
Patient records damaged by mould, contaminated by animal droppings, rotting after water exposure and lying among rubble have resulted in a €645,000 data-protection fine for Ireland’s Health Service Executive. The Data Protection Commission’s investigation went far beyond the two abandoned psychiatric hospitals that originally triggered the inquiry: inspectors visited twelve HSE facilities around the country and found serious weaknesses in the physical storage, retention and management of paper records.
The findings are striking partly because the case involves neither sophisticated cybercrime nor a stolen database. The information was contained in paper files. Yet the legal and practical risks are much the same: confidential medical information can be accessed by unauthorised people, destroyed before it should be destroyed, retained for longer than necessary or become impossible for healthcare staff to retrieve when legitimately required.
The DPC concluded that the HSE had breached several fundamental obligations under the General Data Protection Regulation, including the requirements to safeguard personal information, limit how long identifiable data are retained and report serious breaches promptly. It also found that affected individuals had not been appropriately informed about breaches at the two hospitals that initiated the investigation.
The regulator imposed four separate fines totalling €645,000, reprimanded the HSE and ordered a nationwide audit of facilities holding paper records. The corrective measures may ultimately prove more consequential than the financial penalty because they require the health service to identify where its paper records are located, determine whether the buildings storing them are suitable, destroy files that no longer need to be retained and establish systems capable of tracing records that remain.
The Investigation Began With Intruders Entering Two Former Psychiatric Hospitals
The regulatory investigation traces back to autumn 2023. In October that year, the HSE notified the DPC after individuals gained unauthorised access to paper records stored at the former St Loman’s Hospital in Mullingar, County Westmeath.
St Loman’s was no longer operating as an active psychiatric hospital and the building was contaminated with asbestos. Despite its disused clinical status, paper healthcare records continued to be retained there.
A second breach was notified in November 2023 after unauthorised individuals accessed records in the New Building at the former St Conal’s Hospital in Letterkenny, County Donegal. That building was affected by severe mould.
The breaches became particularly visible because people who entered the facilities uploaded videos to social media showing medical records inside the buildings. What might otherwise have remained an internal records-management failure had become a demonstrable loss of physical control over sensitive patient information.
The issue did not end there. In April 2024, the HSE told the DPC that it had become aware through social media of further unauthorised access to the basement of St Loman’s, where additional records were being stored. According to the regulator, the HSE described these at the time as old mental-health records.
That detail underlines the sensitivity of the material. A record does not become less private simply because the treatment it describes occurred decades earlier. Historical psychiatric records may contain diagnoses, treatment information, family details, addresses and other highly personal information whose sensitivity can persist long after the clinical episode itself.
Twelve Inspections Turned Two Breaches Into a National Records-Management Investigation
The DPC formally commenced its inquiry on 24 May 2024. Rather than examining only St Loman’s and St Conal’s, authorised officers inspected twelve HSE facilities around the country.
The purpose was explicit: investigators wanted to establish whether the conditions highlighted by the two breach notifications represented isolated local failures or reflected a broader problem in how the HSE retained paper records in external storage facilities.
What inspectors encountered went far beyond untidy filing rooms. The DPC reported documents damaged or effectively destroyed by mould. Other records had been contaminated by animal droppings, covered by rubble or other debris, damaged by water or left to rot because of their storage environment.
Some storage areas were described as being in such profound disarray and neglect that the records could no longer reasonably be regarded as organised or accessible files. Paper records were found in disused bathrooms and cubicles, in a shipping container located in a turf shed, in rooms without functioning lighting or heating and in derelict buildings at several different locations.
The regulator’s findings are therefore important for a reason beyond the disturbing condition of individual documents. Record security depends on a functioning system: knowing what information exists, where it is stored, who can access it, how long it must be retained and when it should be securely destroyed. A box of unidentified patient files in an unsuitable building represents a governance failure even before somebody enters the room without permission.
What DPC Inspectors Found
| Finding | Potential Data Risk |
|---|---|
| Records damaged by mould | Loss or destruction of information |
| Animal-dropping contamination | Physical deterioration and inaccessibility |
| Water-damaged or rotting files | Permanent information loss |
| Records among rubble and debris | Loss of organisation and control |
| Disused bathrooms and cubicles | Unsuitable storage conditions |
| Shipping container in turf shed | Security and environmental risk |
| Derelict buildings | Unauthorised access and deterioration |
Source: Data Protection Commission final-decision announcement, 2 September 2026.
A Data Breach Does Not Require a Computer
The case illustrates a widespread misconception about modern data protection. Public discussion often treats information security as synonymous with cybersecurity: ransomware, phishing attacks, stolen passwords and compromised databases.
GDPR protection is technology-neutral. Personal data remain personal data whether they appear in a sophisticated cloud database, an email, a spreadsheet or a paper medical chart stored in a cardboard box.
The HSE’s own guidance defines a personal-data breach broadly enough to include accidental or unlawful destruction, loss or alteration as well as unauthorised disclosure or access. That means mould destroying a patient file can represent a data-security problem even if nobody outside the health service ever reads the information.
Three concepts are particularly important: confidentiality, integrity and availability. Confidentiality means information should not be accessible to people who are not authorised to see it. Integrity means records should remain complete and protected from inappropriate alteration or destruction. Availability means authorised healthcare or administrative staff should be capable of retrieving the information when legitimately required.
The storage conditions identified by the DPC potentially threatened all three. Intruders demonstrated the confidentiality risk. Mould, water and physical contamination threatened the integrity of the files. Disorganisation and destruction threatened their availability.
This last point connects data protection directly with healthcare rather than simply privacy law. A medical record that cannot be found may be useless to an unauthorised intruder, but it can also be unavailable to a clinician, a patient seeking access to their history or an organisation responding to a legal or regulatory requirement.
The DPC Found Four Different Types of GDPR Failure
The €645,000 penalty was not imposed as a single undifferentiated sanction. The regulator identified separate failures covering security, retention, breach notification and communication with affected individuals.
The largest component concerned integrity, confidentiality and security. The DPC found that the HSE had failed to ensure appropriate protection for personal data held in paper records at its external facilities and had failed to implement adequate technical and organisational measures, including proper records-management processes, controls and mechanisms.
A second €300,000 sanction concerned storage limitation. GDPR does not permit organisations to hold identifiable personal information forever merely because deleting it is inconvenient. Information may need to be retained for substantial periods for clinical, legal, regulatory or historical reasons, but the retention period must have a legitimate basis.
The DPC found that the HSE failed to comply with the principle requiring identifiable personal data to be kept for no longer than necessary. In practice, excessive retention can increase risk: every unnecessary box of old records creates another collection of sensitive information that must be secured, catalogued and eventually destroyed.
The remaining €45,000 related to the handling of the breaches themselves. The DPC found failures to notify it without undue delay and within the required 72-hour period in relation to breaches at St Loman’s. It also found that affected data subjects had not been informed about breaches at St Loman’s and St Conal’s as required under Article 34 of the GDPR.
How the €645,000 Fine Was Divided
| GDPR Failure | Fine | Core Issue |
|---|---|---|
| Articles 5(1)(f) and 32(1) | €300,000 | Security, integrity and confidentiality |
| Article 5(1)(e) | €300,000 | Excessive data retention |
| Article 33(1) | €30,000 | Late breach notification |
| Article 34(1) | €15,000 | Failure to inform data subjects |
Source: Data Protection Commission. Total administrative fines: €645,000.
The Regulator Has Not Said How Many Patient Files Were Affected
The physical descriptions are dramatic, but several important numbers are not yet publicly available. The DPC’s announcement does not quantify how many paper records were stored across the inspected facilities, how many were damaged beyond recovery or how many individual patients were represented in those records.
The full regulatory decision has not yet been published. The DPC said it will release it in due course.
It would therefore be incorrect to infer a national number of affected patients from the twelve inspections or to assume that every record held in each facility was damaged. The regulatory findings concern the HSE’s management, security and retention practices as well as the conditions inspectors physically observed.
Similarly, the public information available today does not establish that confidential information from every compromised file was actually read or subsequently misused by third parties. The regulatory issue is broader: once unauthorised access becomes possible, the organisation has already lost the level of control expected over sensitive medical information.
Important distinction: The DPC has confirmed serious storage failures and unauthorised access incidents, but today’s announcement does not provide a definitive number of affected patients, individual records or files permanently destroyed. Those figures should not be invented or extrapolated from the inspection findings.
The Risk Was Not Merely That Someone Might Read the Records
DPC Deputy Commissioner Graham Doyle identified two different forms of risk. Insecure retention creates the possibility that sensitive medical information can be accessed or disclosed to third parties without authority. But there is also a different danger: the information may no longer be available when legitimately required for medical, legal or regulatory purposes.
This is especially important for healthcare records because destruction can itself become harmful. Medical histories may be needed to establish previous diagnoses, treatments, allergies, investigations or clinical decisions. Historical files can also become important when patients seek access to their own information or when past healthcare is examined through legal proceedings, inquiries or regulatory processes.
Not every historic record must be retained permanently. Indeed, one of the HSE’s breaches was precisely that records were held beyond the period for which they were necessary. Good records management therefore requires two apparently opposite actions at the correct time: preserving information securely while there is a legitimate reason to keep it, and destroying it securely once that reason expires.
Keeping everything forever is not a substitute for having a retention system. It can create enormous unmanaged archives whose contents become progressively harder to locate and protect.
The HSE Already Had Rules Requiring Old Records to Be Managed
The findings are particularly significant because the HSE does have formal policies governing record retention. Its current National Records Retention Policy took effect on 1 December 2025 and explicitly incorporates the GDPR principle of storage limitation.
The policy states that records must be managed according to defined retention periods and that responsibility extends to old files held in locations that may no longer be in use. Physical and digital records are both covered.
Different records can legitimately have very different retention periods. Medical, operational, financial and legal requirements can justify keeping information for substantial periods. The central principle is not rapid destruction but controlled retention for a defined reason.
The HSE’s own policy also acknowledges the risk produced by excessive retention. Information kept beyond the required period can become irrelevant, inaccurate, unnecessary or vulnerable to a breach.
The problem identified by the DPC was therefore not simply the absence of written rules. It was the failure to ensure that the practical management of paper archives across the organisation consistently produced the security, traceability and retention control those rules require.
Internal HSE Records Show the Problem Was Already Being Addressed Before Today’s Fine
The HSE’s Audit and Risk Committee was discussing implementation of healthcare records-retention policy before the DPC’s final decision. Minutes from April 2024 recorded that bringing all areas into compliance would require considerable effort and was expected to take at least two years.
By November 2025, data protection was listed among the HSE’s corporate risks and the committee had been briefed about the impending DPC inquiry report concerning paper-record storage and retention.
Minutes from a meeting in April 2026 show that the committee had been advised of significant failures identified in the statutory inquiry. The HSE had established a Records Management Programme intended to develop and oversee a more compliant approach to its records.
This timeline is important when assessing the organisation’s response. The corrective work did not begin this morning when the €645,000 fine became public. The HSE had already begun introducing a national records-management programme and updating retention policy while the regulatory process was continuing.
That does not remove responsibility for the underlying breaches. It does mean the question now becomes whether the reforms already under way are sufficiently comprehensive to satisfy the orders the DPC has formally imposed.
The DPC Has Ordered a Nationwide Audit
The most consequential requirement is a complete audit of locations where the HSE retains paper files. The organisation must establish a reliable inventory and tracking system capable of recording and tracing personal data stored in its facilities.
Records that are no longer necessary for the purposes for which they were retained must be safely destroyed. This means disposal cannot consist simply of clearing buildings or placing unwanted files in ordinary waste streams. Confidential medical records require controlled destruction.
The HSE must also examine whether each physical storage facility is actually fit for purpose. Locations that cannot maintain the integrity, availability and confidentiality of personal information cannot continue being used merely because they already contain boxes of documents.
Where a facility is unsuitable, paper records containing personal data must be removed and transferred to appropriate storage. The HSE must additionally introduce regular testing and assessment of storage locations rather than relying on a one-off clean-up following the investigation.
That requirement attempts to address one of the underlying governance risks exposed by the case. A storage room can be secure and dry when files first arrive but become unsuitable years later through water ingress, structural decay, pest problems, loss of heating or abandonment of the wider building. Record security therefore requires continuing oversight.
What the HSE Must Now Do
| Corrective Measure | Purpose |
|---|---|
| Audit all paper-record storage | Identify what exists and where |
| Assess every facility | Confirm it is fit for purpose |
| Remove records from unsuitable sites | Protect confidentiality and integrity |
| Create tracking and tracing systems | Make records locatable |
| Destroy unnecessary records safely | Meet storage-limitation rules |
| Regularly reassess storage | Prevent the problem recurring |
Source: Data Protection Commission corrective orders announced 2 September 2026.
The HSE Has Accepted the Findings and Apologised
The HSE said it accepts the findings of the regulator and will comply with the recommendations and orders. It apologised to patients and people using its services for the breaches at St Loman’s and St Conal’s and for failures to comply with paper-record retention and management policies.
Both former hospitals had ceased clinical activity but continued operating as storage locations. Following the breaches, the HSE says it strengthened security, assessed the condition of records and began destroying or relocating material where appropriate.
Work remains under way. The organisation says creating a consistent and standardised national approach to archiving and disposal is a priority.
That response identifies one of the institutional problems that can emerge inside a health service of the HSE’s size. Records may originate in hospitals and services established long before modern data-protection systems, while buildings change function, services are reorganised and responsibility for historical archives can become fragmented.
A national system requires somebody to retain ownership of the information even after the clinic, ward or hospital that originally created it has closed. Without clear responsibility, yesterday’s active medical file can become tomorrow’s anonymous box in an unused building.
This Is Not the First Time the HSE Has Lost Control of Paper Health Records
The DPC explicitly treated previous similar infringements as an aggravating factor when calculating the new penalties. That history is important because the current case cannot be understood purely as an unprecedented discovery in two old psychiatric hospitals.
In a decision dating from 2020, the regulator investigated an HSE breach involving documentation containing personal data relating to 78 individuals that was discovered at a public recycling centre in County Cork. Six of the records included special-category information.
A separate inquiry concerned documents relating to 15 people that originated at Our Lady of Lourdes Hospital but were discovered by a member of the public in a front garden. The papers included clinical and treatment information.
The DPC concluded in those cases that the HSE had failed to implement adequate measures governing the use and disposal of hard-copy patient documents. One of the decisions resulted in a €65,000 fine and an order requiring improved compliance.
The circumstances differ significantly from the current investigation. A document discarded into a recycling system is not the same as a historical archive deteriorating inside a disused building. The common element is loss of effective control over physical healthcare information.
That similarity explains why previous enforcement mattered to the current penalty. From a regulator’s perspective, recurrence after an organisation has already been formally told that hard-copy records require stronger safeguards is more serious than an entirely novel failure.
Another HSE Data-Protection Fine Was Issued Only in June
The paper-record investigation also arrives shortly after a separate DPC decision concerning digital health information. In June 2026, the regulator fined the HSE €300,000 following an investigation into a ransomware attack affecting the laboratory information system at Midlands Regional Hospital Tullamore.
The attack itself dated to November 2018. The DPC said approximately 84,000 people may have been affected, although investigators found no clear evidence that attackers had removed clinical information and could not exclude that possibility.
The Tullamore inquiry found failures involving security measures, processor agreements, records of processing activity and information provided to people affected by the breach.
The two decisions concern very different technologies and circumstances and should not be conflated. One involved a cyberattack against a laboratory system; the other concerns physical paper archives. Together, however, they demonstrate the breadth of the information-governance challenge facing a health service that simultaneously operates legacy paper systems and increasingly interconnected digital infrastructure.
The two 2026 decisions have imposed a combined €945,000 in administrative fines on the HSE within less than three months. The larger significance lies in the accompanying corrective requirements rather than the arithmetic alone.
Public Trust Is Especially Important When the Information Is Medical
Healthcare requires patients to disclose information they would often share with almost nobody else. A clinician may need information about mental health, medication, family circumstances, addiction, sexual health, previous trauma or chronic disease in order to provide appropriate treatment.
The patient cannot realistically negotiate how a national health service stores each page of that information. The relationship therefore depends heavily on institutional trust: once information is provided for healthcare, the organisation controlling it is expected to protect it throughout its lifecycle.
Failures involving historical records can be particularly damaging to that trust because the affected patient may have had no reason to know their file still existed or where it had been moved decades after treatment.
Good records management therefore has a public-service dimension beyond regulatory compliance. People need confidence that information will be available to legitimate healthcare professionals when required while remaining inaccessible to everyone else.
Ireland Is Digitising Healthcare While Still Managing a Vast Paper Legacy
The timing of the decision is significant because Ireland is simultaneously embarking on the largest digital transformation in the history of its public health service.
The Government approved procurement of a National Electronic Health Record in February 2026. The long-term objective is a secure integrated electronic record available across publicly funded hospitals and community services.
The National Shared Care Record is already being expanded. By summer 2026, authorised healthcare professionals could use it to view information including medications, GP-requested laboratory and radiology results, discharge summaries, hospital appointments, waiting-list information, referrals and vaccination records drawn from different underlying systems.
Digitisation can reduce some risks associated with moving and storing paper files. Electronic information can be backed up, searched, audited and made available to authorised clinicians without physically transporting a chart from one building to another.
It does not remove the need for records governance. Digital records introduce different risks including cyberattack, inappropriate access, incorrect permissions, data corruption and system failure. The €300,000 Tullamore ransomware decision provides an obvious example.
Nor can a new electronic system simply make Ireland’s paper heritage disappear. Existing archives must still be examined, retained where legally or clinically necessary, preserved when they possess historical value and securely destroyed when their legitimate retention periods have ended.
Scanning Everything Would Not Automatically Solve the Problem
A superficial response to deteriorating paper archives might be to digitise every surviving document. That could improve accessibility in appropriate cases, but indiscriminate scanning would reproduce another part of the problem in electronic form.
Before old records are migrated, the HSE still needs to know what they are, whether they need to be retained, how long they must remain identifiable and who should be allowed to access them. Digitising information that should already have been securely destroyed would extend rather than correct excessive retention.
Quality also matters. A badly damaged page may be impossible to scan accurately. A digital image without sufficient indexing may technically exist while remaining almost impossible for authorised staff to locate.
Effective migration therefore requires classification, retention decisions, metadata, quality control and secure disposal of the original where appropriate. Technology is a tool for executing records policy rather than a replacement for having one.
Historical Psychiatric Records Create Additional Complexity
Former psychiatric institutions illustrate one of the hardest parts of health-record management. Some records may no longer be required for active clinical care yet may retain legal, administrative or historical importance.
Ireland’s institutional healthcare history also means some archives can have significance beyond the treatment of one individual. Historical records can become relevant to research, inquiries, family history or understanding how institutions operated.
That does not mean all old patient files should simply be preserved indefinitely. Archival preservation and data protection have to operate together, balancing legitimate historical value against individuals’ privacy rights and statutory retention requirements.
The HSE has been developing policies concerning archival preservation as part of its wider records-management programme. Today’s decision increases the urgency of completing a consistent system capable of distinguishing material that should be protected as an archive from information that should be securely destroyed.
The Financial Penalty Is Only a Small Part of the Likely Cost
The €645,000 fine is the most visible number in the DPC announcement, but achieving compliance will require expenditure well beyond the administrative penalty.
A national audit means locating storage rooms and facilities throughout a health organisation operating across hundreds of properties. Records have to be inventoried, assessed and moved where necessary. Suitable archive space requires environmental control, physical security and ongoing monitoring.
Files reaching the end of their lawful retention period have to be destroyed securely. Records that remain necessary need indexing and systems capable of showing where they are.
Staff require training and responsibility has to be assigned clearly enough that an archive does not again become institutionally orphaned when a service closes or moves.
The eventual cost cannot be calculated from today’s information, and the HSE has not published a complete estimate associated with the DPC orders. What is clear is that the organisational remediation will be substantially more complex than simply paying a fine.
The Decision Raises a Wider Question About Public-Sector Estates
The case also illustrates how data governance can become entangled with management of old public buildings. A former hospital may no longer have clinical value but can continue containing equipment, documents and infrastructure accumulated over decades.
Closing a facility therefore does not end every responsibility attached to it. Records need to be removed or formally transferred, confidential material destroyed appropriately and physical access controlled until sensitive contents have been cleared.
Buildings contaminated by asbestos or severe mould make this process more difficult because staff cannot necessarily enter and remove documents using normal working procedures. Specialist safety measures may be required, increasing cost and delaying remediation.
None of these practical difficulties remove the HSE’s responsibility as data controller. They do help explain why legacy estates can become a governance problem spanning property management, occupational safety, healthcare administration and data protection simultaneously.
Better Governance Means Knowing When a Record Should Cease to Exist
One of the most important findings in the decision may receive less attention than the photographs and descriptions of damaged documents. Half of the €645,000 penalty — €300,000 — relates specifically to the GDPR storage-limitation principle.
Keeping records longer than necessary is often treated as cautious administration. Organisations fear deleting something that might later be needed, so the apparent low-risk decision is to retain everything.
At large scale, that logic creates precisely the opposite outcome. Archives expand faster than they can be managed. Storage costs increase, catalogues become unreliable and every unnecessary record creates another opportunity for accidental disclosure or destruction.
A mature records system therefore requires the confidence to delete information as well as the ability to preserve it. Retention schedules establish when that point arrives, while exceptions can preserve records when clinical, statutory, legal or archival reasons justify longer storage.
Accountability Cannot End With a One-Off Clean-Up
The DPC’s requirement for continuing assessment is designed to prevent today’s remediation programme from becoming another temporary response. Moving boxes from a mouldy room into a dry building solves the immediate environmental risk but does not establish a sustainable records system.
Each stored record needs ownership, a known location and a retention status. Buildings need periodic inspection. Local services need mechanisms for transferring archives when they relocate or close.
Governance also requires escalation when policy cannot be followed. The HSE’s current retention guidance instructs services unable to comply with the policy to seek support rather than simply leaving records unmanaged.
The practical test of reform will therefore come years after the current media attention has disappeared. Success means that a future abandoned hospital or closed community facility does not still contain forgotten boxes of identifiable patient information.
What Patients Can Reasonably Expect From the HSE Now
The first expectation is implementation of the DPC orders. The HSE has accepted the findings and says it will comply, removing records from unsuitable sites and developing a nationally standardised approach to archiving and disposal.
The second is greater visibility over the scale of the problem. Once the complete audit is undertaken, the health service should have a much clearer understanding of the number and condition of external paper-record repositories.
The third is reliable communication where an individual is materially affected by a high-risk personal-data breach. One of the current infringements involved precisely the failure to communicate breaches to affected people as required by GDPR.
The fourth is integration of legacy records management with the wider digital transformation. Building a national electronic health record while unmanaged paper archives remain scattered through unsuitable facilities would create two parallel information systems with very different levels of control.
This Is a Public-Administration Failure With Clinical Consequences
The conditions described by investigators can easily be presented as a story about bureaucratic neglect. That description captures only part of the problem.
Records management is administrative infrastructure, but in healthcare that infrastructure supports clinical care. A laboratory result, psychiatric history, operative note or medication record can have continuing relevance beyond the administrative process that created it.
Patients rarely see this infrastructure when it works. Files are created, information moves between authorised professionals, retention periods pass and records are eventually archived or destroyed. The system becomes visible only when something fails.
The DPC investigation has made that normally invisible infrastructure unusually visible: a shipping container in a turf shed, files in disused bathrooms, records damaged by mould and intruders able to enter abandoned hospitals where confidential documents remained.
The €645,000 Fine Is Ultimately a Warning About Control
The underlying issue in the DPC decision is not paper itself. Well-managed paper records can comply with data-protection law. Nor is digitisation automatically compliant simply because information is held on a computer.
The central requirement is control. The HSE must know what personal information it holds, why it still holds it, where it is located, whether it remains usable, who can access it and when it should be destroyed.
The two abandoned psychiatric hospitals revealed situations in which that control had broken down. The twelve-site inspection programme then uncovered broader deficiencies in storage conditions and the integrity of records.
The regulator’s response reflects that wider problem. The HSE has not simply been ordered to secure St Loman’s and St Conal’s. It has been ordered to examine its entire network of paper-record storage facilities and establish systems capable of preventing a recurrence.
That is the most important consequence of today’s decision. A €645,000 penalty is substantial and, according to RTÉ, is the largest fine the DPC has imposed on an Irish public body. But the deeper test will be whether Ireland’s largest public organisation can account reliably for the medical information accumulated across decades of healthcare delivery.
As the country moves towards a national electronic health record, the condition of its old paper archives may look like a problem belonging to another era. The DPC’s investigation demonstrates the opposite. Until every record is either securely managed, legitimately archived or properly destroyed, the legacy system remains part of Ireland’s modern healthcare infrastructure — and part of its responsibility to the patients whose lives those records document.
Sources
RTÉ — HSE Fined €645,000 Over Paper Medical Records, 2 September 2026
Data Protection Commission — Launch of HSE Paper Records Inquiry, May 2024
Data Protection Commission — Previous HSE Hard-Copy Records Inquiries
Data Protection Commission — Midlands Regional Hospital Tullamore Decision, June 2026
Health Service Executive — Records Retention Policy
Health Service Executive — National Records Retention Policy, Effective December 2025
Health Service Executive — Records Management Programme
Health Service Executive — Audit and Risk Committee Minutes, April 2026
Health Service Executive — Audit and Risk Committee Records-Retention Update, April 2024
Health Service Executive — Personal Data Breach Guidance
Department of Health — National Electronic Health Record Procurement, February 2026
Health Service Executive — National Shared Care Record Expansion, June 2026
Source & Transparency
This article is published by Ireland Newspaper for editorial and informational purposes.
Published: 2 September 2026 · Updated: 2 September 2026







