Hacking victims who had their personal information stolen during the HSE ransomware attack last year have not been told they were targeted.
It’s a legal requirement for the health authority’s IT management to inform them under GDPR rules. The HSE said in a statement that it was taking time to get through all of the affected data.
The cost of repairing the damage caused by the attack has so far topped €600million and it will cost more to finish the repairs and put new safeguards in place. A spokesman for the HSE said: “The HSE has been reviewing the data that was illegally accessed and copied to allow us to notify individuals as required and is in the process of verifying the identity of the relevant individuals for notification purposes.