DPC (Ireland) - IN-19-9-4
| DPC - IN-19-9-4 | |
|---|---|
| Authority: | DPC (Ireland) |
| Jurisdiction: | Ireland |
| Relevant Law: | Article 5(1)(f) GDPR Article 28 GDPR Article 30 GDPR Article 32(1) GDPR Article 34 GDPR |
| Type: | Investigation |
| Outcome: | n/a |
| Started: | 08.10.2019 |
| Decided: | 10.06.2026 |
| Published: | |
| Fine: | n/a |
| Parties: | Health Service Executive (HSE) |
| National Case Number/Name: | IN-19-9-4 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | English |
| Original Source: | DPC (in EN) |
| Initial Contributor: | bms |
The DPA fined a provider of a hospital €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.
English Summary
Facts
On 14 November 2018, a ransomware attack affected the Laboratory Information System (LIS) of the Midland Regional Hospital Tullamore, which formed part of the Health Service Executive (HSE), the controller. The attack caused the LIS database server to go offline and encrypted data stored on several devices, including backup devices connected to the affected servers.
The attackers accessed the system through an unsecured firewall port and exploited a weak administrator password. The forensic investigation could not conclusively rule out that personal data had been viewed or exfiltrated. Moreover, electronic records created between June 2017 and November 2018 could not be recovered.
The affected information included identifying and contact data as well as clinical information and test results, constituting health data. The controller initially estimated that 50,000 data subjects were affected but subsequently increased this figure to approximately 84,000.
On 16 November 2018, the controller notified the personal data breach to the DPA. It classified the breach as presenting a medium risk and therefore did not individually notify the affected data subjects. Instead, information about the incident was provided through public communications.
On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the controller had complied with its obligations under the GDPR in relation to the security of the LIS, its arrangements with processors, its records of processing activities and its response to the personal data breach.
Holding
The DPA found that the controller infringed Articles 5(1)(f) and 32(1) GDPR because it had failed to implement technical and organisational measures appropriate to the high risks associated with processing large quantities of health data.
In particular, the DPA identified several security deficiencies, including an unsecured remote-access port without multi-factor authentication, a weak administrator password, ineffective intrusion detection and prevention, outdated anti-virus protection, a device running an unsupported operating system, a lack of encryption at rest, insufficient vulnerability and penetration testing, inadequate network segmentation and backup systems that were not sufficiently separated from the affected network. The DPA also noted a lack of effective centralised security oversight. These deficiencies allowed the attackers to access the LIS and move laterally across the network.
The DPA also found a violation of Articles 28(1), 28(3) and 28(9) GDPR. Two external companies maintained the infrastructure and software used by the LIS and qualified as processors. However, the agreements governing these relationships did not provide sufficient guarantees regarding data protection and security and did not contain the mandatory provisions required under Article 28 GDPR.
Furthermore, the DPA found a violation of Article 30(1) GDPR because the controller did not have a compliant record of processing activities in place at the time of the breach. Although certain documentation existed in draft form, it did not contain all required information, including the contact details of the DPO, retention periods and categories of recipients.
Finally, the DPA held that the controller infringed Article 34 GDPR. Considering the sensitive nature of the health data, the number of affected data subjects and the possibility that data had been accessed or exfiltrated, the breach should have been classified as presenting a high risk to the rights and freedoms of approximately 84,000 data subjects. Although the DPA accepted that individual communication would have involved disproportionate effort and that a public communication could therefore be used, the controller's public communications were incomplete. In particular, they did not inform data subjects that some personal data had been irrecoverably lost, that access to or exfiltration of data could not be ruled out, or provide the contact details of the DPO.
The DPA imposed an administrative fine of €300,000 for the infringements of Articles 5(1)(f) and 32(1) GDPR. It also reprimanded the controller for all identified infringements and ordered it to bring its processing into compliance with Articles 5(1)(f) and 32(1) GDPR.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the English original. Please refer to the English original for more details.
In the matter of the General Data Protection Regulation
DPC Case Reference: IN-19-9-4
In the matter of Health Service Executive
Decision of the Data Protection Commission under Section 111 of the Data Protection Act
2018
Further to an own-volition inquiry under Section 110 of the Data Protection Act 2018
DECISION
Decision-Maker for the Data Protection Commission:
Dr Des Hogan, Commissioner for Data Protection and
Mr Dale Sunderland, Commissioner for Data Protection.
10 June 2026
Data Protection Commission
6 Pembroke Row
Dublin 2, Ireland
1Contents
Contents..................................................................................................................................................2
A. Introduction....................................................................................................................................4
B. Personal data breaches...................................................................................................................5
a) Data controller......................................................................................................................6
C. Legal Framework for the Inquiry and the Decision.........................................................................7
a) Legal basis for the Inquiry.....................................................................................................7
b) Legal basis for the Decision...................................................................................................7
D. Factual Background and Material Considered for the Purposes of this Decision ..........................7
a) Controller overview ..............................................................................................................7
b) Impact of the breach.............................................................................................................8
c) Breach response....................................................................................................................9
d) Inquiry IN-19-9-4.................................................................................................................10
E. Scope of the Inquiry......................................................................................................................10
F. Issues for Determination...............................................................................................................11
G. Issue 1: Whether the HSE Infringed Articles 5(1)(f) and 32(1) in Relation to Patient Personal Data
during the Temporal Scope...................................................................................................................12
a) Assessing risk ......................................................................................................................12
b) Likelihood of risk.................................................................................................................13
c) Severity of risk.....................................................................................................................14
d) Technical and organisational security measures implemented by the HSE.......................15
e) Assessment of technical and organisational measures for security...................................18
H. Issue 2: Whether the HSE Infringed Article 28 GDPR in Relation to the Patient Personal Data
During the Temporal Scope..................................................................................................................20
a) The Infrastructure Provider ................................................................................................21
b) The Software Provider........................................................................................................24
c) Assessment.........................................................................................................................25
I. Issue 3: Whether the HSE Infringed Article 30 GDPR in Relation to Patient Personal Data During
the Temporal Scope..............................................................................................................................25
J. Issue 4: Whether the HSE Infringed Article 34 GDPR in Relation to Patient Personal Data During
the Temporal Scope..............................................................................................................................26
a) Analysis of whether the HSE’s risk assessment was appropriate in the circumstances of
the breach.......................................................................................................................................28
i. Nature of risks................................................................................................................28
ii. Post-incident testing and risk analysis...........................................................................32
b) Summary and conclusion on risks arising from these measures........................................36
c) Assessment of the HSE’s Media Communication...............................................................40
d) Conclusion on Issue 4:.........................................................................................................43
K. Decision on Corrective Powers.....................................................................................................43
L. Order for Compliance ...................................................................................................................44
M. Reprimand.....................................................................................................................................45
N. Decision on Administrative Fines..................................................................................................46
a) Whether to impose an administrative fine.........................................................................47
2 i. Article 83(2)(a) GDPR:....................................................................................................48
ii. Article 83(2)(b) GDPR:....................................................................................................57
iii. Article 83(2)(c) GDPR:....................................................................................................59
iv. Article 83(2)(d) GDPR:....................................................................................................60
v. Article 83(2)(e) GDPR:....................................................................................................61
vi. Article 83(2)(f) GDPR:.....................................................................................................62
vii. Article 83(2)(g) GDPR:....................................................................................................62
viii. Article 83(2)(h) GDPR:....................................................................................................63
ix. Article 83(2)(i) GDPR:.....................................................................................................63
x. Article 83(2)(j) GDPR:.....................................................................................................64
xi. Article 83(2)(k) GDPR:....................................................................................................64
xii. Decision as to whether to impose a fine.......................................................................64
b) Decision on the amount of the administrative fine............................................................66
i. Article 83(3) GDPR.........................................................................................................66
ii. Categorisation of the infringements under Articles 83(4)-(6) GDPR.............................67
iii. Seriousness of the infringement pursuant to Articles 83(2)(a), (b) and (g) GDPR.........68
iv. Imposing an effective, dissuasive and proportionate fine ............................................68
v. Aggravating and mitigating circumstances....................................................................68
vi. The relevant legal maximums for the different processing operations........................70
vii. Article 83(1) GDPR: Effectiveness, proportionality and dissuasiveness........................70
O. Summary of Envisaged Action ......................................................................................................72
P. Right of Appeal..............................................................................................................................72
3A. Introduction
1. This document (‘the Decision’) is a decision made by the Data Protection Commission
(‘the DPC’) in accordance with section 111 of the Data Protection Act 2018 (‘the 2018
Act’). The DPC makes this Decision having considered the information obtained in the
separate own-volition inquiry (‘the Inquiry’) conducted by authorised officers of the
DPC (‘the Inquiry Team’) pursuant to section 110 of the 2018 Act.
2. Referenceto ‘the GDPR’in thisDecision isto Regulation (EU) 2016/679 of the European
Parliament and ofthe Council of 27 April2016onthe protectionof naturalpersonswith
regard to the processing of personal data and on the free movement of such data, and
repealing Directive 95/46/EC.
3. The GDPR elaborates on the indivisible, universal values of human dignity, freedom,
equality and solidarity as enshrined in the Charter of Fundamental Rights of the EU and
Article 8 in particular, which safeguards the protection of personal data. Article 8 of the
Charter provides:
1. Everyone has the right to the protection of personal data concerning him or
her.
2. Such data must be processed fairly for specified purposes and on the basis
of the consent of the person concerned or some other legitimate basis laid
down by law. Everyone has the right of access to data which has been
collected concerning him or her, and the right to have it rectified.
3. Compliance with these rules shall be subject to control by an independent
authority.
4. This Decision considers particular aspects of this fundamental right in relation to the
securityofprocessing and compliancewithresponsibilitiesarising whenapersonaldata
breach has occurred.
5. This Decision is provided to the Health Service Executive (‘the HSE’) pursuant to section
116(1)(a) of the 2018 Act, in order to give notice of the Decision and the reasons for it,
and of the DPC’s decision in relation to the powers exercised pursuant to Article 58
GDPR.
6. This Decision contains corrective powers under section 115 of the 2018 Act and Article
58(2) GDPR arising from the infringements identified herein. It should be noted in this
regard that the HSE is required to comply with the corrective powers that are exercised
in this Decision, and it is open to the DPC to serve an enforcement notice on HSE in
accordance with section 133 of the 2018 Act.
4B. Personal data breaches
7. On 16 November 2018, the DPC received a personal data breach notification from the
1
HSE. The breach was stated to have occurred in the Laboratory Information System
(‘LIS’) of the Midland Regional Hospital Tullamore (‘MRHT’).
8. The HSE stated that the LIS and the associated backup systems at the MRHT had been
subjectedto asuccessfulcyber-ransomware attackon 14November2018whichcaused
the LIS database server to go offline. The HSE estimated that the breach occurred at
07:29 hours. This triggered a service alert which was reported by their outsourced
provider at 08:48 hourstotheSeniorMedicalScientistwith responsibilityfor IT.The call
indicated that a ransomware attack was in progress. The breach notification also stated
that the backup devices for the affected servers were connected to the servers and
therefore exploited by the attack. The HSE stated in the breach notificationthat an off-
site backup was available at the , but that
this was incomplete. In correspondence on 4 December 2020, the HSE clarified that a
full recording of backup data had been created, but that records created between June
2017 and November 2018 had been encrypted during the attack and were not
recoverable. The HSE added that paper records of the data in question were available. 5
9. The HSE immediately investigated the incident internally and also engaged with an
external resource (‘External Cybersecurity Consultancy’), to carry out an analysis of the
incident and identify the source and scope of the breach. The External Cybersecurity
Consultancy produced its Forensic Analysis Report to the HSE on 6 December 2018.
10. The ExternalCybersecurity Consultancyforensic report concludedthaton14 November
2018, a bad actor gained access to the LIS environment by means of an unsecured
firewall port, exploited a weak administrator password on a server and was able to
access other devices on the system. According to the report, a variant of the CrySIS
ransomwarewasdeployed, resultinginthe encryption ofdata onseveraldevices on the
LIS.
1 Breach Notification Form, 16 November 2018.
2
3 Breach Notification Form, 16 November 2018, 2.
4 Breach Notification Form, 16 November 2018, 5.
Breach Notification Form, 16 November 2018, 6.
5 HSE letter to DPC, 4 December 2020, 13.
511. The report concluded that large-scale data exfiltration was unlikely, but it could not
conclusively rule out selective records being extracted due to lack of available
information. The report was also unable to conclusively state if personal data was
6
viewed by the attackers, also due to a lack of available information.
12. Article 4(12) GDPR defines ‘personal data breach’ as
a breach of security leading to the accidental or unlawful destruction, loss,
alteration, unauthorised disclosure of, or access to, personal data transmitted,
stored or otherwise processed;
13. Based on the information provided by the HSE in its breach notification and otherwise
during the course of this inquiry, the DPC is satisfied that:
the information affected by the incident notified by the HSE on 16
November 2018 was personal data processed by the HSE,
the incident arose of from a breach of security, and
theincidentledtooneormoreunauthorisedpersonshavingaccesstothat
personal data, allowing them to alter it by way of encryption.
The DPC is therefore satisfied that the incident constitutes a personal data breach
according to the definition in Article 4(12) GDPR.
a) Data controller
14. In commencing the Inquiry, the DPC considered that the HSE determined the purposes
and means of processing the personal data that was the subject of the personal data
concernedinthebreachnotificationmadebytheHSEtotheDPCon16November2018,
and so was the controller, within the meaning of Article 4(7) GDPR, in respect of that
personal data. In this regard, the HSE confirmed in its notification of the personal data
breach to the DPC that it was the controller in respect of tests received from within
Tullamore Hospital, as well as being a processor on behalf of tests received from GPs in
7
the region.
15. The DPC is satisfied that it is the competent supervisory authority to perform the tasks
assigned to it under the GDPR pursuant to Article 55(1) of the GDPR in respect of the
HSE’s compliance with its obligations under the GDPR.
6 External Cybersecurity Consultancy - Forensic Analysis Report, 4.
7 HSE Update Report BN-18-11-244, 30 November 2018, 5.
6C. Legal Framework for the Inquiry and the Decision
a) Legal basis for the inquiry
16. The GDPR is the legal regime covering the processing of personal data in the European
Union (‘EU’). The GDPR is directly applicable in EU member states. The GDPR is given
further effect in Irish law by the 2018 Act. As stated above, the Inquiry was commenced
pursuanttosection110of the2018Act.Bywayof background,underPart6 ofthe 2018
Act, the DPC has the power to commence an inquiry on several bases, including on foot
of a complaint, or of its own volition.
17. Section 110(1) of the 2018 Act provides that the DPC may, for the purpose of section
109(5)(e) or section 113(2) of the 2018 Act, or of its own volition, cause such inquiry as
itthinksfittobe conducted, inordertoascertainwhetheraninfringementhasoccurred
or is occurring of the GDPR or a provision of the 2018 Act, or regulation under the Act,
that gives further effect to the GDPR. Section 110(2) of the 2018 Act provides that the
DPC may, for the purposes of section 110(1), where it considers it appropriate to do so,
cause anyof itspowers under Chapter 4 of Part 6 of the 2018 Act (excluding section 135
of the 2018 Act) to be exercised and/or cause an investigation under Chapter 5 of Part
6 of the 2018 Act to be carried out.
b) Legal basis for the Decision
18. The decision-making process for the Inquiry is provided for under section 111 of the
2018Act,and requiresthe DPC toconsiderthe informationobtainedduring the Inquiry;
to decide whether an infringement is occurring or has occurred; and if so, to decide on
the corrective powers, if any, to be exercised. In making this Decision, the DPC has
carried out an independent assessment of all the materials provided by the Inquiry
Team, of any other materials that have been furnished by the HSE, and any other
materials that the DPC considers to be relevant.
19. Having considered all of the information obtained in this Inquiry, the DPC is satisfied
that the Inquiry was correctly conducted and that fair procedures were followed
throughout. The DPC has had regard to submissions made by the HSE in respect of the
draft version of this Decision (‘the Draft Decision’) sent to the HSE on 1 December 2025
before proceeding to make this final Decision under section 111 of the 2018 Act.
D.Factual Background and Material Considered for the Purposes of this Decision
a) Controller overview
20. The HSE was established by the Health Act 2004 to act as a single body with statutory
responsibilityforthe management and delivery of health and personalsocial servicesto
the population of Ireland.
721. Section 7(1) of the Health Act 2004 states that the object of the HSE is ‘to use the
resources available to it in the most beneficial, effective and efficient manner to
improve, promote and protect the health and welfare of the public.’
22. Nationally,HSEhospitalswereorganisedintosevenhospitalgroups.TheMRHTwaspart
of the Dublin Midlands Hospital Group, an organisational division of the HSE.
23. The MRHT provides acute-care hospital services including a 24-hour emergency
department and is the regional centre for Orthopaedics, Otolaryngology, Oncology,
Haematology, Nephrology and Rheumatology.
24. The Pathology Department at MRHT provides a clinical diagnostic laboratory service for
MRHT’s Biochemistry, Haematology/Coagulation, Immunology, Endocrinology Blood
Transfusion and Microbiology Departments. It also supports some Cellular Pathology
services.
25. According to the HSE, it acts as a controller for any tests received from within the
hospital and as a processor for any tests received from general practitioners.
26. The LIS is an information processing system for clinical tests and results that was
developed in MRHT in the 1990s and extended to cover other hospitals in the Dublin
Midland Hospital Group in the early 2000s. The LIS records and retains information in
relation to diagnostic test requests. This information includes: patient name, patient
address, patient ID, patient DOB, sex, clinical details (date/time of sample collection,
date/time of receipt in the laboratory and date/time of report, specimen type, priority,
results/reports, requesting clinician details) and a record of communications relating to
test results.
27. The DPC is satisfied that the personal data breach outlined in this Inquiry relates to the
processing of personal data in the context of the activities of the HSE, a public authority
established under the laws of Ireland. The breach is therefore properly a matter for
inquiry under the GDPR.
b) Impact of the breach
28. The HSE initially indicated that approximately 50,000 data subjects might have been
affected by the attack. In correspondence to the DPC on 30 November 2018, the HSE
increased this estimate to 84,000 data subjects after a gap in patient records spanning
September 2016to 12 November 2018 was discovered. However, the HSE maintained
8 HSE Update Report BN-18-11-244, 30 November 2018, 5.
9 HSE, ‘DPC Enquiry Consolidated responses’, 7 November 2019, 3.
10 Breach Notification Form, 16 November 2018, 4.
11 HSE Update Report BN-18-11-244, 30 November 2018, 6.
8 that, due to the existence of paper records of lab reports, there was no interruption to
12
patient care.
29. The HSE’s breach notification stated that the potential consequences of the breach for
affected individuals included a loss of control of their personal data and a lack of access
to it. It also made clearthat the ransomware prevented the staffofthe MRHTand other
users of the LIS from accessing patient records held on the system.
30. The breach notification identified that the following identifying details relating to
individuals were affected by the ransomware attack:
Data subject identity (name, surname, birth date)
Contact details.
31. The HSE also indicated that the attack impacted health data, a special category of data
under the GDPR.
32. In its breach notification, the HSE rated the risk level as ‘medium’ because, based on its
initial assessment, the affected data had been encrypted and the HSE did not have
evidence that it had been removed orfallen intounauthorisedhands. Onthat basis, the
HSE did not notify affected individuals.
c) Breach response
33. In correspondence with the DPC on 30 November 2018, the HSE said that it became
aware of the breach at 08:48 hours on 14 November 2018 when the outsourced
provider reported that the remote monitoring service had detected the attack on the
laboratory network. The HSE outlined its immediate incident response as follows:
MRHT engaged the ICT Business lead and HSE ICT to contain the issue and
take preventative actions against contagion of other sites. The firewall
connection between the labs and the HSE LAN was blocked and the
Tullamore Lab IT officer physically disconnected server equipment from
the network,
theLab ManagerandDeputyLabManagerwere informed ofthesituation,
LIS downtime contingency plans were activated,
theHospitalManagementTeamand serviceusers(in-patientlocations,GP
practices) were notified,
12
Breach Notification Form, 16 November 2018, 6.
9 an [outsourced provider] engineer arrived on site and advised on the
severity of the ransomware attack, and
plans to restore systems were put in place.13
d) Inquiry IN-19-9-4
34. The DPC issued the Commencement Letter for the Inquiry on 8 October 2019. This
informed the HSE that the DPC had commenced an Inquiry under the DPC reference IN-
19-9-4inaccordancewithsection110(1)ofthe2018Act. Theletterincludedquestions
withrequestsforclarificationanddocumentation.TheDPCreceivedaresponsetothese
on 7 November 2019. 15
35. Following subsequent queries and responses between 7 November 2020 and 4
December 2020, the DPC issued a draft inquiry report to the HSE on 27 January 2021.
The HSE providedsubmissions on this on 24 February2021. The DPC consideredthose
submissions before issuing the final inquiry report. The DPC sent a notice of
commencement of the decision-making phase of this inquiry to the HSE on 5 December
2022.
36. On 1 December2025, the DPC providedthe HSEacopy ofthe Draft Decision and invited
the HSE to make submissions on it. The HSE responded with submissions on 19 January
2026 and answered further inquiries on 16 March 2026. The DPC has carefully
considered all of the HSE’s submissions when preparing this Decision.
E. Scope of the Inquiry
37. The Commencement Letter indicated that the general scope of the Inquiry would be to
examine whether or not the HSE discharged its obligations in connection with the
subject matter of the personal data breach and determine whether or not any
provision(s) of the Act and/or the GDPR have/has been contravened by the HSE in that
context.
38. The scope of the Inquiry included focus on the HSE’s organisational and technical
measures in place to ensure security of the personal data involved. In particular the
Inquiry examines the ICT security of the HSE laboratory system in MRHT through:
examination of the ICT policies in place at the time of the breach,
explanations of whether ICT policies were fully implemented on the LIS,
13 HSE Update Report BN-18-11-244, 30 November 2018, 2-3.
14 The DPC agreed to a request for an extension to its original deadline of 30 October 2019.
15 HSE, 7 November 2019, ‘DPC Enquiry Consolidated responses’.
16 HSE Response to DPC Draft Inquiry Report, 23 February 2021.
10 examination of how compliance with ICT policies was achieved,
examinationofintrusionprevention anddetection measuresinplaceprior
to the breach occurring,
examinationofthetechnicalandorganisationalmeasuresimplementedas
a result of the breach.
39. In particular, the Commencement Letter outlined that the Inquiry would involve an
analysis of the breach reported to the DPC to determine if any contraventions of data
protection legislation had occurred.
F. Issues for Determination
40. Having reviewed the Final Inquiry Report and the other materials provided during the
course of this Inquiry, the DPC has determined the issues in respect of which it must
make a decision. Those issues are whether the HSE complied with the following
obligations in respect of the personal data of patients processed in the LIS and the
associated backup systems at the Midlands Regional Hospital, Tullamore (‘the Patient
Personal Data’):
Articles 5(1)(f) and 32(1) GDPR, which require controllers to implement
appropriate technical and organisational measures to ensure the
appropriate security of the personal data;
Article 28 GDPR, which requires controllers to engage processors who put
in place sufficient guarantees for the protection of personal data, and to
put in place with processors a contract or other binding legal act
addressing certain matters specified in that Article;
Article 30(1) GDPR, which require controllers to ensure that processing is
in accordance with the GDPR, and to put in place a record of processing
activities that contains the information specified in that Article;
Article34(1)GDPR,which obligesthedatacontroller,intheeventofadata
breach, to assess the risk to the rights and freedoms of data subjects from
that breach and, if the risk is high, to communicate the breach without
undue delay to those data subjects.
41. For the first three issues the DPC has determined that the temporal scope is between
25 May 2018 (the date when the GDPR took effect) and 14 November 2018 (the date of
the cyber-attack) (the ‘Temporal Scope’). For the final issue, which relates to whether
the HSE was obliged to notify data subjects after the cyber-attack, the temporal scope
is from 14 November 2018 onwards.
11G. Issue 1: Whether the HSE Infringed Articles 5(1)(f) and 32(1) in Relation to Patient
Personal Data during the Temporal Scope.
42. Article5(1)(f)GDPRsetsouttheprincipleofintegrityandconfidentiality.Itrequiresthat
personal data shall be
processed in a manner that ensures appropriate security of the personal data,
including protection against unauthorised or unlawful processing and against
accidental loss, destruction or damage, using appropriate technical or
organisational measures.
43. Article32(1) GDPR elaboratesonthe principle ofintegrityand confidentiality.It setsout
criteria for assessing what constitutes ‘appropriate technical and organisational
measures’, stating:
Taking into account the state of the art, the costs of implementation and the
nature, scope, context and purposes of processing as well as the risk of varying
likelihood and severity for the rights and freedoms of natural persons, the
controller and the processor shall implement appropriate technical and
organisational measures to ensure a level of security appropriate to the risk,
including inter alia as appropriate:
a) the pseudonymisation and encryption of personal data;
b) the ability to ensure the ongoing confidentiality, integrity, availability and
resilience of processing systems and services;
c) the ability to restore the availability and access to personal data in a timely
manner in the event of a physical or technical incident; and
d) a process for regularly testing, assessing and evaluating the effectiveness of
technical and organisational measuresfor ensuring the security of the processing.
44. Thus, Articles 5(1)(f) and 32(1) GDPR oblige controllers and processors to implement a
level of security appropriate to the risks presented by their processing of personal data.
a) Assessing risk
45. In determining the appropriate technical and organisational security measures, a
controller must assess the risk presented to the rights and freedoms of data subjects by
the processing, and then assess what security measures must be implemented.
46. Recital 76 GDPR provides guidance on how this risk can be assessed:
The likelihood and severity of the risk to the rights and freedoms of the data
subject should be determined by reference to the nature, scope, context and
purposes of the processing. Risk should be evaluated on the basis of an objective
12 assessment,bywhichitis establishedwhetherdataprocessingoperationsinvolve
a risk or a high risk.
47. With respect to the nature, scope and context of processing, all of the processing
operations that HSE carries out on the LIS personal data under its controllership relate
to the provision of a laboratory diagnosticservicefor the MRHT and local GPs. Asstated
in paragraph 25 above, the HSE acts as controller in respect of tests ordered within the
hospital and as a processor for those ordered by external GPs.
48. MRHTisthe largesthospitalin intheMidlands,withover180 beds,out-patientfacilities
and a busy Emergency Department. It serves counties Westmeath, Laois, Offaly and
Longford, with a combined population in 2018 of more than 292,000 persons. 17
49. The LIS records and retains information in relation to diagnostic test requests. This
information includes: patient name, patient address, patient ID, patient DOB, sex,
clinical details: date/time of sample collection, date/time of receipt in the laboratory
and date/time of report, specimen type, priority, results/reports, requesting clinician
details and a record of communications relating to test results. 18 The nature of the
personal data encompasses clinical data, which is special category health data, and
commonly includes data of vulnerable individuals. 19
50. The aggregate effect of these isto make clear that the processing for which appropriate
technical and organisational measures were required in MRHT was extensive in terms
thenumberof personspotentially affectedandthe types of activitiesthat it served. The
purposes served by the processing and the types of personal data processed were of
high sensitivity and importance to the welfare of the persons concerned.
b) Likelihood of risk
51. The types of risk posed by the HSE’s processing on the LIS system include delay or loss
of access to personal data, as well as unauthorised access to or disclosure of it. The
likelihood of these risks crystallising must vary according to the manner in which they
occur.
52. Loss of access to data can occur where systems degrade or break down, as can happen
when they are not properly maintained and keptup todate, or where an external event
such as a power failure or disruption of a network takes place. The likelihood of these
17
See Midlands Regional Hospital Tullamore, HSE information page, available at
https://www.hse.ie/eng/about/who/acute-hospitals-division/hospital-groups/dublin-midlands-
hospital-group/our-hospitals/mrht/ (accessed 18 February 2025). See also, Statistical Yearbook of
Ireland, 2018, Central Statistics Office.
18 HSE Update Report BN-18-11-244, 30 November 2018, 5.
19 Breach Notification Form, 16 November 2018, 4-5.
13 can range from a medium degree of probability to a remote one, but will generally
increase in line with the complexity of a system and the interdependence of its
components. Related to this, the likelihood of risk affecting one part of a system will
increase where another component on which it depends becomes more vulnerable.
Technical and organisational measures to address such risks must therefore take
account of not only the performance and operation of individual components, but of
the entire system used in the data processing. The data controller should foresee and
address a range of scenarios ranging from delays or inconvenience arising from
maintenance tasks, to more serious losses of access caused by failure of or disruption
to one or more central components.
53. Unauthorised access to or disclosure of personal data is a particular concern in systems
such as the LIS, which processes large amounts of sensitive data that is critical for the
health and wellbeing of data subjects. The likelihood of this risk varies from everyday
mistakes, such as inadvertently mistyping the address for a message, to less common
(though still foreseeable) risks such as deliberate intrusion by unauthorised persons,
whether physically or online. Measures to address these risks, such as access controls,
backup procedures and management protocols, must be periodically reviewed to
identify patterns of events that may indicate vulnerabilities, as well as external sources
that can give information on emerging threats or developments in best practices.
54. TheDPCnotesinthisregardthat,sinceatleast2016, ransomwareattacksonhealthcare
facilities had significantly increased in frequency and severity. This trend was widely
publicised in both health and IT publications. The increased likelihood of this risk to
the LIS system should therefore have been known to the HSE. The DPC finds that the
likelihood of the risk was high.
c) Severity of risk
55. The personal data processed included special category data, including that of
vulnerable persons. The risk arising from this processing of patients’ personal data on
the LIS included that an unauthorised person could gain access to patients’ personal
data, which would pose a high risk to the fundamental rights and freedoms of data
subjects, including the possibility of identity theft and extortion.
20 Healthcare IT News, 17 February 2016, ‘Hollywood Presbyterian hack signals more ransomware
attacks to come’, https://www.healthcareitnews.com/news/hollywood-presbyterian-hack-signals-
more-ransomware-attacks-come (accessed 20 February 2025). See also McCoy TH, Perlis RH.
‘Temporal Trends and Characteristics of Reportable Health Data Breaches, 2010-2017’, Journal of the
American Medical Association. 2018;320(12):1282–1284.
1456. A further risk wasthathaving gained access, an unauthorised person couldcompromise
the integrity or availability of patients’ personal data, causing disruption to or
interference with the medical care of data subjects, with potentially severe
consequences.
57. Similarly, failure of or disruption to the operation of some or all components of the LIS
system could interfere with patients’ care and treatment.
58. Based on this analysis, the DPC assesses the severity of the risk to be addressed by the
HSE’s technical and organisational measures concerning the LIS to be high.
d) Technical and organisational security measures implemented by the HSE
59. The HSE provided details of the technical and organisational measures in place in the
MRHT at the time of the breach. 21
60. The HSE outlined the laboratory local area network (‘LAN’) infrastructure in MRHT as
comprising:
two relational database servers – one live (‘Primary DB Server’) and one
failover (‘Secondary DB Server’);
four client desktops which hosted the LIS-related analyser interface
applications. The software for these applications was provided by an
external software provider (‘the Software Provider’);
a Firewall; and
a Network-attached storage (NAS) device and three external hard drives
for backup storage.
61. The HSE outlined the technical and organisational measures in place at the time of the
breach as follows:
the physical server hardware was housed in secure locations with access
restricted to authorised persons;
access to the Laboratory servers and PCs on the domains involved was
controlledbyusernameandpasswordrestrictions.User accessrightswere
managed using different levels of access within the domains. A secondary
level of authentication was in place for the relational databases;
21
HSE submission 22 October 2020, 2-3.
15 An Anti-Virus (‘AV’) solution was deployed on the systems in the LIS.
Physical access to the servers was restricted to authorised persons.
Logging systems were in place to record logins to the system.
Username and password restrictions were in place for access to the LIS
applications.
62. The HSE provided details of several business continuity measures in place to maintain
availability and resilience of their processing systems:
‘T-PATH-IT-011 .03- Procedure for Processing Samples in Biochemistry -
Haematology - Coagulation - Microbiology and Histopathology during
Planned & Unplanned Computer Down Time’: This laid down a set of
procedures to revert to a largely paper-based process to maintain service
provision at times when computer systems were not available and
‘T-PATH-IT-019 .03 Laboratory System-Server-Database- Backup and
Restoration Procedures’: This detailed procedures for backing up the
servers and databases to storage devices physically attached to the
servers.
63. In relation to regular testing, assessment and evaluation of the effectiveness of the
technicalandorganisation measuresforensuringthe securityoftheprocessing,theHSE
provided the following internal audit documents:
‘PPPG-T-QA-LP-006.06 – Internal Audit in the Pathology Department’; and
‘LIS Audit 2017 HAUD-PATH-2017-002’.
ThesedocumentsmadereferencetothetwoStandardOperatingProceduredocuments
mentioned in paragraph 62 above, as well as ‘T-PATH-IT-003.05 Procedure for
Controlling Access to the LIS and associated IT Infrastructure’.
64. None of the above documents mentioned any procedures for penetration testing or
vulnerability scanning. With regard to business continuity, the risk of having backup
devices directly attached to the servers (thus exposing them to malware infection and
other lateral attacks) was not flagged as a concern.
65. In its submissions of 29 March 2019, the HSE stated that the LIS infrastructure
wasnotunderthemanagementoftheHSEOoCIO.Athird-partysupplier[referred
to in this Decision as ‘the Infrastructure Provider’] provided management and
support of the LIS infrastructure from early 2000s. This operating model resulted
16 in no active oversight of compliance with HSE IT security policies as they evolved
over the years.22
66. In relation to the technical measures in place in the LIS environment at the time of the
breach,theDPCnotesthatinitsbreachnotification,theHSEmentionedthatthebackup
23
devices were directly attached to the servers and were exploited by the attack. This
hindered the HSE’s ability to effectively and efficiently restore the data.
67. The notification also stated that, while there was a firewall in place, external
connections on an unsecure port were still possible. The subsequent forensic analysis
carriedoutbytheExternalCybersecurityConsultancyconfirmedthatthiswasthevector
used by the attackers to gain access to the LIS. The report said:
This incident occurred due to the fact that it was possible to connect to a server
in the HSE lab over a Remote Desktop Connection from the internet. Attackers
frequently spider and search for available remote desktop connections and
attempttoaccessthese.RemoteDesktopisnotconsideredsafetohaveaccessible
from outside of a secure network.
A firewall or gateway protection should be setup to ensure remote desktop
connections are not accessible to the internet. Remote Desktop should only be
24
available for internal connections only.
68. In correspondence with the DPC on 29 March 2019, the HSE relayed a response from
theInfrastructureProviderwhichstatedthatit‘isnotawareofanyothermeasuressuch
as multi-factor authentication’. The absence of such controls would be a contributing
factor to the attackers’ ability to access the LIS network.
69. The External Cybersecurity Consultancy report also revealed that a weak and obvious
password was configured for an administrator account on the Secondary DB Server,
through which the ransomware was deployed. This account was used to access other
devices on the network, including the Primary DB Server. 26 While the Infrastructure
Provider monitored whether or not the Primary DB server was operational, there was
no Intrusion Detection System (IDS) in place. Therefore the Infrastructure Provider,
and consequentlytheHSE, becameawareof the attackonly afterthe Primary DB Server
went offline as a result of the encryption.
22 HSE submission 29 March 2019, 12.
23 Breach Notification Form, 16 November 2018, 3 and 5.
24
25 External Cybersecurity Consultancy - Forensic Analysis Report, 22.
26 HSE submission 29 March 2019, 12.
External Cybersecurity Consultancy - Forensic Analysis Report, 12.
27 HSE Update Report BN-18-11-244, 30 November 2018 7.
1770. The HSE also stated in its breach notification that anti-virus /anti malware software was
not up to date on the devices in the LIS. The External Cybersecurity Consultancy report
also noted that one of the affected devices was running a Microsoft operating system
that had not been supported July 2010. Devices running unsupported versions of
operating system have been directly targeted in numerous high-profile cyberattacks
such astheWannaCryattackin 2017. The existence ofsuchdevicesontheLISnetwork
greatly increased the vulnerability of the system to attacks and consequently the risks
to the rights and freedoms of data subjects.
e) Assessment of technical and organisational measures for security
71. Having considered the technical and organisational measures in place at the time of the
breach, and taking into account the state of the art and the likelihood and severity of
the risk posed by processing on the LIS, it is clear that the implemented measures were
not appropriate to the risk.
72. Endpoint security flaws in the LIS placed the confidentiality of Patient Personal Data at
risk. While the HSE stated that a firewall was in place, the absence of an intrusion
detection and prevention system meant that the HSE had no knowledge of malicious
activityuntil after the attackers chose todeploy the ransomware. An unsecured firewall
port was enabled without any additional security feature such as multi-factor
authentication (MFA).
73. Lack of adherence to strong administrator password policies presented an opportunity
for the attackers to not only view and alter the state of the relational database
(irrespective of whether or not secondary authentication was configured) but also to
move laterally to and exploit several other devices on the network.
74. With regardtothe volume and category of dataprocessed bythe HSE and the high level
of risk, the DPC considers that a more secure method such as Agentless backup would
have been more appropriate. The devices storing the database backups were not
separated from the other devices. This architecture allowed the ransomware to infect
the backup devices as well as the server, resulting in an inability to fully restore the
databasefollowing theattack. Theoffsitebackupstothefacility in werenot
maintained, resulting in loss of data.
75. In addition to lack of separation of the backup devices from the servers, the HSE failed
to implement network segmentation separating the database from the client devices
running the application used to access data. There also appears to have been no user-
28 See Europol ‘Wannacry Ransomware’ (6 November 2017), at
https://www.europol.europa.eu/wannacry-ransomware (accessed 13 January 2025).
18 right restrictions on the remote access account, thus allowing the attackers to infiltrate
multiple devices on the LIS with a single set of credentials.
76. The DPC also noted that encryption at rest was not implemented on the LIS devices.
Recital 51 GDPR states that personal data which are, by their nature, particularly
sensitive in relation to fundamental rights and freedoms merit specific protection, as
the context of their processing could create significant risks to the fundamental rights
and freedoms to the data subjects. Both the European Union Agency for Cybersecurity
(ENISA)29 and the US-based Health Insurance Portability and Accountability Act
30
(HIPAA) recommend encryption at rest to protect health data from unauthorised
access.
77. Furthermore, notwithstanding the lack of such measures, the volume and sensitive
nature of the data should have warranted a more robust ‘defence in depth’ approach.
The LIS environment was not subject to regular security oversight for some time prior
to the breach.
78. To summarise, the inadequacies of the technical and organisational measures in place
at the time of the breach included:
ineffective intrusion detection and prevention systems;
an unsecured remote access port enabled on the firewall without MFA;
a weak and obvious administrator password on the Secondary DB Server
through which the ransomware attack was initiated, which was then used
to move to other devices on the network, including the Primary DB Server;
a device with an unsupported operating present on the network;
Anti-Virus not updated on some of the affected devices;
sensitive data not encrypted at rest;
a lack of adequate security testing, such as vulnerability scanning and
penetration testing on the LIS environment;
an absence of up-to-date off-site backups to successfully restore the data;
a lack of effective centralised governance with regard to ongoing security
audits.
29 ENISA Procurement Guidelines for Cybersecurity in Hospitals.
30 The HIPAA Journal, ‘HIPAA Encryption Requirements - 2025 Update’, available at
https://www.hipaajournal.com/hipaa-encryption-requirements/ (accessed 13 January 2025).
19 Conclusion on Issue 1: The DPC finds that the HSE infringed Articles 5(1)(f) and 32(1) GDPR
by failing to implement appropriate technical and organisational measures to ensure a
level of security appropriate to the risk presented by its processing operations carried out
on the LIS. In correspondence to the DPC on 19 January 2026, the HSE concurred with the
DPC’s provisional conclusions to this effect as set out in the Draft Decision.
H. Issue 2: Whether the HSE Infringed Article 28 GDPR in Relation to the Patient Personal
Data During the Temporal Scope.
79. Article28 GDPR sets outobligationsof the controller and processorconcerningthe data
processing relationship between them. These include the following requirements:
The controller shall use only processors providing sufficient guarantees to
implement appropriate technical and organisational measures to
implement GDPR and protect the rights of the data subjects; 31
Processing by a processor shall be governed by a contract or other legal
act under Union or Member State law, that is binding on the processor; 32
and
The parties have an agreement in writing that clearly establishes the
relationship between the parties and includes provisions requiring the
processor to process peronal data only in accordance with the controller’s
instructions, to ensure the confidentiality and security of the personal
data, and related matters ensuring that processing complies with the
standards mandated by the GDPR. 33
80. The HSE outsourced maintenance of key components of the LIS to two external
companies: theInfrastructure Provider, whichprovidedand monitoredthestatusofthe
system hardware and operating systems, and the Software Provider, which provided
the client software interface. The DPC asked the HSE to provide details of its
arrangements with these companies.
81. On 30 November 2019, in response to the DPC’s request to identify ‘any third-party
contractor or processor with respect to [the HSE’s] Lab System solution’, the HSE
identified the Infrastructure Provider and the Software Provider. In response to the
DPC’s question asking whether ‘a written data processing agreement/contract or
31 GDPR, Article 28(1).
32 GDPR, Article 28(3)
33 GDPR, Article 28(9)
20 equivalent in place’, the HSE stated ‘Service Level Agreement in Place - Confidentiality
34
Agreement in Place.’
82. Havingexaminedallinformationandmaterialssubmittedoverthecourseoftheinquiry,
the DPC finds that the relationship between the HSE and those two companies was that
of controller and processor. The DPC is of the view that normal maintenance of
hardware and software would require engineers to log into systems that store personal
data and move datasets from place to place during backups. This is clearly ‘processing’
as defined in Article 4(2) GDPR, and is done on behalf of the controller, bringing the
relationship into the scope of Article 28 GDPR. A review of the HSE’s contracts with the
Infrastructure Provider and the Software Provider, and the conduct of the parties in
relation to the LIS, indicates that those relationships were not governed in such a way
as to demonstrate compliance with Article 28 GDPR.
a) The Infrastructure Provider
83. The HSE signed an ‘On Site Hardware Maintenance Contract’ with the Infrastructure
Provider on 13 October 2017. The HSE identified this as ‘the Service Level Agreement
35
(SLA) between the MRHT Pathology Department and [the Infrastructure Provider]’.
The contract outlined the following maintenance services which the Infrastructure
Provider would provide in relation to the equipment specified in the contract:
call-outs between 8.30am and 5.30pm from Monday to Friday (excluding
public holidays);
response within 4 hours for Servers;
on-site operating system support in the event of corruption;
management of warranty support with
temporary replacement equipment in the event of machine failure;
call track reporting via ;
telephone support for Windows Operating Systems; and
Remote Managed Service Inclusive.
84. Specifically referring to viruses, the contract stated that the Infrastructure Provider:
shall have no obligation to maintain or repair any Equipment which is affect [sic]
by viruses, worms, Trojan horses, cancelbots, or other contaminants or any codes
or instructions that may or shall be used to access, modify, delete, corrupt,
34 HSE Submission 30 November 2019, 6-7.
35 HSE submission 27 February 2019, 17.
21 deteriorate, alter or damage any data, files or other computer programs used by
the Customer. 36
85. While the firewall is listed as one of the items of equipment covered by the contract,
there is no evidence that the Infrastructure Provider’s obligations in relation to the
ongoingmanagementofthedeviceextendedbeyondthoseof astandard‘breakandfix’
agreement. In other words, the Infrastructure Provider’s responsibilities included
repairing or replacing defective elements of the system as the need arose, but did not
extend to updating or enhancing security in line with changing standards or
circumstances. In particular, there was no provision for updating and maintaining
firewall rules or implementing effective intrusion detection and prevention systems.
86. On 24 April 2019, the HSE submittedaresponsefromthe InfrastructureProvideronthis
matter which stated that the Infrastructure Provider:
do[es] not have policies/procedures for the management of MHRT infrastructure
(including firewalls) as the support agreement is a break/fix contract rather than
37
pro-active management and monitoring of the infrastructure.
87. In relation to the technical measures in place to provide alerts on sign-in behaviour for
the LIS environment, the Infrastructure Provider stated that there
was no pro-active alerting on the MHRT infrastructure sign-in behaviour. [The
38
Infrastructure Provider does] not monitor the MHRT infrastructure.
88. The HSE issued a response to the Infrastructure Provider’s claim on 24 February 2021:
The HSE concede that the SLA and documentation surrounding the support
arrangements in place were ill defined however it is not entirely accurate to
contend that monitoring and management arrangements for the MRHT lab
infrastructure were totally absent.
Domain changes, firewall config, AV licensing, hardware purchasing and repair
were handled via competent [Infrastructure Provider] engineers. Works not
covered under the terms of the SLA were chargeable items and invoiced separate
to the annual maintenance contract.
The ransomware attack under investigation occurred on the 14th of November at
7:20 a.m. Immediately after the attackthe HSE was notified by [the Infrastructure
Provider] of the attackby way of phone callsto the designated laboratory IT Lead.
They also notified the HSE that a service engineer from [the Infrastructure
36 HSE submission 27 February 2019, 21.
37 HSE submission 29 March 2019, 10.
38 HSE submission 29 March 2019, 12.
22 Provider] had been dispatched to MRHT to assist. They were able to do this
because they had monitoring software installed on the HSE servers which
returned alerts to them regarding login behaviour. From the HSE perspective this
call was ‘normal’ and fitted within the remit and responsibilities of [the
Infrastructure Provider].
It is beyond comprehension how [the Infrastructure Provider] can state that there
was ‘…no proactive alerting on theMRHT infrastructure sign in behaviour…’ when
it was this exact process that discovered the attack. A process which the HSE
contends [the Infrastructure Provider] were contracted to provide despite our
inability to find contractual documentation explicitly referring to this function.
89. It is clear that there were differences between the HSE’s and the Infrastructure
Provider’s opinions on the level of support that was in place. While the Infrastructure
Provider claimed that it did not monitor the LIS infrastructure, it was that company
which alerted the HSE to the breach. The HSE stated that this constituted pro-active
alerting of unusual sign-in behaviour. However, as noted in the original breach
notification, the Infrastructure Provider became aware of the breach only when the
Primary DB Server went offline. As was later discovered during the forensic
investigation, the Primary DB Server was accessed by means of remote access from the
Secondary DB Server. There did not appear to be any pro-active alerting of sign-in
behaviour on the Secondary DB Server. In any event, the HSE refers only to monitoring
software on the servers, but not to any preventative measures or technologies that
could have repelled the attack before it moved laterally through the LIS network.
90. On 27 February2019, the HSE submitted a letterfrom the Infrastructure Provider dated
24 May 2018 which outlined how the Infrastructure Provider proposed to ensure
adherence to GDPR. Among other things, this stated that the Infrastructure Provider
had ‘prepared a Data Processor Agreement for customers where our role is as Data
Processor.’ The DPC notes that:
the letter clearly stated that the Infrastructure Provider’s ‘adherence to
GDPR is not sufficient for other organisations to meet their GDPR
obligations’;
it was a general letter sent to all the Infrastructure Provider’s customers
and it did not specifically identify the Infrastructure Provider acting as a
Data Processor for the MRHT Pathology Department;
39 HSE Response to DPC Draft Inquiry Report, 23 February 2021, 4.
40 HSE submission 27 February 2019, 25-27.
23 the purpose of the letter was to ‘outline details of the customer data we
have, what the nature of the data is, what purpose it is used for and how
it is securely protected’;
the letter listed the data held and this data pertained to customer data,
contract data and IT data of which the Infrastructure Provider itself would
be a controller; and
the letter made no references to the clauses required to be included in
contracts between controllers and processors under Article 28(3) GDPR.
91. The DPC is of the view that the letter dealt only with the Infrastructure Provider’s
processing of personal data on its own systems and that there was a lack of sufficient
guarantees in place around the maintenance role concerning server access and the
storage and security of personal data on the HSE servers. The difference of opinion
between the HSE and the Infrastructure Provider as outlined above highlights the
absence of clarity and the need for robust documented processing agreements.
92. Although the Infrastructure Provider’s letter of 24 May 2018 stated that the
Infrastructure Provider had prepared a data processor agreement for customers where
its role was that of a data processor, the HSE did not demonstrate that it had entered
into such an agreement identifying the Infrastructure Provider as a Data Processor for
the services it provided for the MRHT Pathology Department.
b) The Software Provider
93. The HSE provided the DPC with a copy of a software maintenance agreement dated 16
January 2018 between the MRHT Pathology Department and the Software Provider. 41
ThisdescribesthemaintenanceservicesthattheSoftwareProviderprovided ‘inrelation
to its Laboratory Information System’. It also provides that the SoftwareProvider would
review ‘hardware requirements on an annual basis and provide advisory services to
42
laboratory personnel in relation to recommended hardware requirements’. The
agreement stated that the Software Provider would ‘strive to fix most problems by
remote access to the customer site, where it [the Software Provider]’s policy was to
abide by the customer’s agreed remote access procedures’. 43
94. The FinalInquiry Reportconcludedthat this agreement waslimitedtotheprovisionand
maintenanceofthethreeclientdesktopapplicationsutilisedbyMRHT anddidnotmake
any provision for the security of personal data that might be accessed or otherwise
41 HSE submission 27 February 2019, 11.
42 HSE submission 27 February 2019, 11 and 12.
43 HSE submission 27 February 2019, 11 and 13.
24 processed during maintenance operations. The Final Inquiry Report also concluded that
the three client software applications processed a significant amount of personal data
including special category data by way of collection, recording, organisation, storage,
consultation and disclosure by transmission of patients’ laboratory results.
c) Assessment
95. The DPC finds that the HSE’s agreements with the Infrastructure Provider and the
Software Provider did not provide sufficient guarantees to implement appropriate
technical and organisational measures to meet the requirements of the GDPR and
ensureprotectionoftherightsofdatasubjects.Therefore,theagreementsdidnotmeet
the requirements of Article 28(1) GDPR.
96. The DPC finds that the HSE’s agreement with the Infrastructure Provider predated the
entry into effect of the GDPR on 25 May 2018 and was not subsequently updated to
reflect the standards required after that date. It did not offer any guarantees relating to
any appropriate technical or organisational measures in place at MRHT. It did not
include any of the clauses required by Articles 28(3)(a) to (h) GDPR.
97. WithregardtotheagreementwiththeInfrastructureProvider,processingactivitiesthat
should have been governed by a contract or other binding legal act included access to,
operation and system-level protection of databases and information; operation, design
and protection of backup architecture and protocols, disaster recovery procedures in
the event of security incidents and the updating of anti-virus software on the HSE
servers. The DPC finds that the lack of a written contract governing these activities
contravened Article 28(9) GDPR.
Conclusion on Issue 2: The DPC finds that the HSE infringed Articles 28(1), (3) and (9) GDPR
byfailingtouseonlyprocessorsprovidingguaranteestoimplementappropriatetechnicaland
organisational measures to ensure a level of security appropriate to the risk presented by its
processing of Patient Personal Data and by the lack of sufficient binding written agreements
and procedure documentation relating to their processing arrangements.
I. Issue 3: Whether the HSE Infringed Article 30 GDPR in Relation to Patient Personal Data
During the Temporal Scope.
98. Article 30 GDPR requirescontrollers to maintain a Record of Processing Activities under
its responsibility. While neither specifically include the words ‘Record of Processing
Activities’ in their title, the HSE submitted two documents 44 which, it claimed,
44 MRHT Laboratory Data Protection SOP and Procedure for Controlling Access to the LIS and
associated IT Infrastructure.
25 constituted a ‘clear record... of who had access to what data and how that data was
further processed’. 45
99. The DPC noted during the inquiry that the formal approval date for these documents
was 23 November 2018, which post-dated not only the introduction of the GDPR but
alsothe breach itself,thoughthe HSEstatedthatthe documents‘existed indraftformat
prior to the breach’. 47 In addition, while the documents contained some of the
information required under Article 30(1) GDPR, other required information was absent,
specifically contact information for the Data Protection Officer, retention periods and
categories of recipients to whom personal data may be disclosed.
100. The DPC concurs with the findings of the inquiry that there was no formal Article 30
Record of Processing Activity in place at the time that the breach occurred on 14
November 2018, and that the lack of a GDPR-compliant Record of Processing Activity
that was contemporaneous with the processing activities undertaken by MRHT at the
time of the breach was an infringement of Article 30(1) GDPR.
Conclusion on Issue 3: the DPC finds that the HSE infringed Article 30(1) GDPR by failing to
have in place a Record of Processing Activity compliant with the requirements of that Article
at the time of the breach.
J. Issue 4: Whether the HSE Infringed Article 34 GDPR in Relation to Patient Personal Data
During the Temporal Scope.
101. Article 34(1) GDPR provides:
When the personal data breach is likely to result in a high risk to the rights and
freedoms of natural persons, the controller shall communicate the personal data
breach to the data subject without undue delay.
48
102. In its initial notification of the breach, the HSE assigned a medium risk to the breach
and maintained this position throughout the Inquiry and in its submissions on the Draft
Inquiry Report. In the breach notification submitted on 16 November 2018, the HSE
stated that
45 HSE Response to DPC Draft Inquiry Report, 23 February 2021, 3.
46
47 MRHT Laboratory Data Protection SOP, 2.
48 HSE Response to DPC Draft Inquiry Report, 23 February 2021, 3.
Breach Notification Form, 16 November 2018, 3.
49 HSE Response to DPC Draft Inquiry Report, 23 Feb 2021.
26 thereisnoevidencethatdatawasremovedorhasfallenintounauthorisedhands.
50
The data has been encrypted by the ransomware virus only.
51
103. In its reply to the Commencement Notice on 7 November 2019, the HSE listed the
following as reasons for its decision to rate the risk posed by the breach as ‘Medium’:
The nature of the breach (ransomware attack). Typically in this type of
scenario, the attacker is not stealing the data, they are rendering it
unusable.
The type of information held on the lab (which included special category
data).
The number of individuals affected.
The fact that there were some viable backups of the lab data which were
unaffected.
The fact that hard copy reports are sent to requesting clinician.
There was no evidence at the time that the data was removed.
The steps taken on confirmation of the attack which included:
o Unplugging all the servers and workstation on the lab network;
o Blocking the lab systems access to the HSE LAN via the firewall;
o Isolating the HSE server that was connected to the lab system
network;
o Running a manual virus scan on the HSE server which was
connected to the lab system network; and
o Running a virus scan on the Tullamore network.
104. The conclusion of the Final Inquiry Report was that
given the nature and scope of the processingof the special category data, and the
malicious nature of the personal data breach, the HSE should have reassessed the
potential risks to the rights and freedoms of the affected individuals as ‘high’ and
that as a result this would have created an additional obligation on the HSE to
communicate the circumstances of the breach as required by Article 34(1) of the
GDPR.
50 Breach Notification Form, 16 November 2018, 3.
51 HSE, 7 November 2019, ‘DPC Enquiry Consolidated responses’, 5.
27105. AsnotificationofdatasubjectsunderArticle34GDPRisrequiredwhereabreachislikely
to result in a high risk to data subjects, this section will assess whether the HSE’s
assessment of the risk as ‘medium’ was correct. If the risk was medium, then the
requirement to notify data subjects would not have been triggered. If the risk was high,
then the HSE should have notified data subjects.
106. Where the notification obligation is triggered, the notification must be made ‘without
undue delay.’ An assessment of the risk must therefore be carried out promptly after
the breach, in order to determine whether the notification obligation arises. The
European Data Protection Board (“EDPB”)’s guidelines on personal data breach
notification say that
immediately upon becoming aware of a breach, it is vitally important that the
controller should not only seek to contain the incident but it should also assess
the risk that could result from it. There are two important reasons for this: firstly,
knowing the likelihood and the potential severity of the impact on the individual
will help the controller to take effective steps to contain and address the breach;
secondly, it will help it to determine whether notification is required to the
supervisory authority and, if necessary, to the individuals concerned. 52
a) Analysis of whether the HSE’s risk assessment was appropriate in the circumstances
of the breach
107. This section sets out the DPC’s analysis of whether the HSE’s risk assessment was
appropriate, having regard to the nature of risk of adverse effects to data subjects, and
the testing that was conducted to assess the risks that actually occurred.
i. Nature of risks
108. First, it is necessary to consider the nature of the risks to data subjects that could have
arisen from the incident. The analysis below considers the risk of the lack of availability
of data and the risks to the confidentiality of patient data arising from the breach.
109. In relation to the availability of data, the HSE stated that paper-based records are the
primary source of information for clinicians using the LIS, and that the electronic copies
served as a supplementary source. In its submission of 23 February 2021, the HSE
elaborated on this:
Samplesarriveintothelaboratoryreceptiontogetherwithawritten(paperbased)
form, filled in and signed by a relevant person with authority to request a test
52
EDPB ‘Guidelines 9/2022 on personal data breach notification under GDPR’, para 101.
28 (consultant, house doctor, general practitioner etc.). The form is a traditional
paper form with a main sheet and four carbon copies. Each copy is used for the
different laboratory disciplines involved in the tests requested (as a single request
may be for multiple tests in different disciplines of the laboratory).
Once the relevant data is transcribed from the form into the LIS, the sample is
taken and processed by an operator/medical scientist in accordance with the
relevantprotocolforthetestsrequested.Mosttestsinvolvetheuseofautomated
analysers which use either internal processors or else externally attached
processors to control the operation of the analyser and communicate with the
operator of the analyser, finally reporting the result of the test as a numeric value
either directly or through an independent computer. Once the LIS flags that a test
is complete and a result available, it is reviewed by the relevant Lab personnel
before being authorised and returned by way of a printed test result report to the
requesting clinician.
In addition to the printed report, results are returned electronically to a general
practitioner who hastheir own practicemanagement system.Inthat casethe test
result is returned electronically to the GP practice and stored in their practice
management system by the HSE’s Healthlink system. A paper report is also
53
returned in these cases.
110. From this description, it appears that the LIS plays a significant role in the efficiency of
returning sample tests, particularly in relation to the role played by the automated
analysers. Therefore, the impairment of this function caused by the breach is likely to
have had at least some detrimental effects on patient services.
111. In correspondence to the DPC on 25 January 2023 responding to the final report of the
inquiry, the HSE added:
An important element of the risk assessment carried out was that, in normal
circumstances,theelectronicrecordwasonlyavailableforalimitedperiodoftime
(90 days) after which it was not available to clinicians.
112. Irrespective of whether the data on the LIS system was intended to be available to
clinicians after 90 days, the data gap in the offsite backup referred to in paragraphs 8
and 74 above referenced data more than 90 days old. This indicates that the data
remained on the database and was thus accessible by anyone, including unauthorised
persons, with access to the database.
53 HSE Response to DPC Draft Inquiry Report, 23 Feb 2021, 2-3.
54 HSE email to DPC, 23 January 2023.
29113. In its initial assessment of the breach, the HSE was of the opinion that viable backups of
the affected data were available. Ultimately however, the HSE was unable to fully
restore the database to its original state, as electronic records from June 2017 to
November 2018 had not been backed up and so were not recoverable.
114. The DPC considered the risk that confidential information could have been accessed or
extracted inthe incident.In itssubmissionsdated23 February 2021 ontheDraft Inquiry
Report, the HSE maintained that the configuration of the SQL database mitigated this
risk:
The MRHT LIS is designed around a SQL Database structure. This SQL databases
back-boningtheLISwereprotectedbystrongusernameandpasswordrestrictions
(secondary to the domain account credentials the hacker exploited to instigate
the breach). The structure of the SQL relational databases is highly complex
consisting of multiple tables that need to be linked together to make sense. This
is highlighted by the Database Schema.
115. In the context of the specific incident, SQL Server authentication would have been
effective onlyas an extra line of defence if the attackers did not gain administrator level
privileges on the Primary DB Server. It was clear from the outset that the attackers had
administrator level privileges, as they were able to log into and run executables on the
server (in this case, the encryption program). This was later confirmed by the forensic
report. Therefore, the DPC does not consider that secondary SQL authentication
provided a safeguard to the confidentiality of patient data in respect of the incident.
116. The DPC does not agree with the HSE’s assertion that the structure of the SQL database
is ‘highly complex’, and that this helped to prevent the risk posed by the breach being
high. The HSE submitted a sample of the relational database schema on 24 February
2021. This showed that the database included a table called ‘ containing
data capableof identifying individuals,such aspatient name, age, and dateof birth. The
Primary Key of this table is a field named ‘ , which acts as a Foreign Key for
several other tables (referred to as ’) such as ‘ and
‘ 55 Other fields in this table are named ‘ , ‘ and ‘ . These are
commonlyused acronyms for ’, ’and‘ ’
117. Having viewed the schema, the DPC is of the opinion that it would not take a great deal
of time or proficiency in relational database administration to combine and view these
55
HSE Response to Draft Inquiry Report, 23 February 2021, Appendix 1 - LIMS database schema
30 tables using basic ‘Join’ commands. 56 The DPC is therefore of the view that fields
containing personal data capable of identifying individuals, such as those stored in the
table and numeric data stored in the tables, are linkable with
reasonable facility.
118. In correspondence to the DPC on 25 January 2023, the HSE stated:
the data itself whilst special category was not sensitive in nature as the majority
of clinical data in a laboratory information system is numeric in nature and hasno
meaning until associated with the discipline involved and the patient.
119. Although the data were alphanumeric, they do not appear to have been particularly
difficult to read. For example, in the schema provided to the DPC, one of the tables
linked to the table through the field is named ‘ .
In addition to the foreign key, other fields in this table are named ‘ , ‘
and ‘ . These are commonly used acronyms for ’,
’ and ‘ ’ Therefore, the alphanumeric nature of this data would not
have pseudonymised that data sufficiently, as a motivated attacker could link it to
identifiable data fields with only moderate effort.
120. As outlined in paragraphs 114 to115 above, this avenuewasopen tothe attackers once
they had obtained administrator access to the server.
121. The EDPB Guidelines on breach notifications provide guidance on the circumstances
under which data subjects should be notified:
[N]otification of a breach is required unless it is unlikely to result in a risk to the
rights and freedoms of individuals, and the key trigger requiring communication
of a breach to data subjects is where it is likely to result in a high risk to the rights
and freedomsofindividuals.This riskexistswhen thebreachmayleadtophysical,
material or non-material damage for the individuals whose data have been
breached. Examples of such damage are discrimination, identity theft or fraud,
financial loss and damage to reputation. When the breach involves personal data
that reveals racial or ethnic origin, political opinion, religion or philosophical
beliefs, or trade union membership, or includes genetic data, data concerning
health or data concerning sex life, or criminal convictions and offences or related
security measures, such damage should be considered likely to occur. 57
56
Microsoft.com, ‘Joins (SQL Server)’, available at https://learn.microsoft.com/en-us/sql/relational-
databases/performance/joins (accessed 15 December 2024).
57 EDPB ‘Guidelines 9/2022 on personal data breach notification under GDPR’, at paragraph 102.
(Emphasis added).
31122. Based on the preceding analysis, the DPC considers thatthe actual risks to data subjects
arising from the incident included a risk that special category data – in this case health
data – may have been viewed, altered, deleted or exfiltrated. This clearly comes within
the ambit of high risk.
123. The HSEassertedthattherewaslimited risktopatient servicesbecauseofthe existence
of paper records. (The HSE did not quantify the reduction in risk that it considered that
the paper records provided.) The HSE submitted that the purpose of the LIS system is to
provide ‘ease of access’ for clinicians, who could still access all relevant data on the
paper records. However,as noted inparagraph 110, automated tasksperformed on the
electronic dataplayed asignificant role in returning test results. It isthe DPC’s viewthat
the LIS system being offline removed a more quick and convenient means of location
and retrieval, which would have affected clinicians’ ability to access patient data and,
consequently had a potential adverse effect on the efficiency of patient services.
124. The HSE was also unable to restore all of the data due to the backup devices also being
encrypted. Therefore, the DPC is of the opinion that there was a partial loss of
availability of patient personal data as a result the breach. The fact that the database
was not encrypted and not ultimately restored to its original state points to loss of
integrity of the patient data.
125. In the light of these findings, the risks arising from the incident pertain to the
confidentiality, integrity and availability of the patient data processed on the LIS.
ii. Post-incident testing and risk analysis
126. The HSE’s risk assessment took into account risks to special category personal data and
the risk of extraction. The HSE’s breach notification stated ‘Typically in this type of
scenario, the attacker is not stealing the data, they are rendering it unusable’. The DPC
cannot see how there was sufficient empirical evidence to arrive at this conclusion
immediately after the breach was discovered. Due to the LIS devices being encrypted,
the HSE was unable to sufficiently triage the breach to estimate how long the attackers
had access to its network. The DPC also bears in mind that in May 2021, the HSE was
subjected to another ransomware attack. A report on that incident confirmed an eight-
week interval between the network being compromised and deployment of
ransomware. 58 The report also confirmed that data was extracted in that time. This
indicates that it is entirely possible in an incident of this nature that hackers could have
58
HSE, ‘HSE – Independent Post Incident Review’, 3 December 2021, 2.
32 access to a system and engage in malicious activity long before they deploy
ransomware.
127. In its response to the Draft Inquiry Report dated 24 February 2021, the HSE provided
further information about its immediate response to and assessment of the breach:
Oneoftheimmediatepostshutdownactionswastocheckthepossibilitythatdata
hadbeenremovedfromtheHSEenvironment.Todothisourownnetworkpeople
checked network usage…... the HSE had conducted its own investigations and on
the 15 of November, prior to issuing the breach notification on the 16 had th
determined that there was no evidence to show that a 150 Gb+ database file had
been copied out of the Hospital network.
128. The HSE also provided internal email correspondence on the day of the breach, which
stated:
From our (network management software) there is no real change in
baseline traffic and actual traffic up to the time of the event on NHN thus giving
59
credibility to us saying that the DB was not copied over NHN anywhere.
129. While this offers some assurance that large-scale extraction of data did not occur, it
does not rule out the possibility that unauthorised viewing of the data took place.
Additionally, the correspondence quoted above gives no details of the duration of time
during which the network traffic was monitored.
130. It was apparent at the time of discovery of the breach that the attackers had obtained
administrator access tothe database servers.As aresult,they could querythedatabase
directly. It would also have been feasible for them to export and extract data into
smaller file types such as .xls or .csv. Transmission of these files would be harder to
detect solelyby monitoring network traffic. These are plausible possibilities because, at
the time when it first assessed the breach, the HSE had no way to accurately estimate
how long the attackers had access to the LIS environment.
131. The absence of an intrusion detection system, coupled with the enabling of a remote
access port on the firewall, meant that the attackers were able to act without being
detecteduntil theydeployed the ransomware, causing the serverto cease operation.In
correspondence to the DPC on 29 March 2019, the HSE stated that firewall logs were
not reviewed by the Infrastructure Provider in the immediate post-incident
60
investigation.
59 HSE internal email ‘Potential Major Incident - i31733 - Ransomware issue with Tullamore LAB server’,
22 February 2021.
60 HSE submission 29 March 2019, 14.
33132. The External Cybersecurity Consultancy’s investigation into the incident sought to
establish further facts on the attack, particularly in relation to the vector employed and
the scope of the attackers’ activities. However, the DPC notes that, of the five devices
encrypted in the attack, only four were examined by the External Cybersecurity
Consultancy. The encrypted device that was not examined has been identified as the
Primary DB Server. Examination of this server could have shown whether it had been
affected by malicious activity. It is also possible that the event logs were erased from
this server, but in the absence of an examination, it is impossible to know. The failure
to forensically examine this server is thus a material omission from the post-incident
investigation.
133. TheExternalCybersecurityConsultancywasspecificallyaskedtoconfirmifHSEdatawas
61
viewed or extracted during the attack. Its response was:
It is difficult to state conclusively whether HSE data was viewed by the hackers or
not. Many records have been lost by the encryption process… no evidence of file
viewingwasfound,butthenumberofrecordsavailabletocheckthiswasminimal.
While no evidence of data exfiltration was found, it cannot be conclusively ruled
out due to lack of available evidence.
134. The External Cybersecurity Consultancy report also stated that the device operating
system does not record files copied over the unsecured remote access protocol, which
was the vector employedby the attackers. The reportnoted thatthe attackers regularly
cleared the logs of all devices during their operation, thus obscuring much of their
footprint. The encryption process purged most of the log files, which would give a
clearer picture of file-viewing activity.
135. The External Cybersecurity Consultancy also endeavoured to estimate a timeline of the
attackers’ activities. As previously stated, much of the logging information was purged
during the incident. The surviving logging information was used to estimate the
timeline. A summary of the remaining logs for 14 November 2018 are detailed in the
table below:
61
External Cybersecurity Consultancy- Forensic Analysis Report, 4-5.
34 Device Log type Activity
Time
Registry Outbound remote desktop connection made to
07:20:30 ( using username
Registry Outbound remote desktop connection made to
07:25:02 DSKML06071 (MK01) using username
Registry Outbound remote desktop connection made to (
07:25:03 using username
Registry Outbound remote desktop connection made to
07:29:36 using username
Registry file for indicates inbound
07:36:39 Remote Desktop Connection using the clipboard
Registry shows the Remote Desktop executable
07:37 mstsc.exe was last run at this time
Registry Incoming remote desktop connection from
07:37:46 ( using username
Registry Remote desktop session disconnected
07:40:34
Registry Outbound remote desktop connection made to
07:41:22 using username
Event Remote Desktop session from Panama IP of
07:43:26 Log disconnects
136. The earliest available information was a registry log describing an outbound RDP
connection from the Secondary DB Server (referred to in the above table as MK04) at
07:20, implying that the LIS network was breached prior to that point in time. It is
important to note that the majority of remaining logs are in the form of Registry key
modification dates. These record only the most recent modification of the key or sub-
part of the key. They are not the most reliable records for determining in full the
attackers’activityintheLISenvironment,astheydonotshowinterveningmodifications
or access to thefiles. TheExternal CybersecurityConsultancyalludedto this fact intheir
35 report.62 As the record of each modification is overwritten by any subsequent
modification to the file, there is no way of determining from these records when the
attackers first gained access to the LIS network or for how long they were active.
137. The DPC also notes that the time of disconnection from the remote session from the
Panama IP address was recorded, but the time of the initial connection was not. It is
likely that this record was purged when the attackers cleared the event logs after
deploying the ransomware. This raises a reasonable doubt to the HSE’s assertion that
23 minutes was indicative of the length of time during which the attackers were active
in the LIS environment.
b) Summary and conclusion on risks arising from these measures
138. Article 34 GDPR requires notification to data subjects where a personal data breach is
likely to result in a risk to their rights and freedoms.
139. As set out above, the DPC considers that the incident gave rise to risks to the
confidentiality, integrity and availability of patient personal data. The lack of reliable
evidenceofthedurationoftheincidentandthepossibilitythatselectiveextractiontook
place mean that it is not possible for the HSE to demonstrably determine from the
evidence collected in the Inquiry whether or not the confidentiality of patient data was
compromised. While this lack of evidence is due in part to the attackers deleting,
overwriting and encrypting data, the HSE must share responsibility for this lack of
information.Itdidnothaveanintrusiondetectionsysteminplaceandfirewalllogswere
not examined,whichmeant that itdidnot knowthat attackershadaccessto the system
until it went offline.
140. Some aspects of the HSE’s risk assessment do not stand up to scrutiny. The HSE
concluded that ransomware was the sole purpose of the attack despite having
insufficient knowledge of how long its network had been compromised and the attack
vector employed.Therefore, on the basis of the facts available, the DPC sees no basisto
conclude that that the HSE fully assessed the implications of the attackers acquiring
administrator privileges on its devices, particularly the relational database servers, and
the associated risk that special category personal data could have been viewed or
extracted from that database.
141. Over the course of the Inquiry, the HSE referred to the External Cybersecurity
Consultancy’s report to support its assessment of the risks posed by the breach.
However, as outlined above, that report specifically stated that the External
Cybersecurity Consultancy could not rule out the possibility that patient data was
62
External Cybersecurity Consultancy- Forensic Analysis Report, 19.
36 viewed or extracted. The External Cybersecurity Consultancy did not examine the
PrimaryDBserverandcouldnotestablishacompletetimelineoftheattackers’activities
due to incomplete logging information.
142. In its response to the Inquiry Report on 24 February 2021, the HSE stated:
in the short time the attack happened, later confirmed to be 23 minutes, there is
no evidence to show that the database management system itself was breached
in such a way as to make the database schema available to an attacker. 63
143. As outlined in paragraphs 137-139, the External Cybersecurity Consultancy report does
notsupporttheconclusionthatthetimeframeoftheincidentwaslimitedto23minutes.
Havingexaminedthatreport,andnotingthatthePrimaryDBserverwasnotforensically
examined, the DPC is of the opinion that the lack of evidence to which the HSE refers
was caused by the attackers purging logging information that might have provided a
clearer picture of their activity.
144. The HSE also stated:
The modusoperandi of the ransomware variant involved inthe breachisencrypts
files – [the External Cybersecurity Consultancy] testing confirmed no network
64
activity or attempts to store or export data were associated with this variant.
145. While this is true in relation to the behaviour of the ransomware variant, this was only
one of three methods of data viewing or extraction that the External Cybersecurity
Consultancy considered in its report. As outlined earlier, in the absence of records that
were purged or overwritten during the attack, the report concluded that it could not
conclusively rule out file viewing or extraction.
146. The DPC acknowledges that there is no direct evidence that the attackers viewed or
extracted data, and that the deletion of the Event logs prevented the HSE from easily
establishing whether that had occurred. The DPC also acknowledges that testing for
selective extraction in the absence of these logs would be very difficult, and that the
HSE conducted tests for bulk extraction, which ruled out the possibility that a large
single file was copied.
147. Nevertheless, the absence of clear evidence ruling out viewing or extraction of data
leaves a significant residual doubt as to whether confidentiality of patient data was
compromised. The DPC therefore must consider the actual likelihood of confidentiality
63 HSE Response to DPC Draft Inquiry Report, 23 February 2021, 5.
64 HSE Response to DPC Draft Inquiry Report, 23 February 2021, 8.
37 being compromised. If it is likely that confidentiality was compromised, this would
indicate a high risk to data subjects and require notification under Article 34(1) GDPR.
148. The EDPB guidelines 9/2022 on personal data breach notification under GDPR point out
that, in line with Recitals 75 and 76 GDPR, controllers must consider the likelihood and
severity of risk to determine whether the risk posed by a breach is high. Where it is
found to be high, data subjects must accordingly be notified.
149. The severity of the risk to data subjects arising from access to the data was high. The
attackers had access to a relational database from which it was possible within
reasonable means to view and extract special category personal data such as clinical
test results.
150. Controllers must assess the likelihood of the risks on the basis of the information
available at the time of, or shortly after, the breach. In this case, while subsequent
investigations by the External Cybersecurity Consultancy and the HSE do not indicate
that patient personal data was viewed or extracted during the attack, it is important to
bear in mind the purpose of the requirement to notify under Article 34 GDPR. That
purpose is to enable data subjects to respond and protect their rights and freedoms to
the fullest extent possible. This necessarily requires the notification to be made at the
earliestopportunity. Controllersmust notify datasubjects‘without undue delay’, sothe
likelihood of risk should have been assessed at the time of the breach on the basis of
the evidence then available.
151. Anyone with administrator access to the entire database would have been able to
retrievedetailsoftestresultsaboutanyparticularpatient.Retrievingsuchdetailswould
have involved a number of steps to link the data across different tables, but it would
have been possible, within reasonable means, for the attackers to do this while they
were in the system. It also would have been possible to do this if data were extracted in
bulk.
152. The HSE took prompt action to check for significant spikes in network traffic preceding
the incident. While this goes some way to reassuring that bulk extraction of the
database did not take place, it does not, as outlined in paragraph 141, rule out the
possibility that exfiltration or viewing of data of any kind did not occur.
153. The HSE also did not recognise that the attack resulted in reduced availability of patient
data. The HSE claimed that the existence of paper records negated concerns about the
availability of patient data despite stating that the purpose of the LIS was to provide
38 ‘ease of access’forclinicians. Inthis regard,theDPC notesthat inJanuary2023,asenior
HSE official stated to an Oireachtas Committee that paper records were ‘inefficient’. 65
154. While it cannot be conclusively stated that individual records were amended while the
attackers had access to the LIS environment, the very nature of a ransomware attack is
to alter the state of the database so as to render it unusable. This signifies a risk to the
integrity of patient data.
155. ENISA has provided a recommended methodology on assigning level of severity to data
breaches. The severity level (SE) is determined by the formula:
Data Processing Context × Ease of Identification + Circumstances of the breach
WhereSEisbetween3and4,theguidelinesrecommendthatahighseveritybeassigned
and a ‘very high’ risk for any rating greater than 4.
156. For Data Processing Context, ENISA recommend that a base score of 4 be assigned to
specialcategorypersonaldatasuchashealthdata.Additionaldetailssuchasthevolume
of data affected and special characteristics of the data controller are seen as increasing
67
factors for this score.
157. A score of 1 is assigned to Ease of Identification if the data subject can be easily
identified.Inthecaseofthisbreach,adatasubject’sfullname,addressanddateofbirth
were viewable in the Demographics table of the LIS database as per the schema
provided by the HSE.
158. Circumstancesofthe breach iscalculated on four factors: Lossof confidentiality, Loss of
integrity, Loss of availability, and whether malicious intent was involved. Loss of
confidentiality is scored at 0 if data is exposed to confidentiality risks but without
evidencethatillegalprocessinghasoccurred.Inthecircumstancesofthisbreachascore
of 0 is therefore appropriate.
159. Loss of integrity carries an additional score of 0.5 if the original data cannot be
recovered. In the DPC’s view, this is the appropriate weight in this case irrespective of
whetherpaper recordsexisted. TheHSEultimately couldnot restoretheelectronicdata
to its original state.
65
Irish Independent, ‘Healthcare is held back by paper-based records as funding yet to be approved for
66 switch to electronic system’, 25 January 2023.
ENISA, ‘Recommendations for a methodology of the assessment of severity of personal data
breaches’, v.1.0, December 2013.
67 ENISA, ‘Recommendations for a methodology of the assessment of severity of personal data
breaches’, v.1.0, December 2013, Annex 1.
39160. Loss of availability carries an additional score of 0.25 in the case of temporal
unavailability, i.e. where the information can be retrieved from other sources. In this
case, the existence of paper records is relevant. Finally, an extra score of 0.5 is applied
if malicious intent was involved, which is clearly the case for this breach.
161. Applying this methodology, the overall score is 6.25, which is above the threshold for a
high severity breach. Taking this into account, as well as the DPC’s evaluation of the
HSE’s reasoning for their classification of the breach, the DPC does not accept that
‘medium’ wasan appropriate riskrating for thisbreach. Taking into account the scale of
the risk, in terms of the number of affected data subjects, and the special category
personal data affected, the DPC is of the view that the HSE should have assigned a high
risk rating to the breach.
c) Assessment of the HSE’s Media Communication
162. Article 34(2) GDPR states
The communication to the data subject referred to in paragraph 1 of this Article
shall describe in clear and plain language the nature of the personal data breach
and contain at least the information and measures referred to in points (b), (c)
and (d) of Article 33(3).
163. The measures in Article 33(3) referred to above require that the notification should at
least:
communicate the name and contact details of the data protection officer or other
contact point where more information can be obtained;
describe the likely consequences of the personal data breach;
describe the measures taken or proposed to be taken by the controller to address
the personal data breach, including, where appropriate, measures to mitigate its
possible adverse effects.
164. Article 34(3) GDPR provides three limited exceptions to the requirement to
communicate details of a breach assessed to pose a high risk:
The communication to the data subject referred to in paragraph 1 shall not be
required if any of the following conditions are met:
(a) the controller has implemented appropriate technical and organisational
protection measures, and those measures were applied to the personal
data affected by the personal data breach, in particular those that render
the personal data unintelligible to any person who is not authorised to
access it, such as encryption;
40 (b) the controller has taken subsequent measures which ensure that the high
risk to the rights and freedoms of data subjects referred to in paragraph 1
is no longer likely to materialise;
(c) it would involve disproportionate effort. In such a case, there shall instead
be a public communication or similar measure whereby the data subjects
are informed in an equally effective manner.
165. The exception in Article 34(3)(a) GDPR does not apply because the personal data
accessible (and sopotentially disclosed to the attackers) were not encrypted by the HSE
or otherwise rendered unintelligible to unauthorised persons.
166. Similarly, the exception in Article 34(3)(b) GDPR does not apply. As noted in paragraph
133 above, the ExternalCybersecurity Consultancy’s forensic analysis could not exclude
the possibility that the attackers exfiltrated data from the LIS before encrypting it and
cutting off contact.Asthe attackers, and their conduct with any personaldata they may
haveexfiltrated,wereentirelyoutsidethecontroloftheHSE,nothingthattheHSEcould
havedonewouldhavereducedtherisksposedbysuchpossibleexfiltration,orrendered
them unlikely to materialise.
167. Article 34(3)(c) applies where communicating the breach directly to data subjects
‘would involve disproportionate effort’. The DPC notes in this regard that the records of
approximately 84,000 persons were affected by the breach. Given the large number of
data subjects, and the need to communicate ‘without undue delay’, the DPC accepts
that individual communication wouldhave involved disproportionateeffort inthis case.
As prescribed by Article 34(3)(c), ‘a public communication or similar measure whereby
the data subjects are informed in an equally effective manner’ was therefore required.
168. The DPC notes the efforts made by the HSE to publicise the breach. In its submission on
23 February 2021, the HSE stated:
[T]he HSE took part in numerous public communications events, both print and
radio, inorder to explainand assure the people affected. Appendix2 givesfurther
details of these interactions.8
169. The ‘Appendix 2’ referred to by the HSE (’Media Communications’ for the purposes of
this document) includes articles and segments from print and broadcast media outlets
69
on Thursday 15 November 2018, the day after discovery of the breach. The HSE is
quoted as describingthe incident as an ‘isolatedWindows ransomware attack’. Extracts
from the statement, as quoted by numerous print media outlets state:
68 HSE Response to DPC Draft Inquiry Report, 23 February 2021, 2.
69 The HSE did not submit to the DPC the press release that it provided to media outlets.
41 The hospital has been assured that this is an isolated incident and there is no
evidence of contagion in the wider health service beyond the initial attack. The
hospital has been working in conjunction with the HSE Office of the Chief
Information Officer to restore the system and re-instate a functional Laboratory
Information System within a re-configured secure HSE environment. There has
been no impact on patient care and business continuity plans are in operation
until the full system is restored. The HSE have informed the Data Protection
Commission on a precautionary basis.
170. The HSE submitted to the Inquiry that, during the week after discovery of the breach, a
HSEspokespersonalsograntedan interviewto theradiostation Midlands103(‘M103’).
Thespokespersonstatedthatthefallbacktopaper-based recordsmeantthattherewas
no interruption to patient care. M103 asked for further clarityon the security of patient
data. The following is a transcript from that segment of the interview:70
M103: ...to confirm, there is no threat to any patient’s information, their date of
birth, emails that may have been hijacked or hacked?
HSE: Not that we are aware of at this point in time.
M103: But you can’t give 100% certainty that that has not happened.
HSE: At this point in time I have no information to state that that has happened.
It is important to point out that at this point in time, our Laboratory Information
System is 80% fully recovered and with ongoing works that will happen
throughout today, it is expected that we will have our Laboratory Information
System fully restored by the afternoon.
M103: And when do you expect to be able to tell patients that their information
is 100% secure?
HSE: I will rely on the Office of the Chief Information Officer to provide me with
that assurance.
Later in the interview the following exchange took place:
M103: And when will you issue a statement or update to reassure patients?
HSE: We can issue statements throughout the day but at this point in time, I can
assure our patients and the public that there has been absolutely no impact on
patient care and we will continue to maintain that.
70 Recording of interview available at https://soundcloud.com/benfinnegannews/manager-of-tullamore-
hospital-on-ransomware-attack. The quoted extract is at 1:30 to 2:24 of the recording.
42171. While it is commendable that the HSE took prompt action to publicise the breach and
inform the public of its efforts to address the breach and mitigate the adverse effects,
there was no attempt to communicate the name and contact details of the data
protection officer or other contact point for the public to get further information.
172. The DPC understands that the incident was still under investigation at the time of these
media statements and that the public should have been informed of updates as more
information was made available. The HSE did not make any further statements on the
incident. This is concerning for the following reasons:
Despite the assurances given in the M103 interview, the LIS data was not fully
restored, i.e. that personal data had been irrecoverably lost.
The forensic report did not conclusively rule out the possibility that data was
viewed and/or extracted.
173. As concluded by the Inquiry Report, a high-risk rating requires the HSE to communicate
the circumstances of the breach pursuant to Article 34(1) GDPR. The DPC finds that,
following a proper assessment of the breach, a high risk to the rights and freedoms of
84,000 data subjects should have been identified and that the HSE’s failure to
communicatefullyallrequired informationrelating tothebreachtothoseaffecteddata
subjects is a contravention of the provisions of Article 34(1) of the GDPR.
d) Conclusion on Issue 4:
174. The DPC finds that the HSE infringed Article 34 GDPR by failing to fully communicate to
theaffecteddatasubjectswithoutunduedelaythefollowinginformationrelatingtothe
breach:
that patients’ personal data had been irrecoverably lost,
that a forensic examination of the breach could not rule out that patients’
personal data had been accessed or exfiltrated, and
the name and contact details of the HSE’s data protection officer.
K. Decision on Corrective Powers
175. The DPC has set out above, pursuant to section 111(1)(a) of the 2018 Act, its decision
that the HSE has infringed Articles 5(1)(f), 28(1), 28(3), 28(9), 30(1), 32(1) and 34 GDPR.
Section 111(2) of the 2018 Act provides that, where the DPC makes a decision under
section 111(1)(a), it must, in addition, make adecision as towhether acorrective power
should be exercised in respect of the controller or processor concerned and, if so, the
corrective power to be exercised. The remaining question for determination in this
Decisioniswhetherthosefindingsmerit theexercise ofanyof the correctivepowers set
out in Article 58(2) GDPR and, if so, which corrective powers.
43176. Recital 129 GDPR assists in the interpretation of Article 58. It says in respect of the
corrective powers exercised by supervisory authorities:
… each measure should be appropriate, necessary and proportionate in view of
ensuring compliance with this Regulation, taking into account the circumstances
of each individual case ….
177. In the circumstances of this Inquiry, and with particular reference to the findings of
infringements set out above, the DPC finds that the exercise of one or more corrective
powers is appropriate, necessary and proportionate for the purpose of ensuring
compliance with the GDPR.
178. Having carefully considered the infringements identified in this Decision, the DPC has
decided to exercise the following corrective powers in accordance with section 115 of
the 2018 Act and Article 58(2) GDPR:
An order to bring its processing into compliance fine in respect of the
infringements of Articles 5(1)(f) and 32(1) GDPR.
A reprimand to the HSE in respect of its infringements of Articles 5(1)(f), 28(1),
28(3), 28(9), 30(1), 32(1) and 34 GDPR.
An administrative fine in respect of the infringements of Articles 5(1)(f) and
32(1) GDPR. The reasons for this are outlined below.
179. The DPC sets out below further detail in respect of each of these corrective powers that
it has decided to exercise and the reasons why it has decided to exercise them.
L. Order for Compliance
180. Article 58(2)(d) GDPR provides that a supervisory authority shall have the power to
‘order the controller or processor to bring processing operations into compliance with
the provisions of this Regulation, where appropriate, in a specified manner and within
a specified period.’ The DPC orders the HSE to bring its processing into compliance with
the GDPR in the terms set out in paragraphs 182 to 186 below.
181. The DPC’s decision to impose this order is to ensure that full effect is given to the HSE’s
obligation to implement appropriate technical and organisational measures to ensure a
level of security appropriate to the risk posed by the HSE’s processing. In deciding that
an order is appropriate to achieve this end, the DPC has had particular regard to the
high quantity of highly sensitive personal data processed by the HSE. The HSE must
perform the necessary risk assessment to inform the measures that it must implement.
182. The HSE is required to ensure that appropriate technical and organisational measures
are in place to protect the personal data processed in the LIS to satisfy Articles 5(1)(f)
and 32(1) GDPR, with specific regard to the elements of its National Cybersecurity Plan
not yet implemented as at the date of this decision.
44183. The HSE has outlined measures implemented since 2021 as part of its National
Cybersecurity Plan (NCSP) which have rectified many of the cybersecurity deficiencies
which led tothe Breach. The LIS environment hasnowbeen incorporated intothe HSE’s
National Data Centre. Unsecured firewall ports have been disabled and MFA has been
applied for remote access. A new Backup policy has been implemented. 71
184. In correspondence with the DPC on 16 March 2026, the HSE provided details on the
timeline for the remaining action points of its National Cybersecurity Plan. These are
Migrating the LIS into the National MedLIS solution (2026)
Managed Threat Detection & Response Service (2026)
Extended Detection & Response Service (2026)
Digital Risk Protection Service (2027)
Unified Cyber Incident Response Service (2027)
Cyber Governance, Risk, Compliance and Resilience Capability (2027)
Third Party Risk Management Service (2027)
Cyber Awareness and Training Platform (2027).
185. To ensure compliance with the GDPR, the HSE must keep the DPC informed of the
progress of these projects. It must be noted that implementing these measures does
not relieve the HSE of its obligation to continually evaluate the effectiveness of the
measures that it puts in place to ensure compliance with the GDPR.
186. The DPC imposes a deadline of 31 December 2027 for the HSE to comply with the
measures specified above. The DPC further requires the HSE, on the expiry of that
deadline, to submit a report to the DPC outlining the steps it has taken to comply with
those measures.
M.Reprimand
187. Article 58(2)(b) GDPR provides that a supervisory authority shall have the power:
to issue reprimands to a controller or a processor where processing operations
have infringed provisions of this Regulation.
71 HSE response to DPC queries, 16 March 2026.
45188. The DPC issues a reprimand to the HSE in respect of all the infringements identified in
this Decision. The purpose of the reprimand is to dissuade non-compliance with the
GDPR:
The infringements of Articles 5(1)(f) and 32(1) GDPR contributed to a higher risk of
unavailability of patient data and a possible lack of progression of medical care,
with anongoing risktopatienthealth.Therewasalso arisk ofdisclosureof patient
data to unauthorised third parties.
The infringements of Article 28 GDPR demonstrate a failure on the part of the HSE
to properly assess and, where required, adapt its processing arrangements to
comply with the heightened standards imposed by the GDPR.
The infringement of Article 30 GDPR similarly reflects a failure by the HSE to fully
assess and document its processes and procedures to ensure that it could
demonstrate compliance with the GDPR.
The failure to fully communicate all information required under Article 34(1) may
have distressed or inconvenienced data subjects affected by the breach.
TheDPCconsidersthatareprimandisnecessaryandappropriateinrespectofsuch
non-compliance in order to recognise formally the serious nature of the
infringements and to dissuade such non-compliance. The reprimand contributes
to ensuring that the HSE and other controllers and processors take appropriate
steps in relation to current and future processing operations in order to comply
with their obligations with regard to the security of personal data, the proper
management of processing contracts and communication of information about
breaches to data subjects.
N. Decision on Administrative Fines
189. Article 58(2)(i) GDPR provides that a supervisory authority shall have the power
to impose an administrative fine pursuant to Article 83, in addition to, or instead
ofmeasuresreferredtointhisparagraph,dependingonthecircumstancesofeach
individual case.
190. The purpose of administrative fines isto strengthen the enforcement of the rules of the
GDPR. 72Fines sanction non-compliance and seek to re-establish compliance with the
GDPR.
72
GDPR, Recital 148.
46191. AstheDPChasidentifiedinfringementsoftheGDPRabove,theDPCwilldecidewhether
to impose administrative fines in respect of those infringements. In conducting this
assessment, the DPC has had regard to Article 83 GDPR, which sets out ‘General
conditions for imposing administrative fines.’ The DPC has also had regard to EDPB
guidelines, which are designed to ensure a harmonised approach to fining. These
includetheEDPB’sGuidelinesonthe calculationof administrativefines(theEDPBFining
Guidelines),andtheArticle29WorkingParty’sGuidelinesontheapplicationand setting
of administrativefines(theA29WPFiningGuidelines),whichhavebeen endorsedbythe
EDPB. 73
192. As a first step, the DPC will consider whether to impose a fine by applying the criteria
set out in Article 83(2) GDPR. If the outcome of the assessment is that a fine should be
imposed,thentheDPCwillproceedtocalculatetheamount,byreferencetothecriteria
in Article 83(2) GDPR and by considering the other factors set out in Articles 83(1)-(9)
that apply in this case. In particular, Article 83(1) GDPR requires fines to be effective,
proportionate and dissuasive. These principles will inform the calculation of any fine
that is imposed in this Decision.
a) Whether to impose an administrative fine
193. Article 83(2) GDPR states,
Administrativefinesshall,dependingonthecircumstancesofeachindividualcase,
be imposed in addition to, or instead of, measures referred to in points (a) to (h)
and (j) of Article 58(2). When deciding whether to impose an administrative fine
and deciding on the amount of the administrative fine in each individual case due
regard shall be given to the following…
194. Article 83(2) goes on to list 11 criteria from (a) to (k) to be taken into account when
deciding whether to impose an administrative fine. Those provisions are set out below
where they are also applied to the infringements identified herein.
73 EDPB, ‘Guidelines 04/2022 on the calculation of administrative fines under the GDPR’, Version 2.1,
adopted 24 May 2023; Article 29 Data Protection Working Party, ‘Guidelines on the application and
setting of administrative fines for the purposes of the Regulation 2016/679’, WP 253, adopted on 3
October 2017, endorsed by the EDPB on 25 July 2018.
47 i. Article 83(2)(a) GDPR: the nature, gravity and duration of the infringement
taking into account the nature scope or purpose of the processing concerned
as well as the number of data subjects affected and the level of damage
suffered by them
195. Article 83(2)(a) requires consideration of the identified criteria by reference to ‘the
infringement’ as well as ‘the processing concerned.’ The phrase ‘the processing
concerned’ in this Article 83(2) analysis should be understood as meaning all of the
processing operations that HSE carries out on the LIS personal data under its
controllership.
196. Considering next the meaning of ‘infringement’, it is clear from Articles 83(3)-(5), that
‘infringement’meansaninfringementofaprovisionoftheGDPR.Above,HSEwasfound
to have infringed Articles 5(1)(f) and 32(1) GDPR, Article 28 GDPR, Article 30 GDPR and
Article 34 GDPR. Thus, ‘the infringement’, for the purpose of the DPC’s assessment of
the Article 83(2) criteria, should be understood (depending on the context in which the
term is used) as meaning an infringement of Articles 5(1)(f), 28(1), 28(3), 28(9), 30(1),
32(1) and 34 GDPR. While each is an individual ‘infringement’ of the relevant provision,
they all concern the processing concerned and, by reason of their common nature and
purpose, are likely to generate the same, or similar, outcomes in the context of some of
the Article 83(2) assessment criteria. Accordingly, and for ease of review, the DPC will
assess all of these infringements simultaneously, by reference to the collective term
‘infringements’ unless otherwise indicated.
197. As all of the infringements relate to the processing concerned, the considerations and
assessments set out below, save where otherwise indicated, should be understood as
being assessments of the individual Article 83(2) criteria in the context of the
infringements generally.
Taking into account the nature scope or purpose of the processing concerned as
well as the number of data subjects affected and the level of damage suffered
by them
198. This section will consider the nature scope or purpose of the processing concerned,
before considering the number of data subjects affected and the level of damage
suffered by them.
48199. The nature of the processing can include:
the context in which the processing is functionally based (e.g. business activity,
non-profit, political party, etc.) and all the characteristics of the processing.”
200. Circumstances that can lead to supervisory authorities attributing more weight to this
factor include
where the purpose is to monitor, evaluate personal aspects or to take decisions
or measures with negative effects for data subjects, where there is a clear
imbalance between the controller and data subjects or where the processing
involves children or other vulnerable data subjects. 75
201. The nature of the processing relating to the infringements identified herein is the
recording and retaining of information in relation to diagnostic test requests on a
hospital laboratory information system.
202. The scope of the processing is assessed
with reference to the local, national or cross-border scope of the processing
carried out and the relationship between this information and the actual extent
of the processing in terms of the allocation of resources by the data controller…
The larger the scope of the processing, the more weight the supervisory authority
may attribute to this factor.76
203. Thescopeoftheprocessinginthiscaseisregional,andlocalisedtopatientsoftheMRHT
LIS. The MRHT provides acute-care hospital services including a 24-hour emergency
department and is the regional centre for Orthopaedics, Otolaryngology, Oncology,
Haematology, Nephrology and Rheumatology. In turn, the LIS retains information
including Patient Name, Patient Address, Patient ID, Patient DOB, Sex, Clinical Details
(date/time of sample collection,date/time of receipt inthe laboratoryanddate/time of
report, specimen type, priority, results/reports, requesting clinician details) and a
record of communications relating to test results.
204. The EDPB Fining Guidelines state that the purpose of the processing
will lead the supervisory authority to attribute more weight to this factor. The
supervisory authority may also consider whether the processing of personal data
falls within the so-called core activities of the controller. The more central the
processing is to the controller’s or processor’s core activities, the more severe
irregularities in this processing will be. The supervisory authority may attribute
74 EDPB Fining Guidelines, para 53.b.i.
75 EDPB Fining Guidelines, para 53.b.i.
76 EDPB Fining Guidelines, para 53.b.ii.
49 more weight to this factor in these circumstances. There may be circumstances
though,inwhichtheprocessing ofpersonaldatais furtherremovedfromthecore
activities of the controller or processor, but significantly impacts the evaluation
nonetheless (this is the case, for example, of processing concerning personal data
of workers where the infringement significantly affects those workers’ dignity).7
205. The purpose of the processing relating to the infringements identified herein is to
providehealthservicestodatasubjectsandretain andprocesstestresults.Thisisacore
activity of the controller.
206. In relation to the number of data subjects, the EDPB Fining Guidelines state:
The higherthenumberofdatasubjectsinvolved,themoreweightthesupervisory
authority may attribute to this factor. In many cases, it may also be considered
that the infringement takes on "systemic" connotations and can therefore affect,
even at different times, additional data subjects who have not submitted
complaintsorreportstothesupervisoryauthority.Thesupervisoryauthoritymay,
depending on the circumstances of the case, consider the ratio between the
number of data subjects affected and the total number of data subjects in that
context (e.g. the number of citizens, customers or employees) in order to assess
78
whether the infringement is of a systemic nature.
207. Some 84,000 data subjects were impacted by the personal data breach. This is a
significant number of data subjects.
208. The level of damage is considered by reference to any harm suffered by data subjects
orthe‘extenttowhichtheconductmayaffectindividualrightsandfreedoms.’TheEDPB
Fining Guidelines note:
The referencetothe ‘level’ofdamagesuffered,therefore,isintendedtodrawthe
attention of the supervisory authorities to the damage suffered, or likely to have
been suffered as a further, separate parameter with respect to the number of
data subjects involved (for example, in cases where the number of individuals
affected by the unlawful processing is high but the damage suffered by them is
marginal). Following Recital 75 GDPR, the level of damage suffered refers to
physical, material or non-material damage. The assessment of the damage, in any
case, be limited [sic] to what is functionally necessary to achieve correct
evaluation of the level of seriousness of the infringement as indicated in
77 EDPB Fining Guidelines, para 53.b.iii.
78 EDPB Fining Guidelines, para 53.b.iv.
50 paragraph 60 below, without overlapping with the activities of judicial authorities
79
as tasked with ascertaining the different forms of individual harm.
209. The levelofdamagesufferedasaresultoftheinfringementsofArticles5(1)(f)and 32(1)
is high. The personal data affected by the HSE’s failure to adopt and maintain
appropriate security measures included health data of some 84,000 persons relating to
sensitive matters kept strictly confidential by most people. While there is no direct
evidence that the datawas subsequently misused or disclosed bythe attackers, the fact
that it had been accessed, and the uncertainty as to whether it might be misused or
disclosed must have caused distress at least to affected persons. Further, the reduced
availabilityofdatacausedbytheneedtoreverttoapaper-basedsystemislikelytohave
delayed communication of information needed to diagnose, treat or reassure patients.
210. The level of damage suffered as a result of the infringements of Articles 28 is medium.
WhiletheHSEhadsomedocumentedagreementsanddetailsofitsprocessingactivities,
these did not fully meet the requirements of the GDPR and had not been updated to
comply with it. Appropriate documentation that complied with the requirements of
those Articles would have helped to identify and highlight deficiencies in the HSE’s
technical and organisational measures for security that contributed to the
vulnerabilities exploited in the breach, and the risks posed by it.
211. The level of damage suffered as a result of the infringements of Article 30 GDPR is low.
The record produced to the DPC by the HSE recorded most of the information required
by Article 30(1) GDPR, and the information not included in it was readily accessible.
Although the record was created after date of the breach, it appears to have existed in
draft form before, indicating an awareness of the obligation to maintain such a record
and a motivation to comply with that requirement.
212. The level of damage suffered as a result of the infringement of Article 34 GDPR is low in
circumstances where, notwithstanding the HSE’s failure to assess the risk posed by the
breachtobehigh,itneverthelesspromptlytookstepsto informthepublicofthebreach
and its efforts to remediate it. While, as detailed in paragraph 174, the HSE’s Media
Communications did not include all information required by Article 34 GDPR, the DPC is
not aware of any person having suffered any loss, inconvenience or detriment as a
result.
79
EDPB Fining Guidelines, para 53.b.v.
51 The nature of the infringements
213. The EDPB Fining Guidelines state that the nature of the infringement is ‘assessed by the
concrete circumstances of the case.’ In this assessment, the supervisory authority may
review the interest that the infringed provision seeks to protect and the place of
this provision in the data protection framework. In addition, the supervisory
authority may consider the degree to which the infringement prohibited the
effective application of the provision and the fulfilment of the objective it sought
80
to protect.
214. In line with the text of the GDPR, the nature, gravity and duration of the infringements
are all assessed by taking into account the nature, scope or purpose of the processing
concerned as well as the number of data subjects affected and the level of damage
suffered by them. 81
215. The nature of the infringements of Articles 5(1)(f) and 32(1) GDPR identified herein is
the failure by the HSE to implement technical and organisational measures appropriate
to the level of risk arising from its processing of data subjects’ personal and special
category personal data on the LIS. The nature of the infringements of Article 28 GDPR
identified herein is a failure by the HSE to ensure that its agreements with the
Infrastructure Provider and the Software Provider included sufficient guarantees to
ensure that all relevant requirements of the GDPR were met and to ensure the
protections of data subjects’ rights. The HSE failed to ensure that binding agreements
were up to date at the time of the breach, and the policies and procedures for
implementing these agreements were not fully documented. This resulted in a
contravention of the provisions of Articles 28 (1), (3) and (9) GDPR.
216. The nature of the infringement of Article 30 GDPR identified herein is the failure by the
HSE to create and maintain a formal Record of Processing Activities containing all the
information required by that Article.
217. ThenatureoftheinfringementofArticle34GDPRidentifiedhereinwastheHSE’sfailure
to appropriately assess the risk to posed patients as a result of the breach to be high,
and its failure in its Media Communications to include all information required by that
provision.
80 EDPB Fining Guidelines, para 53.a.
81 Article 83(2)(a) GDPR.
52 The gravity of the infringements
218. The gravity (as well as the nature and duration of the infringements) is assessed taking
into account the nature, scope or purpose of the processing concerned as well as the
82
number of data subjects affected and the level of damage suffered by them.
219. The gravity of the infringement of Articles 5(1)(f) and 32(1) of the GDPR is serious in
circumstances where the infringement resulted in vulnerabilities that allowed the
personal data breach to occur and contributed to the risks that the breach created. The
HSE’s lack of technical and organisational measures at the time of the breach
contributed to the potential unauthorised disclosure of personal and special category
data of 84,000 data subjects, including the irretrievable loss of electronic records of
personal and special category data. There also was an adverse effect on availability of
patient’s health information, as the LIS provided ease of access for clinicians. As noted
at paragraph 143, it is not possible to know how long the attackers had access to the
system. Lastly, while there is no clear evidence that the attackers viewed or exfiltrated
clinical data, the forensic report makes it clear that such action cannot be excluded.
220. InrelationtothegravityoftheinfringementofArticle28GDPR,whiletherewasafailure
by the HSE to adhere to that provision of the GDPR in respect of its processors, the
underlying level of damage to data subjects caused by those infringements has been
identified as medium. Thus, the gravity of this infringement is moderate.
221. The gravity of the infringement of Article 30 GDPR is low. There was no Record of
Processing Activity compliant with Article 30(1) in place at the time when the breach
occurred, and some required information was not included in the record formally
approved after the breach. However, the DPC is satisfied that the record existed with
some of the relevant information.
222. The gravity of the infringement of Article 34 GDPR is moderate. The circumstances of
the breach, including the fact that special category personal data of large number of
data subjects was affected, clearly indicated a high risk, which the HSE failed to assess
properly. However, the DPC takes account of the HSE’s steps to publicise the breach –
albeit incompletely – as outlined above, and considers these a mitigating factor of
medium weight.
82
Article 83(2)(a) GDPR.
53 The duration of the infringements
223. In relation to the duration of an infringement, the EDPB Fining Guidelines state:
a supervisory authority may generally attribute more weight to an infringement
with longer duration. The longer the duration of the infringement, the more
weight the supervisory authority may attribute to this factor. 83
224. The A29WP Fining Guidelines note that duration may be illustrative of:
wilful conduct on the data controller’s part, or
failure to take appropriate preventive measures, or
inability to put in place the required technical and organisational measures. 84
225. For the purposes of this Decision, the HSE’s infringements of Articles 5(1)(f) and 32(1)
GDPR commenced on 25 May 2018, when the GDPR took effect. The obligation to
comply with Articles 5(1)(f) and 32 GDPR applied from then, and the information and
materials provided to the DPC during the course of this inquiry make clear that the
deficiencies giving rise to the infringement of those Articles were in existence from at
least that date. In its submission of 7 November 2019, the HSE stated:
The MRHT LIS infrastructure has been fully migrated to the HSE OoCIO
environment within a week of the breach occurring. The Laboratory quality
management policies have been updated to reflect this. SLAs have been drafted
to describe the new arrangements within the OoCIO environment.
The Lab server infrastructure is now managed in line with group policies. Lab
desktops are built per HSE National standards, includingAV and theinfrastructure
support is aligned with National Standards. 85
226. The DPC accepts this as evidence that the deficiencies in the HSE’s technical and
organisational measures for security of personal data processed on the LIS have been
partially recognised and addressed. Therefore, for the purposes of deciding whether to
impose an administrative fine, and for calculating the appropriate amount if applicable,
83 EDPB Fining Guidelines, para 53.c.
84 A29WP Fining Guidelines, 11.
85
HSE Submission, ‘DPC Enquiry Consolidated responses’, 7 November 2019, response to Q. 4 ‘Please
provide a detailed overview of the technical and organisational measures in place for the Tullamore Laboratory
System as a result of this breach.’
54 the DPC proceeds on the basis that the infringements of Articles 5(1)(f) and 32(1) GDPR
lasted from 25 May 2018 until no later than 7 November 2019.
227. The infringement of Article 28 GDPR identified herein similarly commenced on 25 May
2018, when the GDPR took effect. As described in Section H of this Decision, the HSE’s
agreements and arrangements with the Software Provider and the Infrastructure
Provider relating to the LIS pre-dated the entry into force of the GDPR, did not provide
for the matters required in that Article, and were not updated to do so when the GDPR
took effect. The HSE’s arrangements with the Infrastructure Provider in respect of the
LIS terminated when the LIS infrastructure was migrated to the OoCIO environment
during November 2018, and the HSE and the Software Provider entered into a new
‘Service Provider and Data Processing Agreement’ compliant with Article 28 GDPR on 8
April 2019. The duration of the infringements of Article 28 GDPR identified herein is
therefore from 25 May 2018 until 1 December 2018 in the case of the HSE’s
arrangementswiththeInfrastructureProvider,and from 25May 2018 until8April2019
in relation to the Software Provider.
228. The infringement of Article 30 GDPR similarly commenced on 25 May 2018, when the
GDPR took effect. As outlined in Section I above, the HSE’s document dated 23
86
November 2018 contained most, but not all, of the required information. However,
the DPC is satisfied that the information not included was readily accessible and that
the infringement did not persist beyond that date. The duration of the infringement is
therefore from 25 May 2018 to 23 November 2018.
229. The HSE’s infringement of Article 34 GDPR identified herein commenced when the HSE
submitted its breach notification on 16 November 2018 showing an incorrect
assessment of the risk posed by the breach as ‘medium’ rather than ‘high’. As detailed
in Section J of this Decision, the nature of the breach, the type and quantity of the
personal data affected, the failure of backup procedures and the potential harms that
unauthorised third parties might commit with the data all gave an unambiguous
indication of a high risk. The HSE should have identified notification of data subjects
under Article 34 GDPR as a priority at the time of notifying the breach on 16 November
2018.
230. Notwithstanding its incorrect assessment of the risk posed by breach, the HSE acted
promptly to bring information about the breach to public attention through the press
and broadcast media. This action commenced even before the HSE lodged its breach
notification with the DPC. However, as noted previously, the HSE did not publicly
86 MRHT Laboratory Data Protection SOP.
55 identify its Data Protection Officer or other contact point for more information, and did
not make clear that – as the External Cybersecurity Consultancy report pointed out in
December 2018 – the possibility that personal data might have been exfiltrated could
notberuledout.WhilethecontactdetailsoftheHSE’sDataProtectionOfficerareeasily
available to concerned members of the public, the DPC is not aware that the HSE has to
datemade anypublicstatement about thepossibility that personaldata affected bythe
breach may have been exfiltrated.
231. The duration of the infringement of Article 34 GDPR identified herein is therefore
ongoing from 16 November 2018.
Assessment of Article 83(2)(a)
232. Taking account of all of the factors considered in this section, the DPC assesses the
infringements of Articles 5(1)(f) and 32(1) to be of a high seriousness. This conclusion is
made having regard to the assessment above that these infringements were of a high
gravity. It also takes into consideration the nature of the infringements, which
amounted toafailuretoputinplaceappropriatetechnicalandorganisationalmeasures
to protect the personal data on the LIS. It recognises that the level of damage that may
be suffered from a failure to put technical and organisational measures in place to
protect this data is high. While the scope of the processing was localised to the systems
of the MRHT, the large number of data subjects affected is also relevant to the overall
conclusion that the infringements were of a high seriousness.
233. Takingaccountof allofthe factorsassessed above, theDPCconsidersthe infringements
of Article 28 GDPR to be of moderate seriousness. This takes account of the fact that
the infringements were of a moderate gravity and of a relatively short duration.
234. Taking account of all the factors assessed above, the infringement of Article 30 GDPR
wasoflowseriousness.Thistakesaccountoftheshortduration oftheinfringementand
the ready availability of the information not included in the version of the record of
processing activities submitted to the DPC.
235. Taking account of all the factors assessed above, the infringement of Article 34 GDPR
was of moderate seriousness. The HSE’s assessment of the risk posed by the breach
should have concluded that, in circumstances where unauthorised access to large
amounts of special category data had occurred, and where exfiltration could not be
ruled out, that the risk posed by the breach was high. A correct assessment of a high
risk would have likely prompted the HSE to consider and address all requirements of
Article 34 GDPR. Against that, the DPC takes account of the HSE’s prompt action to
inform data subjects through public media channels of the breach and actions being
56 taken to remedy it. While this action did not convey all the information required by
Article 34 GDPR, it reduces the seriousness of the infringement.
ii. Article 83(2)(b) GDPR: the intentional or negligent character of the
infringements
236. The A29WP Fining Guidelines state:
in general, intent includes both knowledge and willfulness in relation to the
characteristics of an offence, whereas ‘unintentional’ means that there was no
intention to cause the infringement although the controller/processor breached
the duty of care which is required in the law.87
237. The EDPB Fining Guidelines state:
The intentional or negligent character of the infringement (Article 83(2)(b) GDPR)
should be assessed taking into account the objective elements of conduct
gathered from the facts of the case. The EDPB highlighted that it is generally
admitted that intentional infringements, ‘demonstrating contempt for the
provisions of the law, are more severe than unintentional ones’. 88 In case of an
intentional infringement, the supervisory authority is likely to attribute more
weight tothisfactor.Dependingonthecircumstances ofthecase,thesupervisory
authority may also attach weight to the degree of negligence. At best, negligence
could be regarded as neutral.
238. In this case, the DPC finds that the infringements were not intentional. The DPC
therefore does not consider there was ‘intent’ on the part of the HSE in the sense that
there was no knowledge or wilfulness on their part in respect of their failures to ensure
compliance with the relevant provisions of the GDPR.
239. In the Article 29 Working Party Guidelines, the following examples and guidance are
given in relation to negligence:
Other circumstances, such as failure to read and abide by existing policies,human
error, failure to check for personal data in information published, failure to apply
technical updates in a timely manner, failure to adopt policies (rather than simply
failure to apply them) may be indicative of negligence.
Enterprisesshouldberesponsible foradopting structuresandresourcesadequate
tothenatureandcomplexityoftheirbusiness.Assuch,controllersandprocessors
87 A29WP Fining Guidelines, 11.
88 EDPB Fining Guidelines, paragraph 56.
57 cannot legitimise breaches of data protection law by claiming a shortage of
resources.
240. Onthebasisoftheguidelinesoutlinedabove,theDPCfindsthattheHSE’sinfringements
of Articles 5(1)(f) and 32(1) GDPR were of a negligent character for the purposes of
Article 83(2)(b). The HSE is a well-funded public body processing large amounts of
sensitive and special category personal data. It was aware that it had obligations under
the GDPR in relation to its processing of that data. The HSE failed to identify all of its
processing operations, or ensure that they were carried out in a manner that complied
with the GDPR. There was a failure to implementadequate technical and organisational
measures, which created vulnerabilities that allowed the breach to occur.
241. The DPC finds that the HSE’s infringements of Article 28 GDPR were of a negligent
character for the purposes of Article 83(2)(b). Sufficient guarantees to implement
appropriate technical and organisational measures were not in place and there was a
failure to produce formal processing agreements during the period from the entry into
effect of the GDPR to the time of the breach. The HSE’s agreements and arrangements
with the Infrastructure Provider and the Software Provider pre-dated the entry into
effect of the GDPR, but a controller with the technical and organisational resources of
the HSE could and should have recognised that its arrangements with its processors did
not comply with the standards introduced by Article 28, and should have acted to bring
them into compliance.
242. The DPC finds that the HSE’s infringement of Article 30 GDPR was of a negligent
characterforthe purposes ofArticle83(2)(b). There wasno formal Record of Processing
Activity in the form required by Article 30 GDPR in place during the period from the
entryintoeffectoftheGDPRuntil23November2018 andthatthelackofanyadequate
Record of Processing Activity that was contemporaneous with the processing activities
undertaken by MRHT at the time of the incident. The resources available to the HSE
should have enabled it to foresee the need for such records well before the GDPR took
effect, and to ensure that they were duly created and maintained. The HSE’s failure to
do so must be attributed to a lack of diligence and care.
243. The DPC finds that the HSE’s infringement of Article 34 was negligent in character for
the purposes of Article 83(2)(b) GDPR. Although the HSE rejected the DPC’s assessment
of the risk posed by the breach as being high, the HSE did so on the basis of a genuine
but, in the DPC’s considered view, misconceived assessment of the risk. The DPC is of
the view that, to justify a finding that an infringement is of an intentional character, it
must be caused by a deliberate or wilful action that knowingly or recklessly disregards
a legal obligation. The DPC does not find that the HSE’s assessment of the risk posed by
thebreachreachedthatthreshold, andthereforefindsthisinfringementtobenegligent
in character.
58 iii. Article 83(2)(c) GDPR: any action taken by the controller or processor to
mitigate the damage suffered by data subjects
244. According to the A29WP Fining Guidelines:
This provision acts as an assessment of the degree of responsibility of the
controller after the infringement has occurred. It may cover cases where the
controller has clearly not taken a negligent approach but where they have done
all they can to correct their actions when they became aware of the
infringement.89
245. In this case, HSE took measures to mitigate the damage suffered by data subjects.
Regarding the infringements of Articles 5(1)(f) and 32(1) GDPR, the HSE acted promptly
afterbecoming aware of thebreachto physicallyisolate the affected environment from
the wider HSE network.
246. The DPC also acknowledges the considerable improvements made by HSE in the
intervening period of time since the breach and its commitment to ongoing
improvements. The HSE has outlined measures implemented since 2021 as part of its
National Cybersecurity Plan (NCSP) which have rectified many of the cybersecurity
deficiencies which led to the Breach. The LIS environment has now been incorporated
into the HSE’s National Data Centre. Unsecured firewall ports have been disabled and
MFA has been applied for remote access. A new Backup policyhas been implemented. 90
247. The HSE hasdemonstrated a commitment toimplementingfurther improvements toits
Cybersecurity posture. Details of these have been outlined in the Order for Compliance
in paragraphs 180-186. In light of this, the DPC considers these mitigating factors to be
of moderate value.
248. The infringement of Article 28 GDPR identified in this Decision arose in large part from
a failure by the HSE to recognise that maintenance, servicing and support services
provided under agreements with third parties involved processing of personal data of
which the HSE was the controller. In correspondence with the DPC, the HSE indicated
that, in the time since the breach, it has adopted new procurement and review
procedures, impact assessments, and standard contract templates, which are designed
to ensure compliance with Article 28 and other provisions of the GDPR. The HSE stated
that:
In summary we have a written contract which has been validated by our legal
advisors with supporting documentation for each vendor, validate the
89 A29WP Fining Guidelines, 12-13.
90 HSE response to DPC queries, 16 March 2026.
59 documentation at thepoint ofthe contract,ensurethatDataProcessingelements
comply with the GDPR act [sic] as a minimum. In addition we have review
meetings with vendors on a regular basis to ensure that there is contract and
support compliance. 91
249. The DPC recognises that these measures demonstrate a significant improvement in the
HSE’s awareness of potential non-compliance and are an essential step in remedying
the deficiencies that led to the infringements of Article 28 GDPR in this case. The DPC
therefore considers this a mitigating factor of medium value.
250. In relation to Article 30 GDPR, the DPC notes that a compliant record of processing
activity was created after the breach. 92 The DPC considers this a mitigating factor of
medium value.
251. In relation to the infringement of Article 34, the DPC considers HSE’s engagement with
numerousmediaoutletsasamitigatingfactortotheinfringementofArticle34.TheDPC
notes that, after the HSE’s initial efforts to inform the public of the breach and efforts
to remediate it, there were no significant public updates on the breach. Further, as
noted in paragraph 174, not all required information was communicated to the public,
including that personal data had been irretrievably lost, that test results would have to
beprocessedfrommanualrecords,andthatunauthorisedviewingandexfiltrationcould
not be ruled out. Accordingly, the DPC finds that this mitigating factor to be of medium
value.
iv. Article 83(2)(d) GDPR: the degree of responsibility of the controller or
processor taking into account technical and organisational measures
implemented by them pursuant to Articles 25 and 32
252. The key question in relation to this provision is whether the HSE ‘did what it could be
expected todo given thenature, the purposes orthe size ofthe processing,seen inlight
93
of the obligations imposed on them by the Regulation.’
253. In its submissions, HSE outlined the measures that it had in place to prevent potential
data breaches. The DPC has had full regard to those measures in this Decision. This
Decision assesses whether HSE complied with its obligations under Articles 5(1)(f) and
32(1)byimplementingappropriatetechnicalandorganisationalmeasurestoensurethe
91
HSE response to DPC queries, 16 March 2026.
92 MRGT Laboratory Data Protection SOP, 2.
93 EDPB Fining Guidelines, 77.
60 requisite level of security of the Personal Data processed on the LIS environment. As
outlined earlier, the DPC finds that HSE infringed those provisions.
254. InrelationtotheinfringementsofArticles28and30(1),theHSEimplementedmeasures
to ensure compliance with those provisions in some contexts. It updated processor
contracts to bring them in line with the requirements of Article 28(3), and adapted its
organisational procedures to mitigate the risk of a recurrence of the infringement. In
relation to Articles 30(1) it formally approved documents relating to processing activity.
The DPC acknowledges that the HSE’s revised RoPA meets the requirements of Article
30 GDPR.
255. InrelationtoArticle34GDPR,theDPCnotesthattheHSE’smediaengagementfollowing
thebreachpartiallycompliedwiththerequirementtonotifydatasubjects.Whereasthe
HSE initially argued that the risk posed by the breach was medium rather than high, in
response to the Draft Decision, the HSE revised their stance on this issue and conceded
that high risk was the appropriate rating. The DPC acknowledges this response.
256. The DPC considers that the HSE holds a high degree of responsibility for all
infringements identified in this Decision. All of these infringements arose from
responsibilities that were clearly those of the HSE as the controller. However, in
circumstances where this factor forms the basis for the finding of the infringement of
Article 32 GDPR against HSE, this factor cannot be considered aggravating in respect of
the infringements. Therefore, the DPC considers that this factor is neither aggravating
nor mitigating in the circumstances.
v. Article 83(2)(e) GDPR: any relevant previous infringements by the controller or
processor
257. In line with the EDPB Fining Guidelines, prior infringements are those already
94
established before the draft decision (in the sense of Article 60 GDPR) is issued.
258. According to the A29WP Fining Guidelines, ‘[t]his criterion is meant to assess the track
record of the entity committing the infringement.’ 95
259. The DPC has concluded other inquiries into the HSE’s processing of personal data, and
has made findings of infringement in those inquiries. On 18 August 2020 and 29
September 2020, Inquiries IN-19-9-1 and IN-19-9-2 respectively made findings of
infringements of Article 5(1)(f) and 32(1) GDPR for the HSE’s failure to implement
appropriate technical and organisational measures to ensure a level of security
94 EDPB Fining Guidelines, para 82.
95 A20WP Fining Guidelines, 14.
61 appropriate to the risk. However, the DPC does not consider them to be either an
aggravating or mitigating factor in this Decision.
vi. Article83(2)(f)GDPR: the degreeof cooperationwith the supervisoryauthority,
in order to remedy the infringement and mitigate the possible adverse effects
of the infringement
260. The extent to which HSE has cooperated with the inquiry is relevant to consider under
this heading. The DPC acknowledges the HSE’s cooperation with the DPC during the
course of the Inquiry. However, the DPC notes that the HSE was, in any event, under a
duty, in light of Article 31 GDPR, to cooperate on request with the supervisory authority
in the performance of its tasks. Subsequent measures taken with regard to the
infringements of Article 5(1)(f), 28, 30 and 32(1) have been separately taken into
account as mitigating factors under Article 83(2)(c) above.
vii. Article 83(2)(g) GDPR: the categories of personal data affected by the
infringement
261. By way of example of the categories that may be relevant to consider here, the A29WP
Fining Guidelines suggest considering whether the infringements concern special
category personal data under Articles 9 or 10 GDPR, whether the data are directly or
indirectly identifiable, whether the data are encrypted, or whether the processing
involves data whose dissemination would cause immediate damage or distress to the
97
individual.
262. The processing in this case involved special category data in the form of health data.
This type of personal data, by its nature, carries a high risk to the rights and freedoms
of theaffected data subjects withtherisk ofsufferingfrom lackofadequate care arising
from the loss of health data. While it is not known whether there was unauthorised
disclosure of this personal data as a result of the personal data breach reported to the
DPC, the inadequate security measures identified in this Decision related to this special
category of personal data. The DPC finds that the sensitivity of this category of personal
data aggravates the infringement of Articles 5(1)(f) and 32(1) in circumstances where
there was a loss of confidentiality of and access to health records of 84,000 data
subjects.
96 A29WP Fining Guidelines, 14.
97 A29WP Fining Guidelines, 14.
62 viii. Article 83(2)(h) GDPR: the manner in which the infringement became known
to the supervisory authority, in particular whether, and if so to what extent,
the controller or processor notified the infringement
263. According totheA29WPFiningGuidelines,thissectioncanbe usedtoconsiderwhether
the DPC became aware of the infringement ‘as a result of investigation, complaints,
98
articles in the press, anonymous tips or notification by the data controller.’
264. The A29WP Fining Guidelines also note that,
The controller has an obligation according to the Regulation to notify the
supervisory authority about personal data breaches. Where the controller merely
fulfils this obligation, compliance with the obligation cannot be interpreted as an
attenuating/ mitigating factor. Similarly, a data controller/processor who acted
carelessly without notifying, or at least not notifying all of the details of the
infringement due to a failure to adequately assess the extent of the infringement
may also be considered by the supervisory authority to merit a more serious
penalty i.e. it is unlikely to be classified as a minor infringement.
265. In this case, the DPC became aware of the infringements as a result of a personal data
breach notification from the HSE on 16 November 2018. The HSE’s compliance with its
obligation to notify personal data breaches under Article 33(1) cannot be considered
mitigating in respect of the infringements of Articles 5(1)(f), 28, 30, 32(1) and 34 GDPR.
ix. Article 83(2)(i) GDPR: where measures referred to in Article 58(2) have
previously been ordered against the controller or processor concerned with
regard to the same subject-matter, compliance with those measures
266. The A29WP Fining Guidelines state
As opposed to the criteria in (e), this assessment criteria only seeks to remind
supervisory authoritiestorefer to measuresthattheythemselves havepreviously
issued to the same controller or processors “with regard to the same subject
matter”. 100
267. As noted above, the DPC does not consider previous infringements by the HSE are to be
relevant to this Decision.
98 A29WP Fining Guidelines, 15.
99 A29WP Fining Guidelines, 15.
100 A29WP Fining Guidelines, 15.
63 x. Article 83(2)(j) GDPR: adherence to approved codes of conduct pursuant to
Article 40 or approved certification mechanisms pursuant to Article 42
268. Such considerations do not arise in this case.
xi. Article 83(2)(k) GDPR: any other aggravating or mitigating factor applicable to
the circumstances of the case, such as financial benefits gained, or losses
avoided, directly or indirectly, from the infringement
269. The DPC considers that the matters considered under Article 83(2)(a) – (j) reflect an
exhaustive account of both the aggravating and mitigating factors applicable in the
circumstances of the case.
xii. Decision as to whether to impose a fine
270. Thedecisiontoimposeanadministrativefine‘needstobetakenonacase-by-casebasis,
101
in light of the circumstances of each individual case.’
271. In order to ensure compliance with the GDPR, it is necessary to dissuade non-
compliance. Depending on the circumstances of each individual case, dissuading non-
compliance can entail dissuading the entity concerned with the corrective measures, or
dissuading other entities carrying out similar processing operations, or both. Where a
serious infringement of the GDPR occurs, a reprimand may not be sufficient to deter
future non-compliance. In this regard, by imposing financial penalties, administrative
fines are effective in dissuading non-compliance. This is recognised by the requirement
in Article 83(1) GDPR for a fine, when imposed, to be effective, proportionate and
dissuasive. Recital 148 GDPR acknowledges that, depending on the circumstances of
each individual case, administrative fines may be appropriate in addition to, or instead
of, reprimands and other corrective powers:
In order to strengthen the enforcement of the rules of this Regulation, penalties,
including administrative fines should be imposed for any infringement of this
Regulation, in addition to, or instead of appropriate measures imposed by the
supervisory authority pursuant to this Regulation. In a case of a minor
infringement or if the fine likely to be imposed would constitute a
disproportionate burden to a natural person, a reprimand may be issued instead
of a fine.
101
EDPB, Binding Decision 1/2023.
64272. Taking into account the assessment of the criteria at (ii) to (xi) above, the DPC has
decided to impose an administrative fine for the infringements of Articles 5(1)(f) and
32(1) GDPR. This takes into account as aggravating factors the high level of seriousness
of those infringements, their negligent nature, the degree of the responsibility of the
HSE, and the fact that they impacted special category personal data. In view of the
nature and seriousness of these aggravating factors, the DPC considers that it is
appropriate to issue a fine. Although mitigating factors were identified in relation to
Article 83(2)(c) GDPR, these did not eliminate the risk to data subjects. The DPC
considers that the factors assessed in relation to Articles 83(2)(e), (f), (h), (i), (j) and (k)
are neither mitigating nor aggravating.
273. While the Order to bring the HSE’s data processing into GDPR compliance in respect of
the infringements of Articles 5(1)(f) and 32(1) GDPR will bring the HSE into compliance
and while the reprimand will assist in dissuadingthe HSE and other entitiesfrom similar
futurenon-compliance,in lightofthe seriousnessofthe infringement,theDPCdoesnot
consider that the Order or reprimand, either taken severally or together, are
proportionate or effective alone. The DPC finds that an administrative fine is necessary
in respect of the infringements of Articles 5(1)(f) and 32(1) GDPR to deter other future
serious non-compliance on the part of HSE and other controllers or processors carrying
out similar processing operations. The reasons for this finding include
The infringements of Articles 5(1)(f) and 32(1) GDPR are serious in nature and
gravity as set out pursuant to Article 83(2)(a) GDPR. Infringements that are of
aseriousnatureandgravitymustbedissuadedbothinrespectoftheindividual
controller and in respect of other entities carrying out similar processing.
Regarding the infringements of Articles 5(1)(f) and 32(1) GDPR, the DPC
considers that the HSE’s non-compliance with its obligations under these
Articles must be strongly dissuaded. Such dissuasive effect is crucial for
protecting the rights and freedoms of those data subjects by implementing
appropriate measures.
Therefore, the DPC considers that an administrative fine is appropriate and necessary
in order to dissuade non-compliance.
274. Having regard to the nature, gravityanddurationof the infringementsof Articles 5(1)(f)
and 32(1) GDPR, the DPC also considers that an administrative fine is proportionate for
ensuring compliance. The HSE’s infringementsof those Articles were a primary cause of
the data breach. In light of this damage, the DPC considers that an administrative fine is
proportionate in response to the HSE’s infringement of Articles 5(1)(f) and 32(1) GDPR
with a view to ensuring future compliance. The DPC considers that an administrative
fine does not exceed what is necessary to enforce compliance in respect of the
infringements identified in this Decision.
65275. The DPC considers that the negligent character of the HSE’s infringements of Articles
5(1)(f) and 32(1) GDPR carries weight when considering whether to impose
administrative fines, and if so, the amount of those fines. This negligence suggests that
an administrative fine is necessary to ensure that HSE directs sufficient attention to its
obligations under Articles 5(1)(f) and 32(1) GDPR in the future.
276. The DPC considers that an administrative fine would help to ensure that the HSE and
other similar controllers take the utmost care to avoid infringements of the GDPR in
respect of users’ data.
277. Regarding the HSE’s infringement of Articles 28, 30 and 34 GDPR, the DPC has taken
account of all of the factors above, and particularly the fact that the seriousness of the
infringements was moderate. The DPC has decided that in all of the circumstances, the
reprimand is are sufficient to address those infringements.
b) Decision on the amount of the administrative fine
278. Above, it was determined that it was necessary to impose an administrative fine. This
section calculates the amount of that fine, taking into account the methodology
required to be applied by the EDPB Fining Guidelines, based on the assessments of the
individual Article 83(2) GDPR criteria that are recorded above.
i. Article 83(3) GDPR
279. In accordance with Article 83(3) GDPR:
If a controller or processor intentionally or negligently, for the same or linked
processing operations, infringes several provisions of this Regulation, the total
amount of the administrative fine shall not exceed the amount specified for the
gravest infringement.
280. As outlined previously, the infringements identified herein all relate to the processing
concerned, i.e. the personal data processed on the LIS.
281. In respect of the interpretation of Article 83(3) GDPR, the DPC is mindful of its
obligations of cooperation and consistency in, inter alia, Articles 60(1) and 63 GDPR.
Accordingly, it is necessary to follow the EDPB’s interpretation of Article 83(3) GDPR
which was set out in the EDPB’s binding decision 1/2021, which was made in relation to
an inquiryconductedbytheDPC. 102Insummary,theviewoftheEDPBisthatthe correct
approach to the interpretation of Article 83(3) requires that:
102
DPC Inquiry IN-18-12-2.
66 326. Although the fine itself may not exceed the legal maximum of the highest
fining tier, the offender shall still be explicitly found guilty of having infringed
several provisions and these infringements have to be taken into account when
assessing the amount of the final fine that is to be imposed. Therefore, while the
legalmaximumofthefineissetbythegravestinfringementwithregardtoArticles
83(4)and(5)GDPR,other infringementscannotbediscardedbuthavetobe taken
into account when calculating the fine.
282. Theimpactofthisinterpretationisthatadministrativefine(s)areimposedcumulatively,
as opposed to imposing only the proposed fine for the gravest infringement. The only
applicable limit for the total fine imposed, under this interpretation, is the overall ‘cap’.
By way of example, in a case of multiple infringements, if the gravest infringement was
one which carried a maximum administrative fine of 2% of the turnover of the
undertaking, the cumulative fine imposed could also not exceed 2% of the turnover of
the undertaking.
283. In this case, the DPC has decided to impose a fine for the identified infringements of
Articles 5(1)(f) and 32(1) GDPR. The gravest infringement is that of Article 5(1)(f) GDPR
as it is an infringement of a core principle of the GDPR.
ii. Categorisation of the infringements under Articles 83(4)-(6) GDPR
284. Articles 83(4)-(6) GDPR set out the caps that apply under the GDPR. The EDPB Fining
Guidelinessaythatthecategorisationof infringementsunderArticle83(4)-(6)GDPRcan
be used to determine the starting point for further calculation. Those Guidelines note
that
With this distinction, thelegislatorprovided a firstindication of the seriousness of
the infringement in an abstract sense. The more serious the infringement, the
higher the fine is likely to be.
The categorisation of the infringements under Articles 83(4) or (5) is a relevant
consideration in assessing the seriousness of the infringements in this case. The
infringement of Article 5(1)(f) found in this case relates to the basic principles of
processing and is ascribed considerably greater significance, with the legislator
providing for, in general, maximum administrative fines double those applicable to the
infringements of Articles 32(1), 28 and 33(1).
67 iii. Seriousness of the infringement pursuant to Articles 83(2)(a), (b) and (g) GDPR
285. The EDPB Guidelines state that the factors assessed in relation to Articles 83(2)(a), (b)
and (g) GDPR indicate the seriousness of the infringement. 103 These factors were
assessed in paragraphs 213 to 240 and 261 to 262 above. The guidelines also state that
This assessment is no mathematical calculation in which the abovementioned
factors are considered individually, but rather a thorough evaluation of the
concrete circumstances of the case, in which all of the abovementioned factors
are interlinked. Therefore, in reviewing the seriousness of the infringement,
104
regard should be given to the infringement as a whole.
286. Having regard to these factors as a whole, the infringements are of a medium to high
levelofseriousness.UnderArticle83(2)(a)theinfringementsofArticles5(1)(f)and32(1)
were found to be of a serious nature and have a high degree of gravity. The
infringements affected special category personal data relating to health which, by their
nature, carry a risk with regard to the fundamental rights and freedoms of 84,000 data
subjects, as assessed under Article 83(2)(g). The infringements were also of a negligent
character, asassessed under Article 83(2)(b). The infringementsare found to have been
of moderate duration. Therefore, balancing these factors, the DPC considers that the
infringements were of high seriousness.
iv. Imposing an effective, dissuasive and proportionate fine
287. Article 83(1) GDPR requires a fine to be effective, proportionate and dissuasive in each
individual case. As the guidelines also say that this doesn’t ‘dismiss a supervisory
authority from the responsibility to carry out a review of the effectiveness,
dissuasiveness and proportionality at the end of the calculation.’ 105Article 83(1) will be
considered again at the end of this calculation.
v. Aggravating and mitigating circumstances
288. Articles 83(2)(a), (b) and (g) GDPR were considered above in relation to the starting
point for the calculation of the fine. In line with the approach suggested in the EDPB
Fining Guidelines, 106this section considers the aggravating or mitigating impact of the
remaining criteria in Article 83(2) GDPR.
103
EDPB Fining Guidelines, paragraph 51.
104 EDPB Fining Guidelines, paragraph 59.
105 EDPB Fining Guidelines, paragraph 64.
106 EDPB Fining Guidelines, paragraph 70.
68289. In relation to Article 83(2)(c), the DPC notes that the HSE adopted measures to mitigate
the damage to data subjects. The DPC considers this a mitigating factor of moderate
weight, as there remain concerns regardingthe HSE’s abilityto safeguard against future
attacks.
290. In relation to Article 83(2)(d), the DPC notes that the HSE had a high degree of
responsibility for the infringements. The DPC consider this factor to be aggravating, as
the HSE did not do what could be expected to be done in the circumstances. The failure
toadopttechnical andorganisational measuresisnotinitself, aggravating,asthisforms
the basis for the infringements identified.
291. In relation to Article 83(2)(e), the DPC notes that the HSE has had previous
infringements, but that these were neither mitigating nor aggravating in the
circumstances.
292. In relation to Article 83(2)(f), the DPC notes that the HSE cooperated with the DPC. As
the HSE has a general obligation to cooperate under Article 31 GDPR, this factor is
considered to be neither mitigating nor aggravating.
293. In relation to Article 83(2)(h), the DPC notes that the manner in which the infringement
became known to the DPC was through a notification of a personal data breach from
the HSE on 16 November 2018. This factor is considered to be neither mitigating nor
aggravating.
294. Inrelationto Article83(2)(i),the DPCnotesthatnomeasureshadpreviouslybeenmade
107
by the DPC with regard to the same subject matter.
295. In relation to Article 83(2)(j), the DPC has found no relevant approved codes of conduct
or approved certification mechanisms. This factor is therefore not applicable.
296. In relation to Article 83(2)(k), the DPC notes that there were no additional aggravating
or mitigating factors for consideration. This is factor is therefore not applicable.
107
Paragraph 101 of the EDPB Fining Guidelines says in relation to this provision: ‘…as opposed to Article
83(2)(e) GDPR, this assessment only refers to measures that supervisory authorities themselves have
previously issued to the same controller or processor with regard to the same subject matter.’ In its
Decision on inquiry IN-19-9-1 (issued on 18 August 2020) the DPC imposed administrative fines and
issued a reprimand to the HSE for infringements of Articles 5(1)(f) and 32 GDPR. However, the
processing concerned in that case related to hard copy records and the DPC does not consider that it
concerns the same subject matter.
69297. Taking into account all of the matters arising for consideration as part of the individual
assessments required to be carried out pursuant to Article 83(2), together with the
recommendations in the Fining Guidelines as detailed above, the DPC imposes an
administrative fine of €300,000 in respect of the infringement of Articles 5(1)(f) and
32(1) GDPR.
298. This fine is at the lower end of the range proposed in the Draft Decision. The DPC’s
choice of this level of administrative fine reflects the mitigation occasioned by the HSE
in acknowledging flaws in its technical and organisations measures, indicating its
commitment to compliance and protecting data protection rights and promptly making
significant improvements in order to reducethe likelihoodof similarbreaches occurring
in the future.
vi. The relevant legal maximums for the different processing operations
The relevant undertaking for the purposes of the fine calculation
299. TheDPCnotesthattheStatehasexerciseditsrightunderArticle83(7)GDPRtolaydown
rules on the extent to which administrative fines may be imposed on public authorities
and bodies, and enacted section 141 of the Act of 2018 setting the maximum fine on
such authorities and bodies at €1,000,000.
300. The DPC notes that the HSE is a public authority (as defined in section 2(1) of the 2018
Act), having been established under the Health Act 2004. Section141(4)ofthe 2018 Act
provides that any administrative fine that the DPC decides to impose on a public
authority or public body shall not exceed €1,000,000 unless that authority or body acts
as an undertaking within the meaning of the Competition Act 2002. As the
administrative fine imposed in this Decision does not exceed that amount, it is not
necessary for the DPC to determine whether the HSE acts as an undertaking for the
purpose of the processing concerned.
vii. Article 83(1) GDPR: Effectiveness, proportionality and dissuasiveness
Effectiveness
301. It is the DPC’s view that for a fine to be effective, it must be large enough to have a
significant effect on the controller or processor such that GDPR compliance, motivated
by avoiding such fines in the future, becomes a factor in the entity’s governance and
management decision-making at the highest level. Furthermore, a sufficiently large fine
is necessaryto ensure that the fine is not just an insignificant expense for the controller
or processor concerned, and to ensure that the controller or processor does not enjoy
70 an unfair advantage by reason of its ability to absorb even large fines for its
infringements of the GDPR.
302. In the DPC’s view, the levels of the fine imposed in this Decision ensure a sufficiently
effective fine, and no further adjustment is required.
Dissuasiveness
303. In order for a fine to be dissuasive, it must dissuade both the controller or processor
concerned, as well as other controllers or processors carrying out similar processing
operations,fromrepeatingthe conductconcerned.TheDPCconsidersthattheimposed
fineisdissuasiveinbothof these respects.TheDPC considersthemonetaryvalue ofthe
fine to be sufficient to have such a deterrent effect.
304. In coming to this conclusion, the DPC has considered that the fine imposed is dissuasive
having regard to the severity of the infringements and the resources of the HSE. The
DPC considers that thefine will bedissuasivefor the HSE and other controllers in similar
positions.
Proportionality
305. Proportionality is a principle of EU law that requires a measure to pursue a legitimate
objective, be appropriate to attain that objective, and not go beyond what is necessary
toachievetheobjective.Theobjectivesoftheadministrativefineinthiscasearetoboth
re-establish compliance with the rules and to sanction the HSE’s infringements. For a
fine to be necessary to these objectives, the DPC must adjust the quantum of any fine
to the minimum necessary to achieve the objectives pursued by the GDPR.
306. The DPC is satisfied that the fine imposed above does not exceed the minimum
necessary to enforce compliance with the GDPR. The infringements relate to the
security measures applicable to health data, were negligent, and the HSE had a high
degree of responsibility for them. Overall, the DPC is satisfied that the imposed fine
complies with the principle of proportionality.
71O. Summary of Envisaged Action
307. In summary, the corrective powers that the DPC has decided to exercise are:
an Order to bring processing into compliance in respect of the HSE’s
infringement of Articles 5(1)(f) and 32(1) GDPR;
a Reprimand to the HSE pursuant to Article 58(2)(b) GDPR regarding the
infringements identified in this Decision
and an administrative fine in respect of the HSE’s infringement of Articles
5(1)f and 32(1) GDPR of €300,000.
P. Right of Appeal
308. This Final Decision is issued in accordance with section 111 of the 2018 Act. Pursuant to
section 150(5)ofthe 2018Act,theHSEhastherightto appealagainstthisFinalDecision
within 28 days from the date on which notice it is served on it. Pursuant to section 142
of the 2018 Act, as the Final Decision imposes an administrative fine, the HSE also has
the right to appeal under that section within 28 days from the date on which notice of
the Final Decision is given to it.
This Decision is addressed to
The Health Service Executive
Dr. Steevens' Hospital, Steeven's Lane,
Dublin 8, D08 W2A8
Ireland
_________________________ _________________________
Dr. Des Hogan Dale Sunderland
Commissioner for Data Protection Commissioner for Data Protection
Chairperson
72




