Notice
Local hospital sends patient COVID-19 results to unintended recipient (2023-09-13)
Issued 2023-09-13View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing a resolved data protection complaint. It recounts how a local hospital's COVID-19 testing portal mistakenly sent one patient's test results to 27 other unintended recipients due to a system error, and how the hospital responded.
- Cause: A change to the hospital's information system disrupted transmission of patient registration data to the testing portal, causing a batch of results to be misdirected to unintended recipients.
- Hospital's remedial actions: Notified the Ombudsman and the affected patient, apologized, reprogrammed the portal and information systems, stopped batch sending of results in favour of individually verified transmissions, introduced password protected encrypted PDF attachments, added new inter system communication checks, and created an internal incident report process for quality assurance.
- Outcome: The Ombudsman reviewed the hospital's response, supported the actions taken as adequate, and closed the matter as an informal resolution.
The notice is purely informational, illustrating how a data breach involving health information was handled and resolved; it does not itself create new binding rules or ongoing compliance duties beyond what data protection law already requires of data controllers.
Applies to
hospitals, data controllers
Topics
Version history
2026-07-30