Five Hard Drives. Five Euros Each. Eight Years of Patient Data.

FH Blog Image 09.24.2026 Five Hard Drives. Five Euros Each. Eight Years of Patient Data (1)

A flea market next to an airbase in Belgium. A bargain hunter with a passion for computers. And fifteen gigabytes of medical records that should have been erased years ago.

In February 2025, Robert Polet, a 62-year-old computer enthusiast from Breda in the Netherlands, stopped at a flea market next to Weelde airbase in Belgium on his way home from a trip. He spotted five 500GB hard drives on sale for five euros each and bought them, he wanted extra storage for his photography and drone footage, he thought.

When he connected the drives at home, he found something else entirely. The drives contained 15GB of medical data covering the period between 2011 and 2019. Patient names, home addresses, dates of birth, Dutch citizen service numbers (BSN), medication details, prescriptions, and other GP and pharmacy records. Hundreds of patients from the Utrecht, Houten, and Delft regions of the Netherlands.

“That was quite a shock,” he told regional broadcaster Omroep Brabant. “I thought: how could something like this happen?”

 

Where the drives came from

Polet returned to the flea market and bought the remaining ten drives the seller had. The seller could not tell him where he had acquired them.

Further investigation pointed to Nortade ICT Solutions, a Dutch company that had developed software for the healthcare sector and had since gone out of business. The drives are believed to have entered the secondary market through a bankruptcy sale.

Wout Kasbergen, a data expert who examined the discovery, explained the likely chain of events. “As a company, you can choose to have the drives properly destroyed and then you pay money for that, or you can sell them to a refurbisher and then you get money from it,” he told Omroep Brabant. “In terms of costs, you can imagine what is often chosen.”

Polet reported his discovery to the Dutch Data Protection Authority.

 

What cryptographic erase would have changed

If the drives from Nortade ICT Solutions had been cryptographically erased before they left the company, the data on them would have been permanently unrecoverable before they ever reached a flea market, a refurbisher, or a bankruptcy sale.

Cryptographic erase works by deleting the encryption key. Once the key is gone, the data on the drive is unreadable regardless of what tools are used or who has physical access to the device. It does not matter whether the drive is sold, lost, stolen, or auctioned. Without the key, the data cannot be read.

Opal Lock by Fidelity Height performs cryptographic erase on compatible TCG Opal and Pyrite self-encrypting drives using the admin password or the PSID printed on the drive label. A Certificate of Sanitization is generated automatically after a successful erase, providing documented, verifiable proof that the drive was securely wiped before it left the organization. That certificate is exactly the kind of record that Dutch law requires and that an auditor, a regulator, or a data protection authority can verify.

Five euros bought fifteen gigabytes of patient data. A cryptographic erase and a Certificate of Sanitization would have made those drives worthless to anyone who connected them.

 

The decommissioning gap

The root cause here is not unique to this incident. Not a sophisticated attacker. Not a vulnerability in software. Just drives that left an organization without the data on them being made unrecoverable first.

Most organizations focus their data security on preventing unauthorized access while devices are in use. The decommissioning stage, when drives are retired, resold, returned to a vendor, or handed to a disposal contractor, receives far less attention. It is also where the gap is most consistently found.

Opal Lock closes that gap. The cryptographic erase operation can be performed using the admin password or the PSID printed on the drive label, which means it can be completed even if the admin password is unavailable. After a successful erase, the Certificate of Sanitization provides the documented proof that compliance requires.

The data on those five drives could have been permanently unrecoverable before they left the building. The process exists. The tools exist. What was missing was the step that should come before any storage device leaves an organization.

 

Compare Opal Lock editions at fidelityheight.com/shops/

Sources: Omroep Brabant | Cybernews | The Register | IT Pro | NL Times | Malwarebytes — February 2025

Ready to buy

Secure your drives. Buy your license now.

Activate hardware encryption on compatible Opal drives in minutes. Select your edition and complete purchase below.