DPC hits HSE with €645,000 fine over rotting medical records

DPC hits HSE with €645,000 fine over rotting medical records

The Data Protection Commission (DPC) has today announced its final decision following an inquiry into the HSE’s processing of personal data contained in paper records, which were found rotting and covered mould in disused hospitals by urban explorers. The DPC’s decision fines the HSE a total of €645,000 and imposes a reprimand and a number of corrective orders.

The inquiry commenced on 24 May 2024 as a result of two personal data breaches notified to the DPC in October 2023 and November 2023.

The first breach was notified to the DPC in October 2023, when individuals gained unauthorised access to paper records stored and retained in St. Loman’s Hospital (Mullingar, County Westmeath). St Loman’s Hospital is a former disused psychiatric hospital which is contaminated with asbestos.

In November 2023, a further breach notification was filed by the HSE with the DPC, when individuals gained unauthorised access to paper records stored and retained in the New Building in St. Conal’s Hospital (Letterkenny, County Donegal). This location is also a former disused psychiatric hospital which is contaminated with severe mould.

Videos uploaded to social media by intruders highlighted that medical records were stored and retained in both facilities.

Separately, in April 2024, the HSE informed the DPC that it became aware, via social media, that there had been unauthorised access to the basement of St. Loman’s Hospital, where further records were being stored and retained. The DPC was, at that stage, advised by the HSE, that these records were ‘old mental health’ records.

Following commencement of the inquiry in May 2024, and as part of the inquiry process, authorised officers from the DPC carried out 12 site inspections nationwide.

The purpose of the site inspections was to ascertain whether the issues identified in the breach notifications were isolated incidents, or whether the issues were systemic, regarding the retention and storage of personal data contained in paper records, held by the HSE, in its external facilities.

The DPC’s findings identified data protection failings concerning the physical conditions of HSE document storage facilities and the integrity of the documents held within those facilities.

Deputy Commissioner, Graham Doyle commented that: “During the site inspections, the DPC observed significant issues with documents damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment or water damaged.

“The DPC discovered storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner. There were records stored in disused bathrooms and cubicles, a shipping container in a turf shed, rooms without functioning lighting or heating, as well as derelict buildings at a number of disparate locations.

The retention of records by the HSE in an insecure manner beyond the period where they should be retained gives rise to an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties. There is also the risk of records not being available for other medical care or other legal or regulatory reasons.”

The DPC’s decision, which was notified to the HSE on 25 August 2026, finds that the HSE:

Infringed the principle of integrity and confidentiality of Article 5(1)(f) GDPR and infringed Article 32(1) GDPR by:

a. Failing to ensure appropriate security of the personal data contained in paper records stored and retained by the HSE in its external facilities;

b. Failing to implement appropriate technical and organisational measures, including proper records management processes, mechanisms and controls, to ensure a level of security appropriate to the risk.

Infringed the principle of storage limitation of Article 5(1)(e) GDPR by failing to retain personal data contained in paper records in a form which permits identification of data subjects for no longer than is necessary.

Infringed Article 33(1) GDPR by:

a. Failing to notify a breach to the DPC without undue delay, and within 72 hours of becoming aware of it, in respect of St. Loman’s Hospital;

b. Failing to notify a breach to the DPC without undue delay, and within 72 hours of becoming aware of it, in respect of the personal data contained in paper records stored and retained in the basement of St. Loman’s Hospital.

Infringed Article 34(1) GDPR by failing to communicate to the data subjects, the personal data breaches which occurred at St. Loman’s Hospital and St. Conal’s Hospital.

In light of the infringements identified the DPC has reprimanded the HSE and ordered it to bring its processing of personal data into compliance with the GDPR, and in particular, into compliance with Articles 5(1)(e), 5(1)(f) and 32(1) GDPR.

It has also ordered that the HSE carry out a complete audit of all storage facilities where it stores and retains paper files and implement management system for storage and tracing paper files and proper destruction of those no longer required.

The DPC fined the HSE a total of €645,000 considering as an aggravating factor that this was not the first infringement concerning the lack of appropriate security measures and the loss of control over personal data contained in paper healthcare records.

Join over 12,300 lawyers, north and south, in receiving our FREE daily email newsletter
Share icon
Share this article: