Last updated 1 month ago
The Health Service Executive (HSE), Ireland's public healthcare provider, was fined €300,000 by the Data Protection Commission (DPC) for a breach of patient personal data at the Midland Regional Hospital, Tullamore. The breach occurred in 2018 via a ransomware attack on the laboratory information system. The DPC announced its final decision on the fine following an inquiry into the incident.
The attack vector was ransomware, which encrypted the laboratory information system and compromised patient personal data. The specific ransomware variant or threat actor was not disclosed in the article. The data compromised included patient personal data, though the exact types (e.g., names, medical records) were not specified.
The DPC imposed a €300,000 fine under data protection regulations. The article does not mention any other post-incident developments such as litigation, ransom payment, or remediation milestones.
Ransomware attack on laboratory information system
The HSE's failure to adequately protect patient data in the laboratory information system against ransomware highlights the need for robust backup and disaster recovery procedures, as well as regular security assessments and employee training to prevent such attacks. The significant fine underscores the regulatory consequences of inadequate data protection measures in healthcare.
Sign in to join the discussion.
Company
Industry
Location
Discovered
Disclosed
Records Affected
Attack Vector