Notice
HSA discloses PCR results to wrong person (2022-03-28)
Issued 2022-03-28View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against the Health Services Authority (HSA). It illustrates how the Ombudsman assessed a personal data breach and the corrective action expected of a data controller, but it is not a rule of general application.
- What happened: A Maternity Ward nurse handed a PCR test result to the wrong patient's partner, disclosing sensitive medical data to an unauthorised recipient.
- Remedial steps taken: HSA confirmed destruction of the wrongly issued document, apologised to the affected data subject, reviewed internal processes, and added an ID cross-check step before issuing printed PCR results.
- Ombudsman's review: The Ombudsman requested the revised procedure and asked whether patients were told about the MyHSA portal as a lower-risk alternative to printed results; after delays, the revised procedure was found compliant with the seventh data protection principle.
- Outcome: The case was closed with no further action once all requirements were met.
The document is a factual case outcome for public awareness rather than a source of new legal obligations; it signals the Ombudsman's expectations around breach remediation and ID verification for handling sensitive health data.
Applies to
Health Services Authority, data controllers handling sensitive personal data
Topics
Version history
2026-07-30