Manx Care has received an Enforcement Notice from the Information Commissioner after a number of data breaches.
According to the document, there have been several breaches, including one where the unencrypted medical record of a patient was emailed to around 2,200 people.
The notice says that damage or distress to individuals is likely due to the lack of appropriate technical and organisational measures.
Manx Care now have four months to comply with GDPR regulations and provide the Commissioner with updates, or face a fine of up to £1m.
You can read the full document here.
Rally action to get underway this week
Chief Minister meets with Jewish Council
Manx Care's TT plans will be be ready soon
Roadworks around Southern race circuit for two weeks
Absolutely quackers! Highways workers rescue ducklings
Nurse pay offer vote result released soon, says union
First callout for Port St Mary lifeboat coxswain
Gas main work shuts Port St Mary roads