Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Data Breach Risks 2.9 Million Norwegians' Health Care Information

by The Gurus
January 26, 2018
in Opinions & Analysis
health
Share on FacebookShare on Twitter

Norway was among the latest successful targets for cybercriminals, and this recent attack involved health information.
The victimized organization was Health South-East RHF, which manages hospitals in nine Norwegian counties in the southeastern part of the country.
It received a notification on Jan. 8 when HelseCERT, a computer response team for the health sector, advised the company of suspicious traffic on their network.
Then, IT professionals at Sykehuspartner HF, the parent company of Health South-East RHF, investigated. Their findings confirmed a severe data breach that potentially affects more than half the population of Norway, or just under 3 million people.

Representatives Waited Too Long to Disclose the Issue

Norway is subject to an upcoming European Union legislation called the General Data Protection Regulation (GDPR). Approved and adopted by members of the European Union Parliament in April 2016, it will come into effect on May 25.
Besides applying to EU member countries, all destinations that provide goods and services to people in the European Union or track their behaviors must abide by the GDPR.
Although the standard has many specifications about data use and storage, one of the particulars is that reports of data breaches to regulatory authorities and affected individuals must occur within 72 hours of the initial knowledge.
A 2017 survey from analytics company SAS revealed 58 percent of respondents were not fully aware of what happens for organizations not in compliance by the deadline.
Regardless of whether the team at Health South-East RHF learned about GDPR noncompliance, they didn’t follow the rules for data breach notifications in this instance, and in fact, waited a week to give disclosure.
Health South-East RHF did not provide a reason for the delay in notifying anyone about the breach. Since the GDPR is not in effect yet, the organization will not get fined. However, analysts warn the prolonged period that passed could highlight the problems other companies might have regarding compliance.
The GDPR takes a tiered approach to non-compliance fines. In the most egregious cases of failure to comply, the amount imposed is €20 million, or up to 4 percent of annual revenue. However, the failure to notify regulatory officials in time results in a potential 2 percent fine.

How Should Health Organizations Respond to This Breach?

Content within the GDPR spells out requirements for handling consumer data. Also, it emphasizes organizations must provide a reasonable level of data protection and privacy to EU citizens. However, the standard does not define what “reasonable” means.
Most personal information forms people fill out include fine print that gives details about an individual’s rights and the responsibilities of the service provider. As the GDPR comes into effect, individuals within and outside the European Union can expect those documents to include full disclosures of data use practices. That may require organizations to edit existing forms to add details or make the material more relevant.
The Norwegian incident should also serve as a wake-up call to remind health facilities that they are continually at risk for data breaches.
Hackers consider patient information especially valuable because it’s highly personalized, and parts of it are valid for a long time. Cybercriminals often sell the data on the black market for top-dollar amounts.
That reality is why it’s so important for health organizations to implement best practices in their facilities and keep data as safe as possible. Several groups can help organizations improve their strategies and make recommendations.
Carrying out a detailed risk analysis is the first step. Then, depending on its findings, organizations may realize the need to patch vulnerabilities, start using more robust encryption technologies or adjust an incident response plan to ensure it minimizes the damage caused.
Having a course of action after a breach is crucial because it eases public fears.
A persistent criticism about how Health South-East RHF handled its incident was that the organization has only given vague responses when speaking about the extent of the breach, the kind of data compromised or what exactly they are doing to stop another infiltration.
The incident in Norway reminds everyone no business, industry or type of data is safe from hackers.
The best response is to take decisive preventive measures that make it harder for cybercriminals to gain access to what they want most.

ShareTweet
Previous Post

Data Breach Risks 2.9 Million Norwegians’ Health Care Information

Next Post

How to make your data safer in 2018

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol