensuring standardized penalty assessments across the European Union.

Critical Analysis of the Evidentiary Record

Systemic Access Vulnerabilities and Historical File Queries

The factual findings documented during on-site inspections revealed an unrestricted data retrieval capability embedded directly within the hospital’s electronic health dossier. Any physician attending to an admitted patient or reviewing an active outpatient file within an authorized unit could execute broad queries across the patient’s entire historical record across other independent operational units.

This architectural vulnerability allowed practitioners to access discharge summaries, diagnostic reports, and physician consultation letters originating from completely unrelated clinical departments. Most critically, records available within these cross-unit searches included archival clinical documentation dating as far back as 1996, specifically identifying historical records from specialized units such as toxicology.

“The physician, regarding patients admitted or holding an outpatient file in an operational unit to which they were authorized, was able to execute a historical search returning the list of hospitalizations and medical letters—dating back to 1996 for the toxicology unit—generated across operational units other than those to which the physician was assigned.”

This technical configuration constituted an unambiguous breach of the core principles of lawful processing, purpose limitation, and data minimization codified under Article 5, Paragraph 1, Letters (a), (b), and (c) of Regulation (EU) 2016/679. Practitioners were systematically granted visibility over highly sensitive, non-relevant past treatments that bore no operational connection to current clinical evaluations.

Consent Architecture Deficiencies and Transition to OTP Protocols

Prior to the supervisory inspection, the hospital systematically secured only a single, undifferentiated consent form covering general medical care purposes. This monolithic intake failed to distinguish between direct point-of-care consultations and the secondary creation of an interconnected corporate digital health dossier.

Following regulatory intervention, the healthcare authority implemented urgent technical remediation to redesign its patient intake systems. The updated digital architecture introduced a segregated, three-tier consent mechanism verified through individual One-Time Password (OTP) codes transmitted directly to the data subject during registration.

Under the revised technical design, patients must independently authorize three distinct data processing layers: initial activation of the corporate health dossier, retroactive ingestion of historical clinical events, and the specific inclusion of categories subject to heightened legal protections (dati a maggior tutela). Each tier requires explicit validation via the timely transmission of a generated OTP code.

Statutory Violations and Sanction Determination

The regulatory authority determined that the historical system setup breached Articles 5(1)(a), 5(1)(f), 9, 25, and 32 of the GDPR, alongside Article 75 of the national Privacy Code and the 2015 Dossier Guidelines. The failure to integrate strict access barriers directly contravened the mandatory principle of data protection by design and by default.

Because the hospital promptly implemented the requisite structural remedies to bring the system into full technical conformity, the supervisory body concluded that ongoing injunctive correctives under Article 58, Paragraph 2 were unnecessary. However, the historic infractions mandated the issuance of an administrative monetary penalty pursuant to Article 83, Paragraphs 4 and 5 of the Regulation and Article 166, Paragraph 7 of the national Code.

Transparency and Legal Foundation

This dossier is compiled entirely from official regulatory enforcement proceedings issued by the national supervisory authority under Provision No. 10166336 dated August 4, 2025. The full administrative document forms part of the permanent public record maintained by the data protection authority and is accessible via its official legal repository.

Under Article 5 of Italian Law No. 633/1941, official texts of legislative, administrative, and judicial acts of the State and public administrations are not subject to copyright restrictions and reside permanently in the public domain. The operational, structural, and legal assessments contained herein serve the public interest in institutional oversight and algorithmic accountability.

Related content

Click to switch theme:

Comments (0)