Article content
In briefShow moreShow lessThe inspection covered organisational measures, structured information and action plans for hospitals and municipalities.
- The inspection covered organisational measures, structured information and action plans for hospitals and municipalities.
- The findings included access lists, information location, reasons for record access and incident management.
- The notice was procedural: it was an intended-order notice, not a final order or final sanction.
The Norwegian Data Protection Authority issued a final inspection report and notified Helseplattformen AS of intended corrective orders. The case concerned security conditions in a system used by hospitals and municipalities and must be read alongside the GDPR and Norwegian patient-record legislation.
The authority identified a need for organisational measures. Security therefore could not be treated solely as a matter of technical settings; it also required clear responsibility, documented processes and follow-up by the organisations using the system. Hospitals and municipalities needed to be able to demonstrate how access was governed and controlled.
The report also addressed structured information and action plans. These should allow deficiencies to be identified, corrective measures prioritised and progress tracked. For management, that is a governance requirement and a source of assurance, not merely a task list for closing isolated technical issues.
Access lists and the location of information were among the areas discussed. Organisations should therefore check that permissions reflect genuine work needs, that inventories remain current and that information locations are clearly and appropriately documented. Weaknesses in these foundations can undermine both prevention and later review.
Another issue concerned the reasons for accessing patient records. It must be possible to understand why access was granted or used and to test whether the use had a legitimate work-related basis. Traceability and retrospective review are consequently central elements of the operational security model.
Incident management was also part of the findings. The organisation must be able to detect, assess and handle security incidents through clear roles and documented measures. This includes both the initial response and the learning process intended to reduce the likelihood of recurrence.
The procedural status is essential. The authority had issued a notice of intended orders, but the material did not describe a final order, final fine or amendment to the GDPR. Any later assessment therefore needed to distinguish confirmed inspection findings, proposed corrective measures and any subsequent decision.
Sources
Norwegian Data Protection Authority: “Notice of intended corrective orders to Helseplattformen,” 2 December 2025.
Norwegian Data Protection Authority: “Final inspection report and notice of intended orders,” 2 December 2025.
For discussion
How can the organisation demonstrate that access control, record-access monitoring and incident management work in practice across organisational levels?

