GDPR compliance programme for a hospital group: from investigation to full compliance
We managed the response to a Spanish data protection authority (AEPD) investigation following a data breach at a private hospital group, and implemented a comprehensive GDPR compliance programme across 12 centres and 3,000 employees.
The challenge
A private hospital group with 12 centres and 3,000 employees under AEPD investigation after a data breach. They needed an urgent response to avoid sanctions and a comprehensive compliance programme to eliminate future exposure.
Our approach
The Challenge
A private hospital group operating twelve centres across three Spanish regions with more than three thousand employees suffered a data breach affecting the health data of approximately four thousand patients. The breach, caused by a ransomware attack, was notified to the AEPD within the legal deadline, but the Agency opened an investigation to assess whether prior security measures had been adequate and whether the breach response had been properly managed.
The potential sanction was significant: the GDPR allows fines of up to €20 million or 4% of global turnover for serious infringements involving special categories of data such as health records. Beyond the financial risk, the company faced considerable reputational exposure in a sector where patient trust is fundamental.
The initial assessment revealed that the group lacked a structured GDPR compliance programme: no DPO had been formally appointed, several high-risk processing categories lacked documented Data Protection Impact Assessments (DPIAs), and breach management protocols were insufficient.
Our Approach
We immediately activated a multidisciplinary team combining data protection lawyers, cybersecurity technical consultants, and a healthcare regulatory specialist. Within the first seventy-two hours we prepared the initial response to the AEPD: a detailed report of the security measures implemented before the breach, a chronological account of incident detection and containment, and the corrective measures already adopted.
The strategy before the AEPD was built on three arguments: notification had been timely and complete; the security measures were reasonable for an entity of this type, although improvable; and the group had proactively adopted additional measures following the breach demonstrating genuine commitment to data protection. We supported each argument with documented evidence.
Simultaneously, we designed and implemented the comprehensive compliance programme: appointment and training of the DPO, records of processing activities for all twelve centres, DPIAs for all identified high-risk processing activities (electronic health records, telemedicine, video surveillance systems), a breach management protocol, and a training programme for all staff tailored to each professional role.
Results
The AEPD closed the investigation by resolution of archiving without imposing any sanction, acknowledging the group’s active cooperation and the corrective measures adopted. This was the optimal outcome achievable given the starting circumstances.
Over the following six months, all twelve centres in the group achieved full compliance with the GDPR and the Spanish health data protection regulations (Law 41/2002 and applicable regional legislation). Three thousand employees completed the training programme specific to their role. The group now has a robust compliance infrastructure with annual reviews and scheduled breach response drills in place.
Results
AEPD investigation closed with no sanction. Full GDPR compliance achieved across all group centres within 6 months.
Client testimonial
The speed with which BMC mobilised a multidisciplinary team — lawyers, technical experts, and healthcare specialists — made the difference between a seven-figure fine and closing the investigation. Their knowledge of the healthcare sector was critical.
Related content
Related insights
15 April 2026
Legal Quarterly Report — Q1 2026
Summary of key legal and regulatory developments for Q1 2026: new legislation, relevant decisions, and compliance recommendations.
Read article25 March 2026
Renting in Spain 2026: The 2% Cap and Mandatory Extensions — Everything You Need to Know
Complete guide to RDL 8/2026: 2% limitation on annual rent updates and extraordinary mandatory extensions of up to 2 years. Analysis for landlords, tenants, and real estate investors.
Read article21 March 2026
Rent Frozen Through 2028: Mandatory Extensions and 2% Cap (RDL 8/2026)
RDL 8/2026 caps annual rent increases at 2% and allows tenants to force up to 2 years of mandatory contract extensions for leases expiring before December 2027. Impact analysis for landlords and tenants.
Read articleAchieve similar results
Let us discuss how we can help your business achieve its goals.