DPC issues €645,000 fine to HSE for inadequate storage and breach notification failures

Original title: Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)

The Data Protection Commission has issued a final decision against the Health Service Executive (HSE) following an inquiry into two unauthorised access incidents to paper medical records stored in external facilities in 2023. The DPC found serious data protection failures related to the physical security conditions of HSE document storage facilities and the handling of the breaches. The HSE must now comply with remedial orders and faces administrative fines totalling €645,000, plus a reprimand, for violations of core GDPR principles on data security, breach notification, and data subject communication.

What changed

  • DPC issued administrative fines totalling €645,000 to HSE for data protection violations
  • DPC issued a formal reprimand to HSE for inadequate physical security of paper records stored in external facilities
  • DPC identified failures in HSE's compliance with Article 32 (security of processing) regarding the physical storage conditions of personal data in paper form
  • DPC identified failures in HSE's compliance with Articles 33 and 34 (breach notification and communication to data subjects) following the unauthorised access incidents
  • DPC issued compliance orders requiring HSE to remediate data protection failings in document storage and breach handling procedures

Who is affected

Health service provider (HSE - Ireland's public health service); data subjects whose medical records were stored in the affected facilities (St. Loman's Hospital in Mullingar and St Conal's Hospital in Letterkenny)

Summary generated by a language model; the official text prevails. Not legal advice.