South African pathology giant Lancet Laboratories fined R100,000 for failing to adequately report multiple data breaches
The Information Regulator of South Africa has issued an
enforcement notice and a fine of R100,000 against Lancet Laboratories for its
failure to adhere to the Protection of Personal Information Act (POPIA). The
regulator cited the pathology group for neglecting to notify both the
regulatory body and the affected data subjects in a timely manner following
multiple security compromises. This enforcement action highlights a growing
global trend where regulators are moving beyond penalizing the breach itself to
strictly punishing failures in transparency and incident response protocols.
For international health organizations operating in
multi-jurisdictional environments, this serves as a reminder of the strict
liability associated with breach notification timelines. The regulator
explicitly criticized Lancet’s lack of urgency, noting that the delay in
notification denied patients the opportunity to take protective measures
against identity fraud. The penalty underscores that effective incident
response is not just about technical containment but also involves rigorous
legal compliance and communication strategies. Lancet has since paid the fine
and is reportedly overhauling its internal data governance framework to prevent
future regulatory censure.
Read the original article at: https://mybroadband.co.za/news/security/619073-large-medical-lab-in-south-africa-suffers-multiple-data-breaches.html
Follow us on Instagram, Twitter, and Facebook to stay up to date with what's new in healthcare all around the world.
Comments
Post a Comment