DPC announces EUR 645,000 fine against HSE for data protection failings in document storage

Original title: Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)

Severity: Info Other, enforcement EU

The Data Protection Commission has issued a final decision against Ireland's Health Service Executive (HSE) following an inquiry into two unauthorized access incidents at psychiatric hospital facilities in October and November 2023, where intruders accessed paper medical records stored in external facilities. The DPC imposed fines totalling EUR 645,000, a reprimand, and compliance orders, citing data protection failings related to physical conditions of document storage facilities and integrity of retained documents. HSE must strengthen physical security measures, document storage conditions, and implement enhanced access controls to ensure compliance with GDPR requirements on data security and breach notification.

What changed

  • DPC issued administrative fines totalling EUR 645,000 against HSE for data protection breaches involving unauthorized access to paper medical records at St. Loman's Hospital (Mullingar) and St. Conal's Hospital (Letterkenny)
  • DPC identified systemic data protection failings in the physical conditions of HSE document storage facilities, particularly concerning environmental controls and document integrity in external storage locations
  • DPC issued a reprimand to HSE for insufficient security measures protecting paper records containing personal data of health service users
  • DPC imposed multiple compliance orders requiring HSE to remediate physical security deficiencies and establish proper safeguards for document storage and retention
  • Findings focused on violations of GDPR Articles 5 (data protection principles), 32 (security of processing), 33 and 34 (breach notification obligations)

Who is affected

Health service providers operating in Ireland; public healthcare organizations responsible for maintaining paper-based medical records; any organization storing personal data in external facilities with inadequate physical security controls

Summary generated by a language model; the official text prevails. Not legal advice.