HSE fined €645,000 after patient records found covered in animal droppings
Translated from English and summarized by DistantNews. Read the original for the full story.
At a glance
- Ireland’s Data Protection Commission fined the Health Service Executive €645,000 after inspections found medical records stored in severely neglected conditions.
- Investigators found files in disused hospitals, bathrooms, a shipping container and derelict buildings, prompting concerns about unauthorized access to sensitive medical information.
- The commission ordered the HSE to audit all paper-record storage facilities and securely destroy records no longer needed.
Ireland’s Health Service Executive has been fined €645,000 after medical records were found contaminated by animal droppings, destroyed by mould, covered in rubble and rotting from water damage.
The DPC’s findings identified data protection failings concerning the physical conditions of HSE document storage facilities and the integrity of the documents held within those facilities.
The Data Protection Commission described some storage areas as being in “profound disarray and neglect.” Inspectors found paper files in disused bathrooms, a shipping container in a turf shed, rooms without working lights or heating, and derelict buildings.
The investigation began in May 2024 after people entered two disused psychiatric hospitals and posted videos online showing boxes of medical records and patient files. The facilities were St Loman’s Hospital in Mullingar, County Westmeath, and St Conal’s Hospital in Letterkenny, County Donegal. Files in poor condition were found at both sites.
The retention of records by the HSE in an insecure manner beyond the period where they should be retained gives rise to an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties.
The commission inspected 12 facilities around the country to determine whether the conditions were isolated incidents or reflected a wider problem with the HSE’s storage and retention of paper records. It said the findings showed failures involving both the physical security of storage facilities and the integrity of the documents held there.
There is also the risk of records not being available for other medical care or other legal or regulatory reasons.
The fines are the largest the DPC has imposed on a public body. It said the HSE’s previous similar breaches, including inadequate security measures and loss of control over personal data in healthcare records, aggravated the case. Deputy Commissioner Graham Doyle warned that insecurely retained records create an ongoing risk of unauthorized access to or disclosure of sensitive medical information. He also said records might not be available when needed for medical care or legal and regulatory reasons. The HSE accepted the findings, agreed to comply with the recommendations and apologized to patients and the public.
We are sorry this has happened and we apologise to patients and the people who
Originally published by RTÉ News in English. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.