Thank you for highlighting this topic. It’s important to note from the outset that the impact on human-rights of sharing health information can be viewed in two ways. If not done correctly, it can be viewed as having a negative impact. However, if not done at all, the consequences can be worse.
For many years now the health service has faced criticism for deploying IT systems that are not ‘joined up’. In the context of patient care, this leads to the inability for data to ‘follow the patient’ – an essential requirement when people are being treated in multiple healthcare settings and, in the case of Ireland at least, healthcare providers that may be public, private or voluntary providers. This need, for better joined up digital health systems, is widely accepted internationally where much progress has been made. In the UK, the first NHS Data Guardian, established the Caldicott Principles that states the 'duty to share' data is as important as the 'duty to care'.
Under Slaintecare, one of the key ambitions is to reduce our reliance on the acute hospital sector and provide more care in the community and closer to home. What we have learned over and over since 2017 is that is data cannot be shared between the hospitals and the community, then this becomes a barrier to delivering more of the care for patients in the community.
In Ireland, the Digital for Care strategic framework, published in 2026, describes what needs to be done to digitise the health service between now and 2030. It calls for the establishment of digital health records for all and for solutions to better join up patient data. The Community Connect and National Electronic Health Record programmes are examples of this.
Furthermore, the Programme for Government commits to ‘Continue to work towards the full digitisation of Irish healthcare records and information systems'; to 'launch a National Patient App', providing patients with easier access to their own health information; and to 'establishing a national system for electronic prescribing.’ Indeed, the European Health Data Space EHDS Regulation places legal responsibilities on EU members states to address this issue.
By deploying some core systems such as the ones referenced in this PQ, it will become possible for data to be made available to all healthcare professionals directly involved in the provision of care to patients, regardless of where those patients were treated previously and regardless of where they will receive care next. This is important because we cannot continue to hold patient data in paper charts that are physically only available in the particular hospital where that patient is being treated in at a point in time. There is much evidence that patient safety issues arise due to poor handover between different physical healthcare settings and different healthcare providers. Simple examples underpinned by research, relate to the impact of medications where multiple prescribers are involved in providing care eg inpatient medications regime, discharge prescriptions and handover to GP for onward care and prescribing in the community. There are real world example of the impact of this on patients and these could be regarded as an impact on their human-rights. The value of resolving these issues through efficient and safe data sharing must be balanced with other rights.
As the deputy rightly points out, establishing these systems comes with significant additional responsibilities in relation to governance, oversight, accountability and compliance with data privacy rights as required under GDPR. Indeed, whilst many cite GDPR as a reason for not sharing data, in fact GDPR makes it very clear that individuals have the right to see their own data and to understand how it being managed. It is only by finding solutions that facilitate data sharing in a digital context that we will be able to make more and more of a individuals health data available to them. This is the purpose of initiatives like national Patient Apps that are now universally deployed across EU member states, something Ireland is only now starting to catch up on.
In relation to oversight and accountability, the HSE is authorised under the Health Information Bill to establish digital health records for all and places responsibilities on all healthcare providers to share data for this purpose. Oversight will be provided by the Department of course but ultimately all of this work must be complaint with GDPR (and NIS 2), so the obligations, responsibilities and consequences of not doing this correctly are known to all.