Notice
Pharmacy gives prescription medicine to the wrong patient (2021-04-14)
Issued 2021-04-14View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informally resolved data protection complaint. It illustrates how the Ombudsman handled a breach where a pharmacy disclosed one patient's prescription medicine, including personal data, to another patient.
- What happened: A pharmacy gave patient X medication belonging to patient Y, which included Y's name and other personal data; X reported it to the pharmacy and to Y.
- Ombudsman's finding: The pharmacy appeared unaware of its obligations under the Data Protection Act (DPA); the breach carried a risk of harassment or embarrassment but was quickly contained, and notification eventually occurred after delays.
- Recommendation: The Ombudsman recommended the data controller develop a privacy notice and an internal data protection policy covering breach reporting, subject access requests and compliance with data protection principles, and provide staff training.
This is a case summary illustrating enforcement practice rather than a new rule or binding instrument; it does not itself create ongoing obligations beyond the specific recommendations made to the pharmacy involved.
Applies to
data controllers, pharmacies
Topics
Version history
2026-07-30