Notice

A healthcare provider suffers phishing attack from former employee emails (2023-05-29)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2023-05-29

Current version last checked: 2026-07-30

Summary

This is a case summary published by the Cayman Islands Ombudsman describing a data breach incident at a healthcare provider, arising from a phishing attack via former employee email accounts. It illustrates how the Ombudsman assessed the incident and the remedial steps the provider took, rather than creating new legal rules.

  • Incident: Phishing attack targeted employee email accounts at a healthcare provider's Cayman office; initially thought to be spoofing with no data breach, later found to have affected clients and vendors.
  • Response: The provider's IT service provider investigated, clients and the Ombudsman were notified, and all company device passwords were changed immediately.
  • Recommended remedial measures: Quarterly user awareness training on data protection and phishing, an SIEM solution, blocking USB devices, multi factor authentication on remote services, mobile device management, restricting external laptop use to management and emergencies, and a policy review.
  • Ombudsman addition: The Ombudsman recommended adding a regular review of overall security and processes as a best practice.

The case is presented as an illustrative outcome rather than a binding directive, showing the standard of remediation the Ombudsman expects following a personal data breach involving phishing.

Applies to

healthcare providers, data controllers

Topics

Version history

2026-07-30

source file (current)