Manx Care has received an Enforcement Notice from the Information Commissioner after a number of data breaches.
According to the document, there have been several breaches, including one where the unencrypted medical record of a patient was emailed to around 2,200 people.
The notice says that damage or distress to individuals is likely due to the lack of appropriate technical and organisational measures.
Manx Care now have four months to comply with GDPR regulations and provide the Commissioner with updates, or face a fine of up to £1m.
You can read the full document here.
House plan to restore Foxdale Deads
Douglas to sign Friendship Agreement with Dublin
Ramsey hosts postponed fireworks display
Tractor run takes to roads this evening
Port Erin hosts lights switch-on
Joe Locke meets princess at annual carol concert
New weather warning issued
Santa's on a Bike ready to raise money for Rebecca House