Health Service Executive (HSE) – Violation Found (Ireland, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Health Service Executive (HSE) faced scrutiny after a ransomware attack compromised personal data of around 84,000 individuals. This incident matters because it underscores the need for strong cybersecurity measures to protect sensitive health information.
What happened
A ransomware attack on HSE's systems potentially exposed personal health data of approximately 84,000 individuals.
Who was affected
Patients whose health information was stored in the compromised systems of the Health Service Executive.
What the authority found
The Data Protection Commission found that HSE did not adequately secure its systems, leading to the data breach.
Why this matters
This case emphasizes the importance of robust cybersecurity practices for organizations handling sensitive personal data, particularly in the healthcare sector.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
On 14 November 2018, a ransomware attack affected the Laboratory Information System (LIS) of the Midland Regional Hospital Tullamore, which formed part of the Health Service Executive (HSE), the controller. The attack caused the LIS database server to go offline and encrypted data stored on several devices, including backup devices connected to the affected servers. The attackers accessed the system through an unsecured firewall port and exploited a weak administrator password. The forensic investigation could not conclusively rule out that personal data had been viewed or exfiltrated. Moreover, electronic records created between June 2017 and November 2018 could not be recovered. The affected information included identifying and contact data as well as clinical information and test results, constituting health data. The controller initially estimated that 50,000 data subjects were affected but subsequently increased this figure to approximately 84,000. On 16 November 2018, the controller notified the personal data breach to the DPA. It classified the breach as presenting a medium risk and therefore did not individually notify the affected data subjects. Instead, information about the incident was provided through public communications. On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the controller had complied with its obligations under the GDPR in relation to the security of the LIS, its arrangements with processors, its records of processing activities and its response to the personal data breach. The DPA found that the controller infringed Articles 5(1)(f) and 32(1) GDPR because it had failed to implement technical and organisational measures appropriate to the high risks associated with processing large quantities of health data. In particular, the DPA identified several security deficiencies, including an unsecured remote-access port without multi-factor authentication, a weak administrator password, ineffective intrusion de
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for Health Service Executive (HSE) in IE
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Health Service Executive (HSE) - Ireland (2026). Retrieved from cookiefines.eu
Last updated: