Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America and Asia-Pacific: 1,905 cases from 39 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
Who?
by company- Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratórií €14.6m 33 % · 1 case
- PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs) €7.8m 17 % · 1 case
- Anonymised companies €7.24m 16 % · 10 cases
- IQVIA Operations France €5m 11 % · 1 case
- Doctolib €4.67m 10 % · 1 case
- Balt USA LLC (Balt-Gruppe) €1.77m 4 % · 1 case
- Attendo Suomi Oy €1.5m 3 % · 1 case
- IDCQ Hospitales y Sanidad, S.L.U. €1.2m 3 % · 1 case
- Hôpital Privé de la Loire €500,000 1 % · 1 case
- Health Service Executive (HSE) €300,000 1 % · 1 case
- 10 more€111,761
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | €300,000 |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Jun 2026 Health Service Executive (HSE)DPC: €300,000 fine against HSE after ransomware attack on hospital laboratory in Tullamore €300,000
In November 2018 attackers encrypted patient data in the laboratory information system of Midlands Regional Hospital Tullamore. The DPC found that the HSE had infringed Art. 5(1)(f), 28, 30, 32(1) and 34 GDPR (including insufficient security, deficient processor contracts and record of processing, and incomplete notification of affected persons), issued a reprimand, imposed €300,000 for the security failings (Art. 5(1)(f) and 32(1)) and ordered it to introduce specified policies and procedures for secure processing.
Laboratory and other specialist hospital systems also belong in security and supplier management; contracts with processors must contain the GDPR safeguards.
Ransomware protection of clinical systems
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5(1)(f), 28, 30, 32(1), 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- DPC: Inquiry into Midlands Regional Hospital Tullamore (IN-19-9-4) Decision of an authority
Checked against the official source on 2 Oct 2026 · Direct link