Patients’ records found strewn around St Loman’s Hospital
When a group of ‘urban explorers’ entered the disused parts of St Loman’s Hospital in October 2023, a video they uploaded to social media showed them discover a large number of paper records lying loose in the building.
The outcome of that discovery is that the HSE has been issued with a fine of €645,000 by the Data Protection Commission (DPC) for the St Loman’s discovery and a similar breach, with video evidence, a month later at another disused psychiatric hospital in County Donegal.
The DPC was first informed in October 2023 that there had been unauthorised access gained to the paper records retained and stored at St Loman’s, which, the DPC noted, is contaminated with asbestos.
In November 2023, a further breach notification was filed by the HSE with the DPC, when individuals gained unauthorised access to paper records stored and retained in the New Building in St Conal’s Hospital (Letterkenny, County Donegal). That location is also a former disused psychiatric hospital which is contaminated with severe mould.
Separately, in April 2024, the HSE informed the DPC that it became aware, via social media, that there had been unauthorised access to the basement of St Loman’s Hospital, where further records were being stored and retained. The DPC was, at that stage, advised by the HSE that these records were ‘old mental health’ records.
The DPC began an inquiry on May 24, 2024 into the HSE’s processing of personal data contained in paper records, stored and retained in the HSE’s external storage facilities, and as well as the fines, imposed a reprimand and a number of corrective orders.
Following commencement of the inquiry in May 2024, and as part of the process, authorised officers from the DPC carried out 12 site inspections nationwide. The purpose of the site inspections was to ascertain whether the issues identified in the breach notifications were isolated incidents, or whether the issues were systemic, regarding the retention and storage of personal data contained in paper records, held by the HSE, in its external facilities.
The DPC findings identified data protection failings concerning the physical conditions of HSE document storage facilities and the integrity of the documents held within those facilities.
Deputy Commissioner Graham Doyle commented that: “During the site inspections, the DPC observed significant issues with documents damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment or water damaged.
“The DPC discovered storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner.
“There were records stored in disused bathrooms and cubicles, a shipping container in a turf shed, rooms without functioning lighting or heating, as well as derelict buildings at a number of disparate locations.
“The retention of records by the HSE in an insecure manner beyond the period where they should be retained gives rise to an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties. There is also the risk of records not being available for other medical care or other legal or regulatory reasons.”
The DPC’s decision, which was notified to the HSE on August 25, 2026, found that the HSE was guilty of four GDPR breaches.
The first of those infringed the principle of integrity and confidentiality by failing to ensure appropriate security of the personal data contained in paper records and by failing to implement appropriate technical and organisational measures, including proper records management processes, mechanisms and controls, to ensure a level of security appropriate to the risk.
The second breach was of failing to retain personal data contained in paper records in a form which permits identification of data subjects for no longer than is necessary.
The third was of failing to notify the two St Loman’s breaches to the DPC without undue delay, and within 72 hours of becoming aware of them, and the fourth was of having failed to inform those to whom the material related that the breaches at St Loman’s and St Conal’s had occurred.
The HSE has now been formally reprimanded and ordered to bring its processing of personal data into compliance with the GDPR rules.
It has also been instructed to carry out a complete audit of all storage facilities where it stores and retains paper files, and to implement “a robust and appropriately designed management system” for recording and tracing all personal data stored and retained in the HSE storage facilities. It is also required to carry out the immediate and safe destruction of paper records containing personal data no longer necessary for the purposes for which they were retained.
A further requirement is that the HSE implement policies and procedures for the purposes of regularly testing, assessing and evaluating the HSE’s compliance with its own retention policies.
The HSE is also directed to carry out a complete audit and assessment of all storage facilities where it stores and retains paper files to ensure each facility is fit for purpose in terms of maintaining the integrity, availability and confidentiality of personal data.