The data controller had to make sure that outsiders could not gain unauthorised access to sensitive personal data and that only the personnel treating a patient had access to his/her patient register.23.  Section 13 of the Patient???s Status and Rights Act provided that health care professionals or other persons working in a health care unit were not allowed to reveal to an outsider (tha