惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
Y
Y Combinator Blog
Engineering at Meta
Engineering at Meta
D
Docker
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
大猫的无限游戏
大猫的无限游戏
腾讯CDC
P
Proofpoint News Feed
A
About on SuperTechFans
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
Google DeepMind News
Google DeepMind News
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
L
LangChain Blog
MyScale Blog
MyScale Blog
博客园 - 三生石上(FineUI控件)
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
N
Netflix TechBlog - Medium
G
Google Developers Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey Data breaches going unreported, says Irish compliance survey
HSE fined €645,000 for storing records in decrepit condit...
Suhasini Srinivasaragavan · 2026-09-02 · via Enterprise – Silicon Republic

HSE records were found stored in disused bathrooms and cubicles, the DPC said.

The Data Protection Commission (DPC) has fined the HSE €645,000 for keeping paper medical records in battered conditions, after it found documents containing patients’ personal data destroyed by mould, contaminated with animal droppings and covered in rubble.

The watchdog was notified of the potential breaches in 2023 after people gained unauthorised access to paper records in the asbestos-contaminated St Loman’s Hospital, a former disused psychiatric facility in Co Westmeath, and St Conal’s Hospital in Co Donegal – also a former disused psychiatric hospital, contaminated with severe mould. The HSE used these locations as external storage facilities.

The HSE filed a breach notification in November 2023 regarding the incident at St Conal’s Hospital, and further informed the DPC in April 2024 of social media posts showing unauthorised access to the basement of St Loman’s Hospital. At the time, the HSE told the DPC that the records in question were “old”.

In its two-year-long investigation launched in May 2024, the DPC found that the HSE violated the GDPR across several instances, including by failing to ensure the security of the personal data stored in HSE’s external storage facilities, and failing to ensure patients’ personal information is not kept for longer than needed.

Furthermore, the HSE failed to inform the DPC of the breach in St Loman’s Hospital within 72 hours of becoming aware of the incident, and failed to inform the data subjects of the personal data breaches, the watchdog also found.

“During the site inspections, the DPC observed significant issues with documents damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment or water damaged,” said DPC deputy commissioner Graham Doyle.

“The DPC discovered storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner. There were records stored in disused bathrooms and cubicles, a shipping container in a turf shed, rooms without functioning lighting or heating, as well as derelict buildings at a number of disparate locations.

“The retention of records by the HSE in an insecure manner beyond the period where they should be retained gives rise to an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties. There is also the risk of records not being available for other medical care or other legal or regulatory reasons.”

Among its corrective measures, the DPC has ordered the HSE to carry out a complete audit for all storage facilities where it stores and retains paper files, destroy records with personal data that are no longer needed and establish a procedure to regularly evaluate HSE’s compliance with its own retention policies.

The HSE told SiliconRepublic.com that contaminated records at St Loman’s have been destroyed, while over-retained records at St Conal’s are also being destroyed.

However, this is not the first time the HSE has been found to be lacking appropriate security measures and control over personal data contained in paper healthcare records. The hefty fine handed today – the largest ever handed to a public body by the data protection watchdog – takes that into account, the DPC said.

“We are sorry this has happened and we apologise to patients and the people who use our services for data breaches at St Loman’s and St Conal’s sites and for our non-compliance with paper record retention and record management policies and procedures,” a spokesperson for the HSE told SiliconRepublic.com.

The health services authority said it is establishing and rolling out a comprehensive national records management programme of work, and updating policies regarding on the storage and retention of records.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.