Irish DPC fines HSE €645,000 over insecure paper medical-record storage

Scott Dooley
5 min read · Sep 18, 2026 Last updated: September 26, 2026

In late 2023, people got into two disused psychiatric hospitals in Ireland and filmed what they found: boxes of patient medical records, left in buildings the Health Service Executive (HSE) no longer used for care but still used for storage. The videos were posted on social media. On 2 September 2026, the Irish Data Protection Commission (DPC) announced a €645,000 fine against the HSE over how those records were kept. Press reports describe it as the largest fine the DPC has imposed on a public body.

The DPC announcement followed a final decision dated 28 August 2026.

Two hospitals, two break-ins

The first breach was at St Loman’s Hospital in Mullingar, County Westmeath, a former psychiatric hospital contaminated with asbestos. The HSE notified the DPC in October 2023 after intruders reached paper records stored there. The second was in the New Building at St Conal’s Hospital in Letterkenny, County Donegal, another former psychiatric hospital affected by severe mould, notified in November 2023. Neither site was used for clinical work any more, but both had stayed in use as HSE storage.

In April 2024 the HSE told the DPC it had learned, again through social media, that someone had got into the basement at St Loman’s, where further records were held. The HSE described these as old mental health records.

The DPC opened an inquiry on 24 May 2024. To find out whether the two hospitals were isolated cases or part of a wider pattern, its authorised officers inspected 12 HSE storage sites around the country.

What the inspectors found

Records had been kept in disused bathrooms and cubicles. Some documents had been destroyed by mould, contaminated with animal droppings, covered in rubble or damaged by water. Many had been kept long after the HSE’s own retention policies said they should have been destroyed.

Graham Doyle, the DPC’s deputy commissioner, said that holding records insecurely beyond their retention period created an ongoing, significant risk that third parties could access sensitive medical information. The DPC also found that the HSE had not reported the St Loman’s breach within the 72 hours the GDPR requires, and it treated earlier, similar infringements by the HSE as an aggravating factor when setting the fine.

How the €645,000 fine was split

  • €300,000 for infringements of GDPR Articles 5(1)(f) and 32, concerning integrity and confidentiality and security of processing.
  • €300,000 for an infringement of Article 5(1)(e), the storage-limitation principle.
  • €30,000 for an infringement of Article 33, concerning notification of a personal-data breach to the supervisory authority.
  • €15,000 for an infringement of Article 34, concerning communication of a personal-data breach to affected people.

The DPC also reprimanded the HSE and ordered it to:

  • audit every facility where it stores paper files;
  • remove records from any site that is not fit for purpose;
  • destroy records containing personal data that it no longer needs;
  • set up a regular check on whether it is following its own retention policies.

The HSE accepted the findings and apologised to patients. It said the contaminated records at St Loman’s have been destroyed and that over-retained records at St Conal’s are being destroyed.

What compliance leads should take from the decision

Map paper records as data assets

Both hospitals had stopped clinical work but stayed in use as storage, which is how a site can drop out of an asset register while still holding personal data. Include paper files in records of processing, information-asset registers and risk assessments. Record what is held, where it is held, who can access it, how it is moved and when it should be destroyed. A storage provider or facilities team may support the process, but accountability does not disappear when records leave the main office.

Test the physical environment

Check doors, locks, alarms, visitor controls, lighting, water and fire risks, environmental conditions, shelving and evidence of intrusion. Inspections should be documented, risk-ranked and repeated. A policy that says records are secure is not a substitute for checking the room where they are stored.

Make retention operational

Retention schedules need owners, review dates and a practical destruction process. If a file has reached the end of its retention period, leaving it in an archive creates continuing exposure. Destruction should be secure, authorised and evidenced.

Exercise the breach plan

Teams should know how to escalate a suspected physical breach, preserve evidence, assess risk and record decisions. The GDPR’s breach rules can require notification to the supervisory authority and communication to affected people. A tabletop exercise can expose gaps in contact lists, decision rights and response times before a real incident does.

Why this matters beyond healthcare

Medical records make the risk especially visible, but the control lesson applies to HR files, safeguarding records, customer applications, legal documents and printed exports. The medium changes the control, not the organisation’s responsibility to protect personal data.

For a UK or US compliance lead, the practical question is simple: could the organisation show where sensitive paper records are, why they are still needed, and what prevents unauthorised access? If the answer depends on informal knowledge, this decision is a prompt to strengthen the control environment. Our coverage of a previous HSE breach shows how the same accountability questions arise when the records are digital.

Questions to ask about paper-record security

  • Have all off-site paper stores been identified and risk-assessed?
  • Are access rights, visitors and incidents recorded?
  • Is there a documented retention and secure-destruction schedule?
  • Can staff recognise and escalate a physical data breach?
  • When was the last documented inspection or exercise?

Sources