South African pathology giant Lancet Laboratories fined R100,000 for failing to adequately report multiple data breaches

 

The Information Regulator of South Africa has issued an enforcement notice and a fine of R100,000 against Lancet Laboratories for its failure to adhere to the Protection of Personal Information Act (POPIA). The regulator cited the pathology group for neglecting to notify both the regulatory body and the affected data subjects in a timely manner following multiple security compromises. This enforcement action highlights a growing global trend where regulators are moving beyond penalizing the breach itself to strictly punishing failures in transparency and incident response protocols.

For international health organizations operating in multi-jurisdictional environments, this serves as a reminder of the strict liability associated with breach notification timelines. The regulator explicitly criticized Lancet’s lack of urgency, noting that the delay in notification denied patients the opportunity to take protective measures against identity fraud. The penalty underscores that effective incident response is not just about technical containment but also involves rigorous legal compliance and communication strategies. Lancet has since paid the fine and is reportedly overhauling its internal data governance framework to prevent future regulatory censure.

Read the original article at: https://mybroadband.co.za/news/security/619073-large-medical-lab-in-south-africa-suffers-multiple-data-breaches.html


Follow us on Instagram, Twitter, and Facebook to stay up to date with what's new in healthcare all around the world.

Comments

Popular posts from this blog

Cybersecurity in Healthcare insights: 27th Nov- 3rd Dec 2025

Cybersecurity in Healthcare Insights: 20th Nov- 26th Nov 2025

Healthcare vendor breach: 1.2 million files alleged stolen—patients exposed