Ireland’s Data Protection Commission (DPC) has fined the Health Service Executive (HSE) €645,000 following an investigation into systemic data security failures that left physical medical records stored in derelict, unsafe, and contaminated facilities. The penalty represents a record financial fine issued to an Irish public body by the privacy watchdog.

The regulator’s inquiry was initiated after intruders broke into disused psychiatric facilities in late 2023—including St Loman's Hospital in Mullingar, County Westmeath, and St Conal's Hospital in Letterkenny, County Donegal—and published footage of exposed patient files on social media. A further breach was reported by the HSE in April 2024 after unauthorized individuals accessed additional paper records stored in the basement of St Loman's.

Following the notifications, DPC inspectors launched a nationwide investigation in May 2024 examining 12 HSE sites to determine whether the security failures were systemic. DPC Deputy Commissioner Graham Doyle stated that officers discovered storage areas in "profound disarray and neglect," with medical files severely damaged or destroyed by mould, contaminated by animal droppings, covered in rubble, or rotting due to moisture.

According to the regulatory findings, confidential paper documents were being stored in unlit and unheated rooms, disused bathroom cubicles, derelict buildings, and a shipping container housed inside a turf shed. The commission determined that these storage conditions created a significant risk of unauthorized access to sensitive patient data.

In addition to the €645,000 fine, the DPC issued a formal reprimand to the HSE alongside a series of corrective orders directing the health authority to overhaul its physical document retention and security protocols.