HSE fined €365,000 over data breaches
Pic: Shutterstock

02 Sept 2026 data law Print

HSE fined €645,000 over data breaches

The data-protection watchdog has fined the HSE a total of €645,000 after an investigation into two data breaches in 2023.

The Data Protection Commission (DPC) has also reprimanded the health body and issued it with orders aimed at bringing its processing of personal data into line with the GDPR.

These include a complete audit of all storage facilities where the HSE stores and retains paper files, and an assessment such facilities to ensure that they are fit to maintain to confidentiality and integrity of personal data.

The HSE must also remove all paper records from any facilities found not to be fit for purpose.

Social-media videos

The 2023 breaches related to two specific locations –  St Loman’s Hospital in Mullingar, Co Westmeath and St Conal’s Hospital in Letterkenny, Co Donegal – that were accessed by unauthorised third parties.

Videos uploaded to social media by intruders highlighted that paper medical records were stored and retained in both facilities.

As part of its inquiry, DPC inspections at 12 HSE sites nationwide identified data-protection failings concerning the physical conditions of HSE document-storage facilities and the integrity of the documents held within those facilities.

Documents ‘destroyed by mould’

DPC deputy commissioner Graham Doyle said that the watchdog observed “significant issues with documents damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment, or water damaged”.

He added that the commission discovered storage areas that were “in such profound disarray and neglect” that the records within them could not be deemed to be filed in any organised or accessible manner.

“There were records stored in disused bathrooms and cubicles, a shipping container in a turf shed, rooms without functioning lighting or heating, as well as derelict buildings at a number of disparate locations,” he stated.

Doyle said that the way that the  HSE retained such records had led to “an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties”.

Security failings

The inquiry found several breaches of the GDPR – including a failure to ensure appropriate security of the personal data contained in paper records stored and retained by the HSE in its external facilities.

The DPC also found that the health body had failed to implement “appropriate technical and organisational measures” to ensure a level of security appropriate to the risk.

It also found that the HSE had failed to notify it of the breach at St Loman’s within the required 72 hours of becoming aware of the issue.

The data watchdog said that similar previous infringements by the HSE were an aggravating factor in calculating the fines.

Gazette Desk
Gazette.ie is the daily legal news site of the Law Society of Ireland

Copyright © 2026 Law Society Gazette. The Law Society is not responsible for the content of external sites – see our Privacy Policy.