In the matter of the General Data Protection Regulation
DPC Case Reference: IN-19-9-2
In the matter of The Health Service Executive (Our Lady of Lourdes Hospital, Drogheda)
Decision of the Data Protection Commission made pursuant to Section 111 of the Data Protection Act
2018
Further to an own-volition inquiry commenced pursuant to Section 110 of the Data Protection Act 2018
DECISION
Decision-Maker for the Commission:
Helen Dixon
Commissioner for Data Protection
29 September 2020
Data Protection Commission
2 Fitzwilliam Square South
Dublin 2, Ireland
Contents
1. Introduction .................................................................................................................................... 4
2. Legal Framework for the Inquiry and the Decision......................................................................... 4
i. Legal Basis for the Inquiry ........................................................................................................ 4
ii. Data Controller .......................................................................................................................... 5
iii. Legal Basis for the Decision ...................................................................................................... 5
3. Factual Background ......................................................................................................................... 5
4. Scope of the Inquiry and the Application of the GDPR ................................................................... 7
5. Inquiry IN-19-9-1 ............................................................................................................................. 8
6. Analysis and Findings .................................................................................................................... 10
i. Assessing Risk ............................................................................................................................ 11
ii. Security Measures Implemented by the HSE............................................................................ 11
a) Measures implemented locally ............................................................................................. 11
b) Measures implemented nationally ....................................................................................... 12
iii. The Appropriate level of Security ............................................................................................. 14
iv. Finding ....................................................................................................................................... 16
7. Decision on Corrective Powers ..................................................................................................... 16
8. Right of Appeal.............................................................................................................................. 16
Appendix: Schedule of Materials Considered for the Purposes of this Decision ............................... 18
1. Introduction
1.1 This document (“the Decision”) is the decision made by the Data Protection Commission (“the
DPC”) in accordance with Section 111 of the Data Protection Act 2018 (“the 2018 Act”). I make
this Decision having considered the information obtained in the separate own volition inquiry
(“the Inquiry”) conducted by an Authorised Officer of the DPC (“the Case Officer”) pursuant
to Section 110 of the 2018 Act. The Case Officer provided the Health Service Executive (“the
HSE”) with the Draft Inquiry Report and the Final Inquiry Report. The scope of the Inquiry is
to examine whether or not the HSE has discharged its obligations in connection with the
subject matter of personal data breach BN-19-5-26 and determine whether or not any
provision(s) of the 2018 Act and/or the General Data Protection Regulation (“the GDPR”) has
been contravened by the HSE in that context.
1.2 The HSE was provided with the Draft Decision on this Inquiry on 24 August 2020 to provide it
with a final opportunity to make submissions. The HSE made submissions on 14 September
2020 and those submissions have been given full consideration for the purposes of this
Decision. This Decision is being provided to the HSE pursuant to Section 116(1)(a) of the 2018
Act in order to give the HSE notice of the Decision and the reasons for it.
2. Legal Framework for the Inquiry and the Decision
i. Legal Basis for the Inquiry
2.1 The GDPR is the legal regime covering the processing of personal data in the European Union.
As a regulation, the GDPR is directly applicable in EU member states. The GDPR is given further
effect in Irish law by the 2018 Act. As stated above, the Inquiry was commenced pursuant to
Section 110 of the 2018 Act. By way of background in this regard, under Part 6 of the 2018
Act, the Commission has the power to commence an inquiry on several bases, including on
foot of a complaint, or of its own volition.
2.2 Section 110(1) of the 2018 Act provides that the Commission may, for the purpose of Section
109(5)(e) or Section 113(2) of the 2018 Act, or of its own volition, cause such inquiry as it
thinks fit to be conducted, in order to ascertain whether an infringement has occurred or is
occurring of the GDPR or a provision of the 2018 Act, or regulation under the Act, that gives
further effect to the GDPR. Section 110(2) of the 2018 Act provides that the Commission may,
for the purposes of Section 110(1), where it considers it appropriate to do so, cause any of its
powers under Chapter 4 of Part 6 of the 2018 Act (excluding Section 135 of the 2018 Act) to
be exercised and / or cause an investigation under Chapter 5 of Part 6 of the 2018 Act to be
carried out.
ii. Data Controller
2.3 In commencing the Inquiry, the Case Officer considered that the HSE may be the controller,
within the meaning of Article 4(7) of the GDPR, in respect of the personal data that was the
subject of Breach BN-19-5-26. In this regard, the submissions made by HSE during the course
of the Inquiry made clear that it determines the purposes and means of the processing under
consideration, and, thus, is a data controller in respect of the personal data subject to BN-19-
5-26.
iii. Legal Basis for the Decision
2.4 The decision-making process for this Inquiry is provided for under Section 111 of the 2018 Act,
and requires that the Commission must consider the information obtained during the Inquiry;
to decide whether an infringement is occurring or has occurred; and if so, to decide on the
corrective powers, if any, to be exercised. As the sole member of the Commission, I perform
this function in my role as the decision-maker in the Commission. In so doing, I am required
to carry out an independent assessment of all of the materials provided to me by the Case
Officer as well as any other materials which have been furnished to me by the HSE, and any
other materials which I consider to be relevant, in the course of the decision-making process.
2.5 The Final Inquiry Report was transmitted to me on 27 April 2020, together with the Case
Officer’s file, containing copies of all correspondence exchanged between the Case Officer
and the HSE; and copies of all submissions made by the HSE, including the submissions made
by the HSE in respect of the Draft Inquiry Report. A full schedule of all documentation
considered by me for the purpose of my preparation of this Decision is appended hereto. I
issued a letter to the HSE on 5 August 2020 to notify it of the commencement of the decision-
making process.
2.6 Having reviewed the Final Inquiry Report, and the other materials provided to me by the Case
Officer (including the submissions made by the HSE), I was satisfied that the Inquiry was
correctly conducted and that fair procedures were followed throughout, including, but not
limited to, notifications to the controller and opportunities for the controller to comment on
the Draft Inquiry Report before it was submitted to me as decision-maker.
3. Factual Background
3.1 The HSE notified the DPC of personal data breach BN-19-5-26 on 1 May 2019. The HSE became
aware of the personal data breach on 30 April 2019 when a member of the public informed
them that they had found documents in their front garden, which is near Our Lady of Lourdes
Hospital. The documents in question were handover notes, generated by the HSE to identify
patients who come under staff care at each shift change. The notes are necessary for
continuing patient care and treatment. The notes contained the personal data of 15 data
subjects and included data relating to clinical information and treatments received. The notes
were printed on 11 April 2019, but the HSE was unable to specify the date on which the breach
initially occurred. The notes have not been accounted for between the date they were printed
and when they were found. A member of the HSE’s Quality & Risk Department retrieved the
pages from the member of the public immediately after being notified. The HSE subsequently
contacted the data subjects and informed them of the breach.
3.2 The HSE initiated an investigation into the personal data breach. The investigation report,
dated 17 June 2019, outlines how the nurse who lost the notes intended to dispose of them
before leaving the hospital at the end of shift. However, they forgot to dispose of them and
lost them on the way home. Following the breach, the HSE circulated a notice to all staff in
Our Lady of Lourdes Hospital reminding them of their obligation to comply with the hospital’s
standard operating procedures for the use of confidential paper waste consoles.
3.3 The Case Officer informed the HSE of the commencement of the Inquiry by way of a Notice of
Commencement of Inquiry (“the Notice”) on 26 November 2019. The Notice set out the scope
and legal basis of the Inquiry. The decision to commence the Inquiry was taken having regard
to the circumstances of personal data breach BN-19-5-26. The Notice informed the HSE that
the Inquiry would examine whether or not the HSE discharged its obligations in connection
with the subject matter of that personal data breach and determine whether or not any
provision(s) of the 2018 Act and/or the GDPR had been contravened by the HSE in that
context. In this regard, the scope of the Inquiry was expressly stated to include Articles 5(1)(f)
and 32(1) of the GDPR, with focus on the areas of Data Protection Governance, Training and
Awareness, Records Management, and Security of Personal Data. The Notice also stated that
personal data breach BN-19-5-26 was the second such occurrence involving the inappropriate
disposal of patient records in the HSE Dublin North East region, and noted the similarities with
the breach that occurred on 6 March 2019 (BN-19-3-179). The Notice set out that the Inquiry
would formally document the facts as they relate to the subject of the Inquiry. The facts, as
established during the course of the Inquiry, are set out below. The Notice also invited the
HSE to make submissions on the background outlined in the Notice and to make submissions
regarding its compliance with Articles 5(1)(f) and 32(1) of the GDPR.
3.4 The HSE acknowledged receipt of the Notice by telephone on 10 December 2019. The Case
Officer provided the HSE with the Draft Inquiry Report on 31 January 2020. The Draft Inquiry
Report set out the Case Officer’s provisional views as to the facts identified and views as to
whether the HSE had complied with its obligations under the 2018 Act and the GDPR. The HSE
made submissions on the Draft Inquiry Report on 3 March 2020. Those submissions identified
factual inaccuracies in the Draft Inquiry Report and made submissions on Data Protection
Governance, Training and Awareness, Record Management, and Security of Personal Data at
Our Lady of Lourdes Hospital and the HSE. Those submissions also appended a number of
documents relevant to the scope of the Inquiry. Those documents are considered throughout
this Decision and are listed in the Schedule appended to this Decision at numbers (xiii) – (xxv).
3.5 The Case Officer wrote to the HSE on 5 March 2020 enclosing a number of specific follow up
questions and seeking further submissions on the measures that were in place at the time of
the personal data breach to comply with Articles 5(1)(f) and 32(1) of the GDPR. The HSE made
further submissions on 20 March 2020. These submissions added to the submissions made on
3 March 2020 and detailed the availability of shredding bins and the standard operating
procedure that was in place for their use. The submissions also set out the education, training
and awareness that was in place, including signage on all wards and training areas and how
self-accountability is promoted. The submissions also outlined how the IPIMs and Trendcare
systems automatically print the name of the person who printed lists at the end of the pages.
3.6 On 27 April 2020, the Case Officer completed the final Inquiry Report and submitted it to me
as decision-maker. I have considered the Inquiry Report and all relevant correspondence and
submissions. The HSE was provided with my Draft Decision on 24 August 2020 and was
afforded the opportunity to make submissions on the infringements that were provisionally
identified therein. On 14 September 2020, the HSE made submissions and I have given full
consideration to those submissions. I have reached final conclusions that infringements of
data protection legislation have occurred. Those infringements are set out in this Decision.
4. Scope of the Inquiry and the Application of the GDPR
4.1 The scope of the Inquiry, which was set out in the Notice of the Commencement of the
Inquiry, is to examine whether or not the HSE has discharged its obligations in connection
with the subject matter of personal data breach BN-19-5-26 and determine whether or not
any provision(s) of the Act and/or the GDPR have been contravened by the HSE in that
context. In this regard, the Notice of Commencement of Inquiry specified that the Inquiry
would focus on Data Protection Governance; Training and Awareness; Records
Management; and Security of Personal Data.
4.2 As outlined above, personal data breach BN-19-5-26 occurred when a nurse inadvertently
took handover documents outside of Our Lady of Lourdes Hospital in their coat pocket and
lost the documents. Having reviewed the Inquiry Report and the other materials provided to
me, I consider that the issue in respect of which I must make a decision is whether the HSE
has complied with its obligations under Articles 5(1)(f) and 32(1) of the GDPR, in connection
with personal data breach BN-19-5-26, regarding its use and disposal of hardcopy documents
containing patients’ personal data. Articles 5(1)(f) and 32(1) oblige the HSE to implement an
appropriate level of security in respect of those processing operations.
4.3 The Notice of Commencement of Inquiry referred to another personal data breach that the
HSE notified to the DPC. The information obtained in relation to that personal data breach
is relevant to the scope of the Inquiry insofar as it details the level of security implemented
by the HSE regarding its use and disposal of hardcopy documents. BN-19-3-173 concerns a
similar incident to BN-19-5-26, in which a staff member accidentally took hardcopy
documents containing medical information outside the hospital and lost them.
4.4 Article 2(1) of the GDPR defines the Regulation’s scope as follows:
“This Regulation applies to the processing of personal data wholly or partly by
automated means and to the processing other than by automated means of personal
data which form part of a filing system or are intended to form part of a filing system.”
4.5 The manual processing of hardcopy documents falls within the scope of the GDPR only if the
personal data within those documents form part of a filing system or are intended to form
part of a filing system.
4.6 Article 4(6) of the GDPR defines “filing system”:
“‘filing system’ means any structured set of personal data which are accessible
according to specific criteria, whether centralised, decentralised or dispersed on a
functional or geographical basis;”
4.7 Recital 15 provides guidance for interpreting the material scope of the GDPR:
“In order to prevent creating a serious risk of circumvention, the protection of natural
persons should be technologically neutral and should not depend on the techniques
used. The protection of natural persons should apply to the processing of personal
data by automated means, as well as to manual processing, if the personal data are
contained or are intended to be contained in a filing system. Files or sets of files, as
well as their cover pages, which are not structured according to specific criteria should
not fall within the scope of this Regulation.”
4.8 Medical files form part of a “filing system” because they contain the personal data of patients
and are accessible according to specific criteria, such as the patient’s name or other
identifier. Therefore, any personal data processed by the HSE that are intended to form part
of medical files fall within the scope of the GDPR, regardless of whether such personal data
are actually stored in such files. This prevents controllers from attempting to circumvent the
GDPR by processing personal data manually and/or outside of their usual filing systems. The
handover lists in BN-19-5-26 contained special category personal data concerning health.
Therefore, I am satisfied that some of the personal data on those documents are also
intended to be recorded separately in a filing system. Therefore, even where that personal
data are recorded separate to the filing system, the GDPR is applicable on the basis that the
personal data concerning health is intended to be recorded in the medical files.
5. Inquiry IN-19-9-1
5.1 The DPC commenced a separate inquiry (IN-19-9-1) on 17 October 2019 in respect of a
personal data breach that occurred in Cork University Maternity Hospital. The scope of that
Inquiry was to examine whether or not the HSE discharged its obligations in connection with
the subject matter of that personal data breach and to determine whether any provision(s) of
the 2018 Act and/or the GDPR has been contravened. The personal data breach in IN-19-9-1
occurred when documents were taken outside of Cork University Maternity Hospital and
disposed of it in a public recycling area. Thus, the Decision in respect of IN-19-9-1 considered
whether the HSE has complied with its obligations under Articles 5(1)(f) and 32(1) of the GDPR
in connection with its processing operations concerning its use and disposal of hardcopy
documents containing patients’ personal data. The DPC issued its Decision to the HSE on 18
August 2020 and found that the HSE infringed Articles 5(1)(f) and 32(1) of the GDPR by failing
to implement appropriate technical and organisational measures to ensure a level of security
appropriate to the risk presented by those processing operations. The duration of those
infringements found in that Decision concerned the period of 25th May 2018 to 4th June 2019.
5.2 Regarding Inquiry IN-19-9-2, the personal data breaches under consideration in this Decision
occurred on 6 March 2019 and 30 April 2019 respectively. As outlined above, the processing
under consideration in this Decision also concerns the HSE’s use and disposal of hardcopy
documents containing patients’ personal data. The issue for consideration in this Decision is
whether the HSE has complied with its obligations under Articles 5(1)(f) and 32(1) of the GDPR
in respect of these processing operations. Therefore, the same processing operations are
under consideration in this Decision as were under consideration in Decision IN-19-9-1.
Furthermore, the personal data breaches under consideration in this Decision occurred during
the period under consideration in Decision IN-19-9-1.
5.3 This Decision must independently consider the appropriateness of the measures
implemented by the HSE at the time of BN-19-5-26. The HSE’s submissions make clear that it
implemented certain measures in Our Lady of Lourdes Hospital that were not implemented
in the hospital where the breach in Decision IN-19-9-1 occurred. The scope of this Inquiry is
specific to personal data breach BN-19-5-26 and, therefore, this Decision must consider
measures that were implemented in Our Lady of Lourdes Hospital, even if those measures
had not been implemented by the HSE in other regions. Therefore, it does not necessarily
follow from the findings of infringements in Decision IN-19-9-1 that the HSE has failed to
discharge its obligations in connection with the subject matter of personal data breach BN-
19-5-26. This Decision must consider the technical and organisational measures that the HSE
implemented both on an organisation-wide basis and locally to determine whether it has
discharged its obligations in connection with the subject matter of personal data breach BN-
19-5-26.
5.4 Inquiries IN-19-9-1 and IN-19-9-2 were each commenced to document the facts, and to
assess, as appropriate, whether or not the HSE has discharged its obligations in connection
with the respective personal data breaches under consideration in each inquiry. Both inquiries
were conducted in a manner that ensured that fair procedures were followed throughout,
including by ensuring that there was no pre-judgment of the issues arising for consideration
in each inquiry. Articles 5(1)(f) and 32(1) of the GDPR oblige controllers and processors to
implement appropriate technical and organisational measures to ensure a level of security
appropriate to the risk presented by its processing of personal data. Hence, controllers and
processors must consider the risk presented by each of its processing operations and must
implement appropriate measures in respect of each of those processing operations. The HSE,
as controller of the personal data subject to personal data breach BN-19-5-26, and as
controller of the personal data subject to the breach considered in Decision IN-19-9-1, is
responsible for implementing an appropriate level of security and for demonstrating
compliance pursuant to Articles 5(2) and 24(1) of the GDPR. The processing operations in both
inquiries concern the HSE’s use and disposal of hardcopy documents containing patients’
personal data and the Commission must make a decision under Section 111 of the 2018 Act
in respect of each inquiry commenced under Section 110 of that same Act.
6. Analysis and Findings
6.1 Having reviewed the Inquiry Report and the other materials provided to me, I consider that
the issue in respect of which I must make a decision is whether the HSE has discharged its
obligations, in connection with the subject matter of personal data breach BN-19-5-26, by
implementing appropriate technical and organisational measures pursuant to Articles 5(1)(f)
and 32(1) of the GDPR regarding its use and disposal of hardcopy documents containing
patients’ personal data.
6.2 Article 5(1)(f) of the GDPR provides for the principle of integrity and confidentiality. It
requires that personal data shall be:
“processed in a manner that ensures appropriate security of the personal data,
including protection against unauthorised or unlawful processing and against
accidental loss, destruction or damage, using appropriate technical or organisational
measures”
6.3 Article 32(1) of the GDPR elaborates on the principle in Article 5(1)(f) by setting out criteria
for assessing what constitutes “appropriate security” and “appropriate technical or
organisational measures”:
“Taking into account the state of the art, the costs of implementation and the nature,
scope, context and purposes of processing as well as the risk of varying likelihood and
severity for the rights and freedoms of natural persons, the controller and the
processor shall implement appropriate technical and organisational measures to
ensure a level of security appropriate to the risk, including inter alia as appropriate:
(a) the pseudonymisation and encryption of personal data;
(b) the ability to ensure the ongoing confidentiality, integrity, availability and
resilience of processing systems and services;
(c) the ability to restore the availability and access to personal data in a timely
manner in the event of a physical or technical incident;
(d) a process for regularly testing, assessing and evaluating the effectiveness of
technical and organisational measures for ensuring the security of the
processing.”
6.4 Articles 5(1)(f) and 32(1) of the GDPR oblige controllers and processors to implement a level
of security appropriate to the risks presented by its processing of personal data. The
processing operations within the scope of this Decision concern the HSE’s use and disposal
of hardcopy documents containing patients’ details. In considering the technical and
organisational measures that the HSE was obliged to implement, regard must be had to the
risk presented to the rights and freedoms of natural persons by those processing operations.
Therefore, the first step is to assess this risk.
i. Assessing Risk
6.5 The HSE confirmed in its submissions dated 20 March 2020 that it had not conducted a risk
assessment in respect of the processing at the time of personal data breach BN-19-5-26.
As outlined in Decision IN-19-9-1, the HSE’s use and disposal of hardcopy documents
containing patients’ personal data presents a high risk, both in likelihood and severity, to the
rights and freedoms of natural persons. The risk relates to the potential for an unauthorised
disclosure of patient personal data where hardcopy documents are not stored or disposed of
securely. The number of staff, the quantity of documentation that they are required to
handle, and the transient nature of some of that documentation creates a high risk that the
documents may not be stored or disposed of securely. A risk of unauthorised disclosure
naturally follows from this risk. The high severity of the risk to the rights and freedoms of
natural persons occurs due to the sensitive nature of the processing that the HSE undertakes
and the purposes for which it is undertaken. The provision of health and personal social
services is intrinsically linked to the rights and freedoms of patients, and unauthorised
disclosures of health data has significant capacity to infringe those rights and freedoms. The
technical and organisational measures that the HSE is obliged to implement must be
appropriate to this risk.
ii. Security Measures Implemented by the HSE
6.6 The HSE’s submissions outline the technical and organisational measures that it had in place
at the time of personal data breach BN-19-5-26. The submissions detail measures that are
specific to Our Lady of Lourdes Hospital and measures that were implemented on an
organisation-wide basis by the HSE. This Decision will first consider the measures
implemented locally, and, second, the measures implemented nationally.
a) Measures implemented locally
6.7 The HSE made submissions in relation to its procedure titled, “Louth Hospitals Procedure for
Use of Confidential Paper Waste Console”, which was developed in June 2018 and issued to
staff on numerous occasions since 2018. This standard operating procedure defines how
secure shredding is implemented at Our Lady of Lourdes Hospital and Louth County Hospital.
It provides that all staff are responsible for ensuring the proper disposal of confidential
material that they handle and requires ward and department managers to communicate the
procedure to all staff. The procedure sets out a process for how confidential waste is to be
stored pending its disposal, and how waste paper consoles are to be located and maintained.
A contracted company carries out confidential waste shredding and it issues a certificate of
destruction on completion.
6.8 The HSE submitted a list of the locations of confidential waste consoles throughout Our Lady
of Lourdes Hospitals and submitted that the consoles display a notification regarding the
shredding of handover sheets. Posters are located throughout the hospital to remind staff to
dispose of the handover sheets prior to departing from the Hospital. There is an annual audit
carried out at Louth Hospitals in relation to Healthcare records to ensure adherence to the
standard imposed by the hospitals.
6.9 The HSE’s submissions outline how it promotes training and awareness on data protection to
staff specifically at Our Lady of Lourdes Hospital. Data protection training forms part of the
induction programme for new starters at Louth Hospitals. Training events and presentations
were arranged for existing staff at Louth Hospitals in 2018 in advance of the GDPR coming
into force. The HSE Deputy Data Protection Officer and the Consumer Affairs unit provide
ongoing face-to-face presentations and training at Louth Hospitals on data protection. 881
staff have attended that training up to the end of 2019. The HSE’s submissions dated 3 March
2020 outline a significant amount of communications made by the Deputy Data Protection
Officer to staff at Our Lady of Lourdes Hospital in order to raise awareness about data
protection requirements. The General Manager of Our Lady of Lourdes Hospital made similar
communications to the heads of departments and to staff generally, including
communications concerning security of data and confidential waste shredding. A GDPR
Survey was also undertaken at Our Lady of Lourdes Hospital to promote awareness of data
protection.
6.10 The HSE implemented a programme of data protection compliance inspections, with 157
such inspections being undertaken in the Dublin North East region from 2014 – 2018. The
inspections entail face-to-face interviews with staff. Some inspections are unannounced and
undertaken following personal data breaches.
6.11 Regarding handover lists, the HSE submitted that the number of lists printed each day is
limited to number of staff rostered. Furthermore, the IPIMS management system and the
Trendcare Access system promote accountability by including a footer on each page
identifying the username and time of printing. However, this does not promote individual
accountability for each list because the lists are printed and then circulated amongst staff. In
this regard, the HSE submitted that staff will be required staff to sign the lists when receiving
them in the future.
b) Measures implemented nationally
6.12 The HSE’s Data Protection Policy, Version 1.0, dated 25 May 2018, was in place at the time of
the notified personal data breaches. The Policy applies to all HSE staff, students, interns and
work experience candidates, amongst others. Section 6.8 provides:
“All persons covered under this policy are prohibited from disclosing a data subject’s
confidential information (including personal data or special categories of personal
data), unless this policy or a legal basis allows for such disclosures.”
6.13 The HSE’s booklet, “Data Protection is Everyone’s Responsibility”, includes a confirmation to
all managers that staff in their area have read and understand the Data Protection Policy. The
HSE requires all managers to hold a copy of the signed undertaking in relation to staff in their
respective areas of responsibility1.
6.14 The HSE “Waste Management Awareness Handbook”, Rev A, dated 2014, sets out polices for
various types of waste. It requires shredding of confidential documents before recycling.
However, the HSE does not have any standard operating procedure that determines how the
particularly high-risk handover lists and inpatient lists must be created, used, and disposed
of.
6.15 The HSE’s “Standards and Recommended Practices for Healthcare Records Management”,
Rev 3.0., dated May 2014, comprehensively sets out standards for the HSE’s responsibilities
in respect of healthcare records management. It places responsibility on all line managers to
ensure adequate training of staff and to apply the appropriate recommended practices in
relation to healthcare records management2. The document also provides for security,
stating that “Every healthcare record is confidential and as such should be kept secure at all
times”3.
6.16 The HSE also made submissions on codes and manuals implemented by the Nursing and
Midwifery Board of Ireland (the “NMBI”) and the Code of Ethics for the lrish Medical Council
(“the IMC”). The NMBI and IMC are statutory bodies that regulate the nursing and midwifery
professions and doctors in Ireland. Such codes and manuals are not measures implemented
by the HSE and the HSE, as data controller, is ultimately responsible for ensuring an
appropriate level of security. However, in assessing the appropriate level of security, it is
appropriate to have regard to the context in which the processing occurs. Therefore, I
consider that binding professional standards imposed on members of regulated professions
may be relevant to a controller’s assessment of the technical and organisational measures
that it is obliged to implement. Without prejudice to the obligation on the HSE, as controller,
to implement an appropriate level of security, in assessing the appropriate technical and
organisational measures that must be implemented, I accept that I must have regard to
collaboration between the HSE, training schools, and the regulated professions. While this
context is relevant to assessing the measures that are appropriate to the risk, the HSE, as
data controller, is responsible for ensuring that appropriate security measures are
implemented. The NMBI’s “Code of Professional Conduct and Ethics for Registered Nurses
and Registered Midwives”, dated December 2014, details the principle of trust and
confidentiality and provides that “Patients have a right to expect that their personal
information remains private”. The HSE’s submissions also outlined how its Doctors work
under the Code of Ethics for the Irish Medical Council and how confidentiality forms part of
the HSE contract for all staff.
1
HSE submissions on the Draft Decision, dated 13 September 2020.
2
At page 123.
3
At page 131.
6.17 The HSE also submitted its “Information Technology Security Policy”, Rev 3.0, dated February
2013. This policy concerns information technology security and resources. This policy is not
applicable to the risk presented by the HSE’s use and disposal of hardcopy documents
containing patients’ personal data. Therefore, the content of those policies fall outside the
scope of this Decision.
6.18 The HSE implemented an online “Fundamentals of GDPR” training programme. The
programme provides a comprehensive introduction to the GDPR. As of 31 December 2019,
2,270 staff from the RCSI Hospital Group had completed the programme. The HSE was unable
to provide individual hospital statistics. The HSE also provided customised GDPR Awareness
sessions to hospitals and community services. The HSE promotes GDPR training with its staff
using national broadcast emails and on the HSE intranet. The HSE, at corporate level, has
issued broadcasts to staff regarding data protection since 2013. It facilitated a number of
“town hall” style GDPR awareness sessions in hospitals to improve data privacy vigilance.
6.19 The HSE tests and evaluates the effectiveness of its technical and organisational measures
through a Data Protection Audit Programme in the Dublin North East region. Furthermore, all
managers commensurate with Grade Vlll and above are required to sign a Controls Assurance
Statement, which confirms compliance with Data Protection Policies and Procedures. As
outlined above, the HSE also undertakes a significant number of data protection compliance
inspections in the Dublin North East region.
iii. The Appropriate level of Security
6.20 Decision IN-19-9-1 considered the level of security implemented in Cork University Maternity
Hospital, and found that the lack of a standard operating procedure concerning secure
shredding infringed Articles 5(1)(f) and 32(1) of the GDPR. It is important to acknowledge that
Louth Hospitals did have an appropriate procedure in place at the time of personal data
breach BN-19-5-26. As outlined above, the HSE implemented a standard operating procedure
setting out how secure shredding is to be implemented in Louth Hospitals. The document
titled “Louth Hospitals Procedure for Use of Confidential Paper Waste Console” gives clear
instruction for putting into practice the HSE’s policy of shredding confidential documents. It
sets out accountability for ensuring secure disposal of confidential waste, how confidential
waste is to be stored pending its disposal, and how waste paper consoles are located and
maintained. The existence of this procedure in Louth Hospitals must be commended, despite
the fact that equivalent procedures are not available in other HSE regions.
6.21 However, the procedure for the use of confidential consoles alone is not sufficient in respect
of the risks presented by the HSE’s processing. Having regard to the particularly high risk
presented by the HSE’s use and disposal of handover lists, I find that an appropriate level of
security must also include a standard operating procedure for handover lists, which sets out
responsibility for the secure creation, use, and disposal of the lists. The HSE implemented
various policies concerning the confidentiality of patients’ health data. Furthermore, Our
Lady of Lourdes Hospital has undertaken significant steps to promote staff awareness of the
secure disposal of handover lists. However, in light of the frequency with which the lists are
created and disposed of, there remains a significant risk that staff may inadvertently disclose
or lose handover lists. General prohibitions on unlawful disclosures are not sufficient to
protect against this risk. A specific process that incorporates data secure practices is
appropriate in light of the sensitivity of personal data contained on the lists and the speed at
which the HSE generates and disposes of the lists.
6.22 The HSE must determine the provisions of the handover list standard operating procedure
based on its own risk assessment and in light of its own functions. I note the HSE’s submission
that staff will be required to sign the lists when receiving them to promote accountability.
The HSE may also consider an IT solution or a sign-off sheet where staff confirm that they
have safely disposed of lists at the end of each shift. The HSE must determine which measures
to adopt to ensure accountability for secure disposal of the lists, and the precise content of
the procedure, in light of a broader assessment of its functions and the risk. However, the
handover lists procedure must provide clear instructions to staff as to how the lists can be
shared, when and how they must be disposed of, and responsibility for ensuring they are
disposed of securely. In addition to general awareness amongst staff, a process for promoting
individual accountability for the disposal of the lists at the end of each shift is also
appropriate. The procedure should also set out the managerial responsibility for bringing the
procedure to the attention of staff members.
6.23 Having regard to the high risk to the rights and freedoms of data subjects presented by the
HSE’s use and disposal of hardcopy documents containing patients’ personal data, an
appropriate level of security must include significant staff training to ensure that staff give
effect to the HSE’s policies and processes. As outlined above, Louth Hospitals provide data
protection training to new staff and on-going training for existing staff. The HSE also provides
the online “Fundamentals of GDPR” training on an organisation-wide basis. The HSE has also
issued a number of broadcasts to staff with regard to data protection since 2013. However,
the HSE presented no evidence of measures in place to ensure that existing staff partake in
the on-going refresher training provided in Louth Hospitals. Furthermore, the HSE presented
no evidence of measures in place to ensure that staff complete the “Fundamentals of GDPR”
training. 2,270 staff from the RCSI Hospital Group had completed the programme as of 31
December 2019, however this is a fraction of the total number of staff employed in the
Group, and no hospital-specific figures are available. I find that the appropriate level of
security requires measures to ensure completion of available training by all staff. I find that
the organisational measures implemented by the HSE in this regard were not appropriate to
the risk.
6.24 I have had regard to the state of the art and the cost of implementing a standard operating
procedure for handover lists and measures to ensure the completion of existing HSE training.
I am satisfied that implementing the measures would not impose a cost that is
disproportionate to the risk. Therefore, the failure to implement the measures infringes
Article 5(1)(f) and 32(1) of the GDPR in the circumstances.
iv. Finding
6.25 I find that the HSE infringed Articles 5(1)(f) and 32(1) of the GDPR by failing to implement
appropriate technical and organisational measures to ensure a level of security appropriate
to the risk presented by its use and disposal of hardcopy documents containing patients’
personal data in connection with the subject matter of personal data breach BN-19-5-26. The
measures that ought to have been implemented include a standard operating procedure that
sets out responsibility for the secure creation, use, and disposal of handover lists; and
measures to ensure completion of existing HSE data protection training.
7. Decision on Corrective Powers
7.1 I have set out above, pursuant to Section 111(1)(a) of the 2018 Act, my decision to the effect
that the HSE has infringed Articles 5(1)(f) and 32(1) of the GDPR. Under Section 111(2) of the
2018 Act, where the Commission makes a decision (in accordance with Section 111(1)(a)), it
must, in addition, make a decision as to whether a corrective power should be exercised in
respect of the controller or processor concerned and, if so, the corrective power to be
exercised.
7.2 Pursuant to Section 111(2), I have decided that it is not appropriate to exercise corrective
powers in this Decision. I have made this decision in light of the findings of infringements and
the corrective powers exercised in Decision IN-19-9-1. That Decision considered the same
processing operations, undertaken by the same controller, during the same period under
consideration in this Decision. Furthermore, the finding of infringements found in this
Decision mirror the infringements found in Decision IN-19-9-1 and do not identify any
additional measures that the HSE ought to have implemented.
7.3 Decision IN-19-9-1 ordered the HSE to bring its processing operations, regarding the use and
disposal of hardcopy documents containing patients’ personal data, into compliance with
Articles 5(1)(f) and 32(1) of the GDPR. The HSE has commenced a process to mitigate the risk
associated with those processing operations. The order made in Decision IN-19-9-1 sets out
measures that must be implemented by the HSE. I consider that, if this Decision made an
order, it would simply repeat the order already made. Furthermore, the imposition of other
corrective measures in this Decision, would not be appropriate in circumstances where
Decision IN-19-9-1 has already imposed a reprimand and an administrative fine in respect of
the HSE’s failure to implement the measures identified in this Decision. Therefore, this
Decision will not exercise corrective powers in respect of the infringements found herein.
8. Right of Appeal
8.1 This Decision is issued in accordance with Section 111 of the 2018 Act. Pursuant to Section
150(5) of the 2018 Act, the HSE has the right to appeal against this Decision within 28 days
from the date on which notice of the Decision is received by it.
Helen Dixon
Commissioner for Data Protection
Appendix: Schedule of Materials Considered for the Purposes
of this Decision
The Case Officer delivered the Final Inquiry Report to me on 27 April 2020. I was also provided with
all of the correspondence and submissions received in compiling the report, including:
i. The DPC’s Final Inquiry Report, Inquiry Reference IN-19-9-02;
ii. Breach Notification Form BN-19-3-172;
iii. Correspondence between the DPC and the HSE in respect of Breach Notification
Form BN-19-3-172;
iv. Breach Notification Form BN-19-5-26;
v. HSE investigation regarding BN-19-5-26, dated 17 June 2019;
vi. The HSE’s Waste Management Awareness Handbook, dated 2014
vii. HSE Data Protection Policy, dated 25 May 2018
viii. HSE Information Technology Security Policy, dated February 2013;
ix. DPC Notice of Commencement of an Inquiry, dated 17 November 2019 ;
x. HSE Code of Governance, dated July 2011;
xi. DPC Report “Data Protection Investigation in the Hospitals Sector”, dated May
2018;
xii. HSE’s submissions on the Draft Inquiry Report, dated 3 March 2020;
xiii. Summary of information provided by the Deputy Data Protection Officer to heads
of department at Louth Hospitals,
xiv. List of HSE GDPR/Data Protection Policies,
xv. Document outlining how data protection matters were communicated to heads
of department from the Regional Manager of Consumer Affairs from 2012 – 2017,
xvi. List of HSE National IT Security Policies,
xvii. Memorandum from the Director of Nursing to the Nursing Team dated 2 May
2019;
xviii. Template data breach checklist;
xix. List of training awareness events held in advance of the GDPR coming into force
in 2018;
xx. Pre-GDPR emails regarding data protection notices and alerts;
xxi. Confidential console lists including locations;
xxii. Louth Hospitals Procedure for Use of Confidential Paper Waste Console;
xxiii. Memorandum addressed to staff in Louth Hospitals concerning security and
confidentiality under the Data Protection Acts 1988 and 2003;
xxiv. Statement by Our Lady of Lourdes Hospital regarding the personal data breach;
xxv. The GDPR poster awareness campaign November/December 2018;
xxvi. Correspondence from the DPC to the HSE dated 5 March 2020;
xxvii. HSE submissions from 20 March 2020;
xxviii. HSE document, “About Human Resources”, dated 16 April 2020;
xxix. Chapter 9 of the HSE Code of Governance, submitted separately to the HSE Code
of Governance, dated July 2011;
xxx. HSE “Standards and Recommended Practices for Healthcare Records
Management”, Rev 3.0, dated May 2014; and
xxxi. The HSE’s submissions on the Draft Decision by email, dated 14 September 2020.