DPC (Ireland) - IN-19-9-4
Ireland's DPC fines HSE €300,000 for GDPR violations after ransomware attack.
Summary
Ireland's Data Protection Commission (DPC) has fined the Health Service Executive (HSE) €300,000 for inadequate security measures that led to a ransomware attack. The attack affected the health data of 84,000 individuals and resulted in violations of GDPR Articles 5(1)(f), 32(1), 28, 30, and 34. The DPC cited numerous security deficiencies, including an unsecured remote-access port, weak passwords, outdated antivirus, and lack of encryption, which allowed attackers to compromise the LIS system.
Full text
Help DPC (Ireland) - IN-19-9-4: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 13:42, 13 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators257 edits Tag: Decisions [1.0] Latest revision as of 10:20, 18 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators257 editsTag: Visual edit Line 100: Line 100: }}}} The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of [[Article 28 GDPR|Articles 28]], [[Article 30 GDPR|30]] and [[Article 34 GDPR|34 GDPR]]. == English Summary ==== English Summary == Line 114: Line 114: On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the controller had complied with its obligations under the GDPR in relation to the security of the LIS, its arrangements with processors, its records of processing activities and its response to the personal data breach.On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the controller had complied with its obligations under the GDPR in relation to the security of the LIS, its arrangements with processors, its records of processing activities and its response to the personal data breach. === Holding ====== Holding === The DPA found that the controller infringed Articles 5(1)(f) and 32(1) GDPR because it had failed to implement technical and organisational measures appropriate to the high risks associated with processing large quantities of health data.The DPA found that the controller infringed [[Article 5 GDPR|Articles 5(1)(f)]] and [[Article 32 GDPR|32(1) GDPR]] because it had failed to implement technical and organisational measures appropriate to the high risks associated with processing large quantities of health data. In particular, the DPA identified several security deficiencies, including an unsecured remote-access port without multi-factor authentication, a weak administrator password, ineffective intrusion detection and prevention, outdated anti-virus protection, a device running an unsupported operating system, a lack of encryption at rest, insufficient vulnerability and penetration testing, inadequate network segmentation and backup systems that were not sufficiently separated from the affected network. The DPA also noted a lack of effective centralised security oversight. These deficiencies allowed the attackers to access the LIS and move laterally across the network.In particular, the DPA identified several security deficiencies, including an unsecured remote-access port without multi-factor authentication, a weak administrator password, ineffective intrusion detection and prevention, outdated anti-virus protection, a device running an unsupported operating system, a lack of encryption at rest, insufficient vulnerability and penetration testing, inadequate network segmentation and backup systems that were not sufficiently separated from the affected network. The DPA also noted a lack of effective centralised security oversight. These deficiencies allowed the attackers to access the LIS and move laterally across the network. The DPA also found a violation of Articles 28(1), 28(3) and 28(9) GDPR. Two external companies maintained the infrastructure and software used by the LIS and qualified as processors. However, the agreements governing these relationships did not provide sufficient guarantees regarding data protection and security and did not contain the mandatory provisions required under [[Article 28 GDPR|Article 28 GDPR]].The DPA also found a violation of [[Article 28 GDPR|Articles 28(1)]], [[Article 28 GDPR|28(3)]] and [[Article 28 GDPR|28(9) GDPR]]. Two external companies maintained the infrastructure and software used by the LIS and qualified as processors. However, the agreements governing these relationships did not provide sufficient guarantees regarding data protection and security and did not contain the mandatory provisions required under [[Article 28 GDPR]]. Furthermore, the DPA found a violation of [[Article 30 GDPR|Article 30(1) GDPR]] because the controller did not have a compliant record of processing activities in place at the time of the breach. Although certain documentation existed in draft form, it did not contain all required information, including the contact details of the DPO, retention periods and categories of recipients.Furthermore, the DPA found a violation of [[Article 30 GDPR|Article 30(1) GDPR]] because the controller did not have a compliant record of processing activities in place at the time of the breach. Although certain documentation existed in draft form, it did not contain all required information, including the contact details of the DPO, retention periods and categories of recipients. Finally, the DPA held that the controller infringed [[Article 34 GDPR|Article 34 GDPR]]. Considering the sensitive nature of the health data, the number of affected data subjects and the possibility that data had been accessed or exfiltrated, the breach should have been classified as presenting a high risk to the rights and freedoms of approximately 84,000 data subjects. Although the DPA accepted that individual communication would have involved disproportionate effort and that a public communication could therefore be used, the controller's public communications were incomplete. In particular, they did not inform data subjects that some personal data had been irrecoverably lost, that access to or exfiltration of data could not be ruled out, or provide the contact details of the DPO.Finally, the DPA held that the controller infringed [[Article 34 GDPR]]. Considering the sensitive nature of the health data, the number of affected data subjects and the possibility that data had been accessed or exfiltrated, the breach should have been classified as presenting a high risk to the rights and freedoms of approximately 84,000 data subjects. Although the DPA accepted that individual communication would have involved disproportionate effort and that a public communication could therefore be used, the controller's public communications were incomplete. In particular, they did not inform data subjects that some personal data had been irrecoverably lost, that access to or exfiltration of data could not be ruled out, or provide the contact details of the DPO. The DPA imposed an administrative fine of €300,000 for the infringements of Articles 5(1)(f) and 32(1) GDPR. It also reprimanded the controller for all identified infringements and ordered it to bring its processing into compliance with Articles 5(1)(f) and 32(1) GDPR.The DPA imposed an administrative fine of €300,000 for the infringements of [[Article 5 GDPR|Articles 5(1)(f)]] and [[Article 32 GDPR|32(1) GDPR]]. It also reprimanded the controller for all identified infringements and ordered it to bring its processing into compliance with [[Article 5 GDPR|Articles 5(1)(f)]] and [[Article 32 GDPR|32(1) GDPR]]. == Comment ==== Comment == Latest revision as of 10:20, 18 August 2026 DPC - IN-19-9-4 Authority: DPC (Ireland) Jurisdiction: Ireland Relevant Law: Article 5(1)(f) GDPR Article 28 GDPR Article 30 GDPR Article 32(1) GDPR Article 34 GDPR Type: Investigation Outcome: n/a Started: 08.10.2019 Decided: 10.06.2026 Published: Fine: n/a Parties: Health Service Executive (HSE) National Case Number/Name: IN-19-9-4 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): English Original Source: DPC (in EN) Initial Contributor: bms The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alon