The Health Service Executive (HSE) has been fined €645,000 by the Data Protection Commission (DPC) following an inquiry into the storage and retention of personal data in paper records at its external storage facilities. The fine was accompanied by a reprimand and corrective orders requiring the health service to bring its processing of personal data into compliance with the General Data Protection Regulation (GDPR).
Inquiry and Findings
The DPC's inquiry began on 24 May 2024 after two personal data breaches were notified to the commission in October and November 2023. In the first incident, individuals gained unauthorised access to paper records stored at St Loman’s Hospital in Mullingar, Co Westmeath, a disused former psychiatric hospital contaminated with asbestos. The second breach occurred at St Conal’s Hospital in Letterkenny, Co Donegal, also a disused former psychiatric hospital, where records were stored in the New Building, contaminated with severe mould.
Videos uploaded to social media by intruders showed medical records being stored at both locations. In April 2024, the HSE separately informed the DPC that it had become aware, through social media, of unauthorised access to the basement of St Loman’s Hospital, where further records were stored. The HSE told the DPC at the time that these were "old mental health records".
Following the launch of its inquiry, the DPC carried out 12 site inspections nationwide. Inspectors found documents that had been damaged or destroyed by mould, contaminated by animal droppings, covered in rubble or other debris, rotting because of storage conditions, and damaged by water. Records were found stored in disused bathrooms and cubicles, in a shipping container in a turf shed, in rooms without lighting or heating, and in derelict buildings.
DPC Statement and Corrective Orders
Deputy Commissioner Graham Doyle said the DPC had identified data protection failings relating to the physical condition of storage facilities and the integrity of documents. He said the retention of records in an insecure manner, beyond the period they should be retained, gave rise to an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties.
The DPC found breaches of GDPR articles relating to integrity and confidentiality (Article 5(1)(f)), security of processing (Article 32(1)), storage limitation (Article 5(1)(e)), failure to notify breaches without undue delay (Article 33(1)), and failure to communicate breaches to affected data subjects (Article 34(1)).
The DPC ordered the HSE to carry out a complete audit of all facilities where it stores paper files, including establishing a robust system for recording and tracing personal data, ensuring the immediate safe destruction of unnecessary records, and regularly testing compliance with retention policies. The HSE must also conduct a complete audit and assessment of its storage facilities to establish their suitability, remove records from unsuitable facilities, and implement tracking systems.
The DPC considered, as an aggravating factor, that the HSE had previously committed similar infringements. The decision was notified to the HSE on 25 August 2026, and the full decision is to be published in due course.
HSE Response
The HSE said it acknowledges and accepts the report's findings and that work is ongoing. The health service apologised to patients for the data breaches at the St Loman’s and St Conal’s sites and for non-compliance with its paper record retention policies.