Ireland’s Data Protection Commission (DPC) fined the Health Service Executive (HSE) €645,000 after unauthorised individuals accessed paper medical records stored at the disused St. Loman’s Hospital in Mullingar and St. Conal’s Hospital in Letterkenny. The investigation began after the HSE reported two breaches in October and November 2023; videos posted to social media by intruders revealed the records held at the sites.
The DPC found that the HSE failed to provide adequate physical security for external document-storage facilities and to preserve the integrity of the archived records. Alongside the financial penalty, imposed on 28 August 2026, the regulator issued a reprimand and ordered the HSE to implement compliance measures and communicate details of the breaches as required.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
The DPC issued its final decision, finding failures in the physical security and document integrity of HSE storage facilities, including St. Loman's Hospital in Mullingar and St. Conal's Hospital in Letterkenny. It imposed €645,000 in fines, issued a reprimand and compliance orders, and required the HSE to notify affected data subjects of the breaches.
Ireland's Data Protection Commission commenced an inquiry into the HSE's handling of personal data in paper records stored at external facilities, following the two breach notifications.
The HSE submitted a second personal-data-breach notification concerning unauthorised access to paper medical records at its external storage locations.
The Health Service Executive submitted a personal-data-breach notification concerning unauthorised access to paper medical records held at a disused former psychiatric hospital.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceedpb.europa.eu
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.