Irish DPC fines HSE €645,000 over unsecured paper medical records
Key Takeaways
- 01The Irish Data Protection Commission fined the HSE €645,000 for GDPR failures involving unsecured paper medical records.
- 02The DPC found breaches of GDPR Articles 32–34, covering data security, breach notification to regulators, and communication with affected individuals in high-risk cases.
- 03The HSE must comply with DPC orders addressing its handling of the incident and communications required by the decision.
- 04The decision reinforces that GDPR security duties cover physical medical files as well as electronic health-record systems.
Ireland’s Data Protection Commission (DPC) has fined the Health Service Executive (HSE) €645,000 after finding failures in its handling of unsecured paper medical records. The decision, published on 3 September 2026, concerns breaches of the EU General Data Protection Regulation (GDPR), including Articles 32 to 34.
The GDPR requires organisations to apply appropriate security measures to personal data, assess whether a breach must be notified to the regulator, and, where a breach creates a high risk to individuals, communicate it to affected people. The DPC concluded that the HSE did not meet these requirements in relation to paper records.
Alongside the fine, the DPC issued orders requiring the HSE to bring its practices into compliance and to communicate as directed. The decision underlines that GDPR security obligations apply to physical records as well as digital systems, particularly where health information is involved.
Healthcare bodies and other organisations holding sensitive paper files should ensure they have effective physical access controls, record-handling procedures, breach-assessment processes, and notification arrangements. They should also be able to identify affected individuals and communicate with them when a data breach creates a high risk to their rights and freedoms.