Irish HSE fined €645K after medical records were found in mold and rubble
Disused bathrooms and a shipping container are no place to store medical records.

A man dressed in a leprechaun costume in Dublin. By Robert Alexander/Getty Images
- Ireland’s DPC fined the HSE €645,000 for failing to secure paper patient records.
- Intruders accessed medical records at two former psychiatric hospitals and posted video footage online.
- Inspectors found records damaged by mold, water, animal droppings, rubble, and poor storage conditions.
- The DPC said the HSE failed to secure data, report breaches promptly, and notify affected people.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Data Protection Commission (DPC) has issued a €645,000 fine to the Irish Health Service Executive (HSE) for failing to properly protect paper health records in its external storage facilities.
The Irish privacy regulator and data protection authority launched a formal investigation into the matter on May 24th, 2024, after receiving 2 complaints of personal data breaches in the preceding months.
In both cases, unknown individuals gained unauthorized access to paper medical records stored at 2 separate former psychiatric hospital facilities. The intruders made a video showing the paper records and uploaded it to social media.
In April 2024, the HSE informed the DPC of the incidents. Ireland’s public healthcare organization, responsible for running and managing healthcare services across the country, assured the data protection authority that these records were “old mental health” records.
As part of the investigation, the DPC carried out 12 site inspections nationwide. The goal was to ascertain whether these issues were isolated incidents or whether they were systemic.
The regulator found several data protection failings in storing and protecting the integrity of the documents within the facilities. Some health records were destroyed by mold, contaminated by animal droppings, covered in rubble, rotting due to the storage environment, or water-damaged.
The DPC discovered storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organized or accessible manner. There were records stored in disused bathrooms and cubicles, a shipping container in a turf shed, rooms without functioning lighting or heating, as well as derelict buildings at a number of disparate locations,DPC Deputy Director Graham Doyle says in a press release.
He goes on the record by saying that insecurely storing medical information beyond its required retention period left sensitive data at risk of unauthorized access and disclosure by third parties. There was also the risk of records not being available for other medical care or other legal or regulatory reasons, Doyle concludes.
The DPC states that the HSE has violated several provisions of the General Data Protection Regulation (GDPR), including failing to implement appropriate security measures to protect patients’ personal data, failing to notify a breach to the DPC without undue delay, and failing to communicate with the affected victims about the breach.
All things considered, the DPC imposed a fine of €645,000 on the Irish public healthcare organization.