[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fc5ArKsdyLbai5iDceu8K6vnnNsbbiuzQQi6h0EXcHgU":3},{"article":4,"iocs":57},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"92847b2c-0d77-4ab6-8e88-a6e758331575","DPC (Ireland) - IN-19-9-4","dpc-ireland-in-19-9-4-bab556","Created page with \"{{DPAdecisionBOX |Jurisdiction=Ireland |DPA-BG-Color= |DPAlogo=LogoIE.png |DPA_Abbrevation=DPC |DPA_With_Country=DPC (Ireland) |Case_Number_Name=IN-19-9-4 |ECLI= |Original_Source_Name_1=DPC |Original_Source_Link_1=https:\u002F\u002Fwww.dataprotection.ie\u002Fsites\u002Fdefault\u002Ffiles\u002Fuploads\u002F2026-08\u002F05.08.2026%20IN-19-9-4%20FD%20redacted.pdf |Original_Source_Language_1=English |Original_Source_Language__Code_1=EN |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Langua...\" Show changes","Ireland's Data Protection Commission (DPC) has fined the Health Service Executive (HSE) €300,000 for inadequate security measures that led to a ransomware attack. The attack, which exploited an unsecured firewall port and a weak password, affected the Laboratory Information System (LIS) and encrypted data for approximately 84,000 individuals. The DPC found violations of GDPR articles related to security, processing agreements, and breach notification.","Ireland's DPC fines HSE €300,000 for inadequate security leading to ransomware attack.","Help DPC (Ireland) - IN-19-9-4: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 13:42, 13 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators254 edits Tag: Decisions [1.0] (No difference) Latest revision as of 13:42, 13 August 2026 DPC - IN-19-9-4 Authority: DPC (Ireland) Jurisdiction: Ireland Relevant Law: Article 5(1)(f) GDPR Article 28 GDPR Article 30 GDPR Article 32(1) GDPR Article 34 GDPR Type: Investigation Outcome: n\u002Fa Started: 08.10.2019 Decided: 10.06.2026 Published: Fine: n\u002Fa Parties: Health Service Executive (HSE) National Case Number\u002FName: IN-19-9-4 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): English Original Source: DPC (in EN) Initial Contributor: bms The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts On 14 November 2018, a ransomware attack affected the Laboratory Information System (LIS) of the Midland Regional Hospital Tullamore, which formed part of the Health Service Executive (HSE), the controller. The attack caused the LIS database server to go offline and encrypted data stored on several devices, including backup devices connected to the affected servers. The attackers accessed the system through an unsecured firewall port and exploited a weak administrator password. The forensic investigation could not conclusively rule out that personal data had been viewed or exfiltrated. Moreover, electronic records created between June 2017 and November 2018 could not be recovered. The affected information included identifying and contact data as well as clinical information and test results, constituting health data. The controller initially estimated that 50,000 data subjects were affected but subsequently increased this figure to approximately 84,000. On 16 November 2018, the controller notified the personal data breach to the DPA. It classified the breach as presenting a medium risk and therefore did not individually notify the affected data subjects. Instead, information about the incident was provided through public communications. On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the controller had complied with its obligations under the GDPR in relation to the security of the LIS, its arrangements with processors, its records of processing activities and its response to the personal data breach. Holding The DPA found that the controller infringed Articles 5(1)(f) and 32(1) GDPR because it had failed to implement technical and organisational measures appropriate to the high risks associated with processing large quantities of health data. In particular, the DPA identified several security deficiencies, including an unsecured remote-access port without multi-factor authentication, a weak administrator password, ineffective intrusion detection and prevention, outdated anti-virus protection, a device running an unsupported operating system, a lack of encryption at rest, insufficient vulnerability and penetration testing, inadequate network segmentation and backup systems that were not sufficiently separated from the affected network. The DPA also noted a lack of effective centralised security oversight. These deficiencies allowed the attackers to access the LIS and move laterally across the network. The DPA also found a violation of Articles 28(1), 28(3) and 28(9) GDPR. Two external companies maintained the infrastructure and software used by the LIS and qualified as processors. However, the agreements governing these relationships did not provide sufficient guarantees regarding data protection and security and did not contain the mandatory provisions required under Article 28 GDPR. Furthermore, the DPA found a violation of Article 30(1) GDPR because the controller did not have a compliant record of processing activities in place at the time of the breach. Although certain documentation existed in draft form, it did not contain all required information, including the contact details of the DPO, retention periods and categories of recipients. Finally, the DPA held that the controller infringed Article 34 GDPR. Considering the sensitive nature of the health data, the number of affected data subjects and the possibility that data had been accessed or exfiltrated, the breach should have been classified as presenting a high risk to the rights and freedoms of approximately 84,000 data subjects. Although the DPA accepted that individual communication would have involved disproportionate effort and that a public communication could therefore be used, the controller's public communications were incomplete. In particular, they did not inform data subjects that some personal data had been irrecoverably lost, that access to or exfiltration of data could not be ruled out, or provide the contact details of the DPO. The DPA imposed an administrative fine of €300,000 for the infringements of Articles 5(1)(f) and 32(1) GDPR. It also reprimanded the controller for all identified infringements and ordered it to bring its processing into compliance with Articles 5(1)(f) and 32(1) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the English original. Please refer to the English original for more details. In the matter of the General Data Protection Regulation DPC Case Reference: IN-19-9-4 In the matter of Health Service Executive Decision of the Data Protection Commission under Section 111 of the Data Protection Act 2018 Further to an own-volition inquiry under Section 110 of the Data Protection Act 2018 DECISION Decision-Maker for the Data Protection Commission: Dr Des Hogan, Commissioner for Data Protection and Mr Dale Sunderland, Commissioner for Data Protection. 10 June 2026 Data Protection Commission 6 Pembroke Row Dublin 2, Ireland 1Contents Contents..................................................................................................................................................2 A. Introduction....................................................................................................................................4 B. Personal data breaches...................................................................................................................5 a) Data controller......................................................................................................................6 C. Legal Framework for the Inquiry and the Decision.........................................................................7 a) Legal basis for the Inquiry.....................................................................................................7 b) Legal basis for the Decision...................................................................................................7 D. Factual Background and Material Considered for the Purposes of this Decision ..........................7 a) Controller overview ..............................................................................................................7 b) Impact of the breach.............................................................................................................8 c) Breach response....................................................................................................................9 d) Inquiry IN-19-9-4.................................................................................................................10 E. Scope of the Inquiry................................................................................................","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DPC_(Ireland)_-_IN-19-9-4&diff=52692&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F8\u002F82\u002FLogoIE.png","2026-08-13T13:42:17+00:00","2026-08-13T14:00:16.62238+00:00",8,[18,21,24,26,29],{"name":19,"type":20},"DPC","vendor",{"name":22,"type":23},"Laboratory Information System (LIS)","product",{"name":25,"type":23},"firewall",{"name":27,"type":28},"attackers","threat_actor",{"name":30,"type":20},"Health Service Executive (HSE)","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":31,"icon":33,"name":34,"slug":35},null,"Policy","policy",[37,42,47,52],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":48},{"id":49,"icon":33,"name":50,"slug":51},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":53},{"id":54,"icon":33,"name":55,"slug":56},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[58],{"type":51,"value":59,"context":60},"ransomware","Ransomware attack on HSE's LIS"]