GetMySAR

GetMySAR Ireland

Getting your medical records in Ireland

HSE, hospital, GP or private clinic — your records are yours to see. Which of the two legal routes to use, who to actually send the request to, and what a complete response looks like.

1. Two legal routes to the same records

In Ireland you can ask for your health records under either of two laws, and which one applies depends on who holds the records:

  • A subject access request under the GDPR — works against any holder of your records: the HSE, voluntary hospitals, private hospitals and clinics, GPs, consultants, physiotherapists, counsellors. Free, one-month deadline.
  • The Freedom of Information Act 2014 — works against public FOI bodies, which include the HSE and most publicly funded hospitals, but not private providers. Requests for your own personal records carry no application fee.

For your own records the SAR route is usually the simpler ask: one law, every provider, and the DPC behind it if it is ignored. FOI earns its keep where you want records about your care that are not personal data — policy documents, incident reviews — or where an FOI decision’s formal appeal path to the Information Commissioner is what you are after.

2. Who actually holds your records

There is no single national file. Records live with the provider that created them:

  • Your GP holds your primary care record — send the request to the practice itself, whoever funds your care.
  • Each hospital holds the records of care it provided. Public hospitals have medical records departments; address your request there, naming the hospital, your dates of treatment and any patient number.
  • HSE community services — public health nursing, mental health services, disability services — hold their own files. The HSE site explains where to direct requests — search it for access to your personal information or data protection.
  • Private consultants and clinics hold theirs — GDPR route only.

One request per holder. Three providers means three requests, each with its own one-month clock.

3. Making the request

Use the standard Irish SAR: the step-by-step guide has template wording, or the free letter generator writes it for you. For medical records, add what locates the file: dates of treatment, wards or departments, consultant names, your patient or medical record number if you have it.

An organisation may ask you to confirm your identity, but only where it has reasonable doubts about who you are, and it should ask for no more than it needs. Where it genuinely needs that information, it can wait for it before acting on your request — so provide it promptly.

Expect an identity check here more than anywhere else — health data is special category data and providers are right to be careful. Proportionate ID plus your date of birth and address history is normal.

4. How long it takes

An organisation must respond without undue delay and within one month of receiving your request. It may extend by up to two further months where requests are complex or numerous, but it must tell you within the first month that it is extending, and why.

There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies of your data.

Large historical files are the classic “complex request” — an extension notice inside the first month is lawful. Silence is not. The DPC route is the answer to silence.

5. What comes back, and what can be withheld

Clinical notes, referral and discharge letters, test results, imaging reports, medication records, and correspondence about you. Other people’s data — a family member mentioned in your notes, a third party’s statement — can be redacted, because your right to a copy must not adversely affect the rights of others.

Health records have one further wrinkle: information can be withheld where disclosure would be likely to cause serious harm to your physical or mental health. It is narrow, it must be considered case by case, and a blanket refusal citing it is challengeable through the DPC. Records of someone who has died are outside the GDPR — for those, the FOI route and its rules for next of kin are the place to look.