Ireland Fines Health Service €645,000 After Medical Files Were Found in Abandoned Hospitals

Table of Contents

Ireland’s Data Protection Commission on September 2 issued a final decision against the Health Service Executive over paper records stored in external sites. The HSE must pay €645,000. It also received a reprimand and orders to audit every paper store, move files out of unfit buildings, and destroy records that should already be gone.

The inquiry started May 24, 2024, after two breach notices. In October 2023 people got into paper files at St. Loman’s Hospital in Mullingar, County Westmeath, a closed psychiatric hospital contaminated with asbestos. In November 2023 the same thing happened at the New Building at St. Conal’s Hospital in Letterkenny, County Donegal, another closed psychiatric hospital with severe mould. Intruders posted video. The clips showed medical records on site.

In April 2024 the HSE told the DPC it had learned from social media that someone had also entered the basement at St. Loman’s. The HSE said those files were “old mental health” records.

Inspectors then visited 12 sites across the country to see whether the two hospitals were outliers.

What the inspectors found

Deputy Commissioner Graham Doyle said they found documents damaged or destroyed by mould, contaminated by animal droppings, covered in rubble, rotting in the room they sat in, or water-damaged. Records sat in such disorder that they could not be treated as filed. Officers found files in disused bathrooms and cubicles, in a shipping container in a turf shed, in rooms with no working lights or heat, and in derelict buildings.

Doyle’s point was not only theft. Files kept past the point they should exist remain available to anyone who walks in. Files that have rotted or vanished also cannot be produced for care, litigation, or a regulator.

The GDPR counts

The decision, sent to the HSE on August 25, 2026, found:

Article 5(1)(f) and Article 32(1): no appropriate security for paper records in external stores, and no records-management controls matched to the risk.

Article 5(1)(e): storage limitation. Records were kept in identifiable form longer than necessary.

Article 33(1): late notice of the St. Loman’s breaches, including the basement, outside the 72-hour clock.

Article 34(1): failure to tell the people whose data was reached at St. Loman’s and St. Conal’s.

The fine split is €300,000 for integrity and security, €300,000 for storage limitation, €30,000 for late authority notice, and €15,000 for failing to tell data subjects. The DPC treated prior similar HSE failures on paper healthcare records as an aggravating factor. The full decision will be published later.

Corrective orders require a complete audit of paper stores: a tracking system for every file, immediate safe destruction where retention has expired, and regular tests of the HSE’s own retention rules. A second audit must decide which buildings are fit to hold records. Files in unfit sites must move. Locations must be tracked. Storage conditions must be rechecked on a schedule.

Paper is still a processing system

This case is not about a cloud misconfiguration. It is about boxes in buildings nobody treated as production systems. GDPR’s security and storage-limitation rules do not pause because the medium is cardboard. A closed hospital with asbestos or mould is not an archive. It is an uncontrolled store of health data.

Health systems that still run off-site paper need a live inventory, a destruction calendar that actually runs, and buildings that can keep water, animals, and trespassers out. If the first time you learn a basement was entered is a social-media clip, Article 33 and 34 are already in play.

€645,000 will not rebuild St. Loman’s. The orders that matter are the ones that force the HSE to find every remaining pile and either house it or shred it.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.