Notice

HSA discloses PCR results to wrong person (2022-03-28)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2022-03-28

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against the Health Services Authority (HSA). It illustrates how the Ombudsman assessed a personal data breach and the corrective action expected of a data controller, but it is not a rule of general application.

  • What happened: A Maternity Ward nurse handed a PCR test result to the wrong patient's partner, disclosing sensitive medical data to an unauthorised recipient.
  • Remedial steps taken: HSA confirmed destruction of the wrongly issued document, apologised to the affected data subject, reviewed internal processes, and added an ID cross-check step before issuing printed PCR results.
  • Ombudsman's review: The Ombudsman requested the revised procedure and asked whether patients were told about the MyHSA portal as a lower-risk alternative to printed results; after delays, the revised procedure was found compliant with the seventh data protection principle.
  • Outcome: The case was closed with no further action once all requirements were met.

The document is a factual case outcome for public awareness rather than a source of new legal obligations; it signals the Ombudsman's expectations around breach remediation and ID verification for handling sensitive health data.

Applies to

Health Services Authority, data controllers handling sensitive personal data

Topics

Version history

2026-07-30

source file (current)