Key Takeaways

  • Thousands of HSE medical files are reportedly stored in an unlocked former morgue and nearby outbuildings at Cottage Hospital, Drogheda.
  • The disclosure follows a Data Protection Commission inquiry into 12 HSE facilities and total fines of €645,000.
  • The case highlights how physical records can create security, availability and retention risks comparable with poorly governed digital data.

Thousands of paper medical files are being kept in an unlocked former morgue and surrounding outbuildings at Cottage Hospital in Drogheda, according to The Irish Sun. The HSE said the County Louth site is being prioritised through its national records-management programme.

The disclosure puts a local example behind a much broader governance problem. Healthcare security discussions tend to focus on ransomware, compromised accounts and vulnerable clinical systems. Yet paper files can expose equally sensitive information when access controls, environmental protection and disposal processes break down.

That distinction matters. There is no indication in the supplied findings that every exposed file was accessed by an unauthorised person. But GDPR security obligations address risk, not just confirmed misuse. An unlocked storage area containing medical information can raise questions about who could enter, whether access is logged and whether missing records would even be detected.

The Drogheda report comes shortly after the Data Protection Commission completed an inquiry covering 12 HSE storage facilities. Inspectors found records affected by mould, water, rubble and animal contamination. Some were held in derelict buildings or rooms without functioning lighting or heating.

Those conditions create two related risks. Confidential information might be viewed or removed without authorisation. At the same time, damaged or disorganised files may become unavailable when clinicians, administrators, patients or legal teams need them. Information security, in other words, is not only about keeping people out. It also involves preserving the usability and integrity of the record.

The DPC imposed total fines of €645,000, described as its largest penalty against a public body, and issued corrective orders covering audits, stronger controls and safe destruction. The findings included infringements of GDPR Article 5(1)(f), which concerns integrity and confidentiality; Article 32, covering security of processing; and Article 5(1)(e), the storage-limitation principle. The European Data Protection Board also published details of the decision.

Retention creates an awkward operational balance. HSE guidance generally calls for patient records to be retained for the patient’s lifetime plus eight years after death. Long retention periods can be justified by continuing care, litigation and accountability requirements. They also produce a large physical archive that needs controlled access, indexing, environmental protection and documented destruction.

Keeping a file for decades does not mean leaving it where space happens to be available. Records awaiting destruction still contain protected data. Each box should remain identifiable, retrievable and secured until disposal is authorised and recorded. Otherwise, an organisation may know that it owns a large archive without knowing precisely what it contains, where individual files sit or when their retention periods expire.

Can digitisation solve the problem? Partly. Scanning can improve retrieval and reduce dependence on ageing buildings, but it also introduces classification, quality-control and access-management work. A poor digital migration can reproduce the same disorder on servers. Organisations also need to establish whether scanned copies satisfy clinical, evidential and retention requirements before original documents are destroyed.

For the HSE, the immediate challenge is likely to involve more than fitting locks. A credible remediation programme would typically map each storage location, inventory the records, restrict and monitor access, assess environmental damage, identify files eligible for destruction and document every transfer. External providers such as Iron Mountain and Restore Records Management can support storage or destruction, although accountability for lawful processing remains with the HSE.

The Cottage Hospital case therefore carries a wider lesson for public bodies and regulated businesses. Legacy paper is still part of the information estate. If it sits outside central governance, procurement controls and security monitoring, it can become an invisible liability. The HSE’s national programme now has an opportunity to turn a troubling storage site into a repeatable model for discovering, securing and reducing records risk across the health service.