The Irish authority fines the Health Service €645,000 for failures in paper data security

The Irish Data Protection Commission (DPC) has fined the Health Service Executive (HSE) a total of €645,000 for serious failures in the security and management of paper medical records stored in external warehouses.

Facts and context

The Irish data protection authority (DPC) today published a sanction decision against the Health Service Executive (HSE), including the imposition of a €645,000 fine, for failures related to the security and retention period of paper medical records, as well as the management of associated data breaches.

The case originated from two data breach notifications in October and November 2023, concerning unauthorized access to paper medical records in former decommissioned psychiatric hospitals, revealed by videos shared on social media.

Grounds for the decision

Following these notifications and a subsequent report in April 2024, the authority conducted 12 on-site inspections which revealed systemic failures in the physical storage conditions of the archives. The authority noted storage conditions so degraded that records were damaged or destroyed, and stored in such disorder that they were neither organized nor accessible. The following breaches were identified:

  • Obligation to ensure the integrity, confidentiality, and security of data (Article 5(1)(f) of the GDPR and Article 32(1) of the GDPR): The authority found that the HSE had not implemented appropriate technical and organizational measures to ensure the security of paper records. Inspections revealed deplorable storage conditions (mold, animal droppings, debris, humidity) in inappropriate and unsecured locations such as disused restrooms or a shipping container, constituting a clear violation of the obligation to protect data against unauthorized access or loss of integrity.
  • Obligation of storage limitation (Article 5(1)(e) of the GDPR): The authority found that the HSE retained personal data in a form allowing identification of data subjects for longer than necessary for the purposes for which they were processed. The presence of old archives in abandoned buildings, without management or destruction processes, characterized this breach.
  • Obligation to notify data breaches to the supervisory authority (Article 33(1) of the GDPR): The HSE failed to notify the DPC without undue delay and within 72 hours two distinct breaches occurring at St. Loman hospital, one concerning an initial unauthorized access and the other a subsequent access to the basement of the same building.
  • Obligation to communicate data breaches to data subjects (Article 34(1) of the GDPR): The authority concluded that the HSE failed to inform data subjects of breaches occurring at St. Loman and St. Conal hospitals, although these breaches were likely to result in a high risk to their rights and freedoms.

Authority's decision

Consequently, the authority imposed a fine of €645,000 on the Health Service Executive.

Furthermore, the authority ordered the HSE to comply with the GDPR by imposing a reprimand and corrective measures. These include conducting a comprehensive audit of all its paper record storage sites to implement a management and traceability system, securely destroying unnecessary archives, and regularly evaluating its own retention policies. The HSE must also ensure that all storage locations are suitable to guarantee the integrity, availability, and confidentiality of data, and relocate records from non-compliant sites to appropriate facilities.

Lessons learned

This decision reminds that:

  • The obligation to implement appropriate technical and organizational security measures applies with the same rigor to paper archives as to digital data, including the physical security of storage premises.
  • The absence of a lifecycle management policy for archives, including clear destruction procedures after retention periods, constitutes both a breach of the storage limitation obligation and a major risk factor for data security.
  • The recurrence of similar breaches, even under different circumstances, is considered a significant aggravating factor when determining the amount of the fine.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire