Ireland’s Health Service Executive (HSE) has been fined €645,000 after regulators discovered serious failures in the way sensitive paper medical records were stored and protected.
The Data Protection Commission (DPC) began its investigation in May 2024 following breaches involving two former psychiatric hospitals. Unauthorized individuals accessed records at St. Loman’s Hospital in Mullingar and St. Conal’s Hospital in Letterkenny. Videos showing medical documents at the facilities were subsequently posted on social media.
The investigation later expanded beyond those incidents. DPC officials inspected 12 HSE storage locations across Ireland to determine whether poor record management was a wider problem.
Inspectors found documents being kept in severely unsuitable conditions. Some records had been damaged or effectively destroyed by mould and water, while others were contaminated with animal droppings, surrounded by rubble or left to deteriorate. Files were discovered in disused bathrooms and cubicles, derelict buildings and even a shipping container located inside a turf shed. Some storage rooms lacked functioning lighting or heating.
The regulator concluded that the HSE failed to implement adequate security and records-management measures. It also found that personal information had sometimes been retained for longer than necessary, increasing the possibility of unauthorized disclosure while making records harder to locate when required.
Additional GDPR violations concerned the handling of the breaches themselves. The DPC determined that the HSE failed to report certain incidents within the required 72-hour period and did not properly inform affected individuals about breaches at St. Loman’s and St. Conal’s hospitals.
The €645,000 penalty consists of €600,000 for security and storage-limitation failures, €30,000 for delayed breach notifications and €15,000 for failing to communicate the breaches to affected people.
Alongside the fine, the HSE must audit its paper-record storage facilities, securely destroy information that no longer needs to be retained, and move records away from locations deemed unsuitable for protecting sensitive medical information.
