Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America and Asia-Pacific: 1,905 cases from 39 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Becton, Dickinson and Company (BD) €166.7m 42 % · 1 case
- Anonymised companies €56.6m 14 % · 21 cases
- Access DX Laboratory, LLC €31.7m 8 % · 1 case
- Advanced Pathology Solutions PLLC und APS MSO LLC €25.9m 6 % · 1 case
- C.R. Bard, Inc.; Liberator Medical Supply, Inc.; Liberator Holdings; Rochester Medical Corporation €16.3m 4 % · 1 case
- NUWAY Alliance, Inc. €15.8m 4 % · 1 case
- Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratórií €14.6m 4 % · 1 case
- Oroville Hospital €9.77m 2 % · 1 case
- NeoGenomics Laboratories Inc. €8.59m 2 % · 1 case
- PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs) €7.8m 2 % · 1 case
- 33 more€46m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | €300,000 |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Jun 2026 Health Service Executive (HSE)DPC: €300,000 fine against HSE after ransomware attack on hospital laboratory in Tullamore €300,000
In November 2018 attackers encrypted patient data in the laboratory information system of Midlands Regional Hospital Tullamore. The DPC found that the HSE had infringed Art. 5(1)(f), 28, 30, 32(1) and 34 GDPR (including insufficient security, deficient processor contracts and record of processing, and incomplete notification of affected persons), issued a reprimand, imposed €300,000 for the security failings (Art. 5(1)(f) and 32(1)) and ordered it to introduce specified policies and procedures for secure processing.
Laboratory and other specialist hospital systems also belong in security and supplier management; contracts with processors must contain the GDPR safeguards.
Ransomware protection of clinical systems
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5(1)(f), 28, 30, 32(1), 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- DPC: Inquiry into Midlands Regional Hospital Tullamore (IN-19-9-4) Decision of an authority
Checked against the official source on 2 Oct 2026 · Direct link