GetMySAR

GetMySAR Ireland

Getting your medical records in Ireland

HSE, hospital, GP or private clinic — your records are yours to see. Which of the two legal routes to use, who to actually send the request to, and what a complete response looks like.

GetMySAR is an independent service. We are not the HSE, not a hospital and not a law firm. Nothing here is legal advice. Every route on this page is one you can use yourself, and asking for your own records is free.

1. Two legal routes to the same records

In Ireland you can ask for your health records under either of two laws, and which one applies depends on who holds the records:

  • A subject access request under the GDPR — works against any holder of your records: the HSE, voluntary hospitals, private hospitals and clinics, GPs, consultants, physiotherapists, counsellors. Free, one-month deadline.
  • The Freedom of Information Act 2014 — works only against FOI bodies, which include the HSE and most publicly funded hospitals, but not private providers.

The deadlines are set by different statutes and are not the same length. Section 13 of the FOI Act 2014 gives an FOI body “as soon as may be, but not later than 4 weeks” to decide, while a subject access request runs on the GDPR’s calendar month. Four weeks is the shorter of the two in most months, which is the one genuine argument for FOI on timing — and it buys you a decision, not necessarily the records.

The bigger difference is money. A subject access request has no fee at all except in the narrow manifestly-unfounded case. Under FOI, section 13 requires the decision notice itself to specify “the amount of any fee under section 27 payable by the requester”, so a charge is part of the design of that route in a way it is not part of the other.

For your own records the subject access request is usually the simpler ask: one law, every provider, and the DPC behind it if it is ignored. FOI earns its keep where you want records about your care that are not your personal data — a policy document, an incident review, a service’s correspondence with the Department — or where you specifically want an FOI decision’s formal appeal path to the Information Commissioner.

2. Who actually holds your records

There is no single national file and no central HSE address to write to. This is not an inference — it is what the HSE’s own subject access request form instructs. It tells you to “send the completed form or letter to your local hospital or service provider where you think your records are held”.

So records live with the provider that created them:

  • Your GP holds your primary care record. GPs in Ireland are independent contractors rather than HSE employees, so the practice is its own controller — send the request to the practice itself, whoever funds your care.
  • Each hospital holds the records of the care it provided. Public hospitals have medical records departments; address your request there, naming the hospital, your dates of treatment and any chart number.
  • HSE community services — public health nursing, mental health services, disability services — hold their own files.
  • Private consultants and clinics hold theirs. GDPR route only: they are not FOI bodies.

If you do not know which office to write to, the HSE publishes a Contact a Data protection office page listing a national office, local offices and its data protection forms. That is the page to start from.

A dead end to know about before you hit it. The HSE’s current subject access request form points readers to https://www.hse.ie/eng/gdpr/ for further information. As at 6 September 2026 that address returns the HSE’s own “Page not found”. Use the Contact a Data protection office page above instead. The form itself is still the current one and still works — it is only the reference on it that has gone stale.

One request per holder. Three providers means three requests, each with its own one-month clock.

3. The HSE's form — useful, and optional

The HSE publishes a one-page Subject Access Request form (and an Irish-language version). It is worth using, because it asks for exactly what the office needs to find your file — but you are not obliged to. The form says so itself: “this form is to aid with the Subject Access Request process but we will accept your request made in writing”.

That matters if a service tells you a request is invalid because it is not on the form. It is not, and the HSE’s own document is the thing to quote back.

Whichever you use, the form shows what to include:

  • Full name, date of birth, and any previous names.
  • Your hospital chart number, if you have one. This is the single most useful field on the form.
  • Current address, and previous addresses if you have moved.
  • Phone number and email address.
  • A description of the information you want, “including dates and locations of services involved”.
  • A copy of photo ID. The form names a “Passport, Driving Licence, Public Service Card”.

An organisation may ask you to confirm your identity, but only where it has reasonable doubts about who you are, and it should ask for no more than it needs. Where it genuinely needs that information, it can wait for it before acting on your request — so provide it promptly.

Expect the identity check to be taken seriously here more than anywhere else — health data is special category data and providers are right to be careful. Proportionate ID plus your date of birth and address history is normal.

If you would rather write a letter than fill in a form, the step-by-step guide has template wording and the free letter generator writes it for you.

4. What you are entitled to beyond the copy

Almost every guide to this subject stops at “a copy of your data”. Article 15 gives you more than that, and the DPC sets out the full list: confirmation of whether your data is being processed, a copy of it, and then eight further pieces of information —

  • the purposes of the processing;
  • the categories of personal data;
  • who it has been or will be disclosed to, and in particular any recipients outside the country;
  • the retention period, or the criteria used to decide it — the question “how long will you keep my records” is part of the request, not a separate one;
  • that you have rights to rectification, erasure, restriction and objection, and how to use them;
  • that you may raise a concern with the DPC;
  • where the data did not come from you, any available information on its source;
  • whether there is automated decision-making or profiling, and meaningful information about how those decisions are made.

On a medical file the source item is often the interesting one: it is how you find out which other practice, insurer or service sent something into your record.

You can also make the request verbally. The DPC is explicit that “the GDPR does not set out any particular method for making a valid access request, therefore a request may be made by an individual in writing or verbally”, while encouraging writing “to avoid disputes over the details, extent, or timing”. For a hospital records department, put it in writing.

5. How long it takes, and what it costs

An organisation must respond without undue delay and within one month of receiving your request. It may extend by up to two further months where requests are complex or numerous, but it must tell you within the first month that it is extending, and why.

There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies of your data.

The DPC adds that access requests “must be responded to free of charge and in an accessible form”, and that controllers “should seek to facilitate access requests being both made and responded to easily, including electronically where appropriate”.

On format, the general rule is that a controller should respond the same way you asked. Where you make the request electronically, the DPC says the information should come back “in a commonly used electronic format” unless you ask otherwise — worth stating in the request if you would rather not be sent a box of photocopies.

Large historical files are the classic “complex request”, and an extension notice inside the first month is lawful. Silence is not. The DPC route is the answer to silence.

6. What comes back, and what can be withheld

Clinical notes, referral and discharge letters, test results, imaging reports, medication records, and correspondence about you.

Other people in your file. A family member mentioned in your notes, a third party’s statement — these can be redacted, because Article 15(4) says your right to a copy must not “adversely affect the rights or freedoms of others”. The DPC frames this as a balancing exercise rather than a switch, and says the considerations “should not result simply in a refusal to provide all relevant information” — the controller should comply as far as it can while protecting the third party. A whole file withheld because one page mentions somebody else is not that.

The serious-harm restriction, and its limits. Health records carry a further restriction that other records do not. Section 60(5) of the Data Protection Act 2018 allows rights to be restricted by regulations where they “would be likely to cause serious harm to the physical or mental health of the data subject” — and, in the same breath, “to the extent to which, and for as long as, such application would be likely to cause such serious harm”.

Read that second half. The restriction is bounded twice over: by how much of the record it reaches, and by how long it lasts. It is not a permanent seal on a file, and something withheld on this ground during an acute episode is not necessarily withheld a year later. A blanket refusal citing serious harm, with no indication of scope or duration, is challengeable through the DPC.

Opinions given in confidence. Section 60(3)(b) of the same Act restricts access where the data “consist of an expression of opinion about the data subject by another person given in confidence”. On a health file that can reach a referral written in confidence by one clinician to another. It has no equivalent in the plain GDPR text and it surprises people.

A refusal has to be a reasoned one. The DPC is clear that “an organisation must always respond to your requests within one month, even if they believe they have grounds to refuse it”, and that a refusal must set out “clearly which limitation or restriction they are relying on … their reasons for not taking action, and informing you of the possibility of lodging a complaint with the DPC or seeking a judicial remedy”. That is a three-item checklist you can hold a refusal letter against. Most fail it.

7. Records of someone else, and of someone who has died

A subject access request is for your own data. Two adjacent cases come up constantly on health records and neither is a subject access request:

  • A child’s records. The right belongs to the child; a parent normally exercises it on their behalf, and the older and more capable the child, the more the provider has to weigh the child’s own wishes. Ask the provider what it requires before sending anything.
  • Someone who has died. The GDPR applies to living people, so there is no subject access request here. In Ireland the route runs through the Freedom of Information Act rather than through data protection law, and it has its own rules about who may apply.

This page does not set out the deceased-records rules, because the build that wrote it did not read the relevant FOI provisions and regulations closely enough to state them, and half-remembered rules about a bereavement are worse than none. Ask the provider’s FOI officer, or the Office of the Information Commissioner, which oversees FOI in Ireland and is a different body from the Data Protection Commission. Confusing those two is the single most common Irish mistake on this subject.

8. If you are ignored or refused

Raise it with the organisation first — its data protection officer, if it has one, is the right address. If that gets you nowhere, Article 77 of the GDPR gives you the right to lodge a complaint with the Data Protection Commission, which supervises data protection law in Ireland.

You are not an unusual case if this happens. The DPC states that “the majority of the complaints and queries the Data Protection Commission receives concern individuals seeking to exercise their ‘right of access’”. The most-complained-about right is the one on this page.

Before complaining, check the response against the checklist in section 6: did it arrive within the month, does it name the restriction relied on, does it give reasons, and does it tell you about the DPC and about a judicial remedy? A response missing all four is a much easier complaint to make than “I am not happy with what I got”.

How to complain to the DPC covers what happens next, and check what you got back helps if a response has arrived and looks thin.

Where this comes from

Everything quoted above is from the HSE’s own subject access request form, the Data Protection Commission’s published guidance, or the statutes, each linked at the point it is used.

The HSE reorganises its web addresses often — two paths cited in earlier versions of this page have moved, and one printed on the HSE’s own form is dead. If a link here fails, start from the Contact a Data protection office page in section 2.

Sources checked 6 September 2026.