Case Study 18: Health Service Executive [2012] IEDPC 18 (2012)

Case Study 18: Health Service Executive [2012] IEDPC 18 (2012)

The HSE failed to ensure staff adherence to established procedures for secure fax transmission of sensitive data, resulting in repeated unauthorized disclosures despite prior recommendations and remedial measures.

Citation
[2012] IEDPC 18
Parties
Data Controller: Health Service Executive; Regulator: Irish Data Protection Commission
Jurisdiction
Ireland
Procedural Posture
Data Protection Investigation / Decision
Outcome
breach found
Legal Topics
Data Breach, Patient Confidentiality, Fax Transmission Error, Organizational Measures

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 1 Authorities cited 1 Party arguments 2 Amounts and remedies 1
Sign in to unlock

Parties

Health Service Executive

Data Controller

Irish Data Protection Commission

Regulator

Procedural Posture

Data Protection Investigation / Decision

  1. 1 Whether the HSE failed to implement adequate measures to prevent unauthorized disclosure of patient data via fax
  2. 2 Whether the HSE complied with prior recommendations from the Data Protection Commission

Ratio Decidendi

The HSE failed to ensure staff adherence to established procedures for secure fax transmission of sensitive data, resulting in repeated unauthorized disclosures despite prior recommendations and remedial measures.

Court Disposition

breach found

Orders

  • HSE to reinforce staff training and adherence to fax procedures
  • HSE to implement additional technical and organizational safeguards, including a dedicated fax number and visible instructions on all machines