*** Bahrain Medical Centre Fined BD1,000 for Sharing Patient Health Data | THE DAILY TRIBUNE | KINGDOM OF BAHRAIN

Bahrain Medical Centre Fined BD1,000 for Sharing Patient Health Data

Bahrain’s Personal Data Protection Authority has imposed an administrative fine of BD1,000 on a medical centre after finding that it had violated the Personal Data Protection Law by sharing a patient’s health information with his employer without prior consent or a valid legal basis.

The decision followed a complaint submitted by a citizen, who reported that the medical centre had sent information and a document relating to his medical examinations to his workplace by email. The complainant considered the disclosure a violation of his privacy and a breach of Bahrain’s personal data protection regulations.

The authority launched an investigation into the complaint and heard the complainant’s statement. It also notified the medical centre of the complaint and received its defence, while requesting relevant explanations and documents from the complainant’s employer.

Following the investigation, the authority concluded that there was no evidence that the patient had provided prior consent that met the legal requirements for sharing his health information with his employer. It also found that none of the exceptional circumstances allowing such data to be processed without consent had been established.

The authority stressed that data controllers and processors must comply with the Personal Data Protection Law, issued under Law No. 30 of 2018, and its implementing decisions, particularly when handling sensitive personal data.

It emphasised that health information can only be processed on the basis of a legitimate and clearly defined legal ground, in accordance with the requirements and safeguards established by law, and only to the extent necessary to achieve the legitimate purpose of the processing.

The authority highlighted the particular importance of these requirements in the medical and healthcare sectors, where personal health information is considered highly sensitive and can reveal details about an individual’s medical condition.

It urged data controllers in both the public and private sectors to verify the legal basis for any processing before accessing or handling personal information, clearly define the purpose and scope of the processing, restrict access to authorised individuals, and implement appropriate technical and organisational measures to prevent unlawful use, disclosure or sharing of personal data.

The authority stressed that compliance with these requirements is not merely an administrative procedure, but an essential safeguard for protecting individuals’ privacy and sensitive personal information.