Notice

Local hospital sends patient COVID-19 results to unintended recipient (2023-09-13)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2023-09-13

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing a resolved data protection complaint. It recounts how a local hospital's COVID-19 testing portal mistakenly sent one patient's test results to 27 other unintended recipients due to a system error, and how the hospital responded.

  • Cause: A change to the hospital's information system disrupted transmission of patient registration data to the testing portal, causing a batch of results to be misdirected to unintended recipients.
  • Hospital's remedial actions: Notified the Ombudsman and the affected patient, apologized, reprogrammed the portal and information systems, stopped batch sending of results in favour of individually verified transmissions, introduced password protected encrypted PDF attachments, added new inter system communication checks, and created an internal incident report process for quality assurance.
  • Outcome: The Ombudsman reviewed the hospital's response, supported the actions taken as adequate, and closed the matter as an informal resolution.

The notice is purely informational, illustrating how a data breach involving health information was handled and resolved; it does not itself create new binding rules or ongoing compliance duties beyond what data protection law already requires of data controllers.

Applies to

hospitals, data controllers

Topics

Version history

2026-07-30

source file (current)