Manx Care has received an Enforcement Notice from the Information Commissioner after a number of data breaches.
According to the document, there have been several breaches, including one where the unencrypted medical record of a patient was emailed to around 2,200 people.
The notice says that damage or distress to individuals is likely due to the lack of appropriate technical and organisational measures.
Manx Care now have four months to comply with GDPR regulations and provide the Commissioner with updates, or face a fine of up to £1m.
You can read the full document here.
Douglas Council goes electric
Southern residents now invited to give views on 20mph zones
Manxnet email users warned about scam as service becomes paid-for
Over 100 claims for damage to government property
MHK demands U-turn on MiCards
No sailings to Liverpool this weekend due to terminal works
Passport and immigration public counters to be shut tomorrow
Police appealing to public after street fight