Notice

Pharmacy suffers ransomware attack (2021-12-02)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2021-12-02

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data breach investigation involving a pharmacy. It illustrates how the Ombudsman applies the Data Protection Act (DPA) to breach notifications and enforcement decisions, rather than creating new rules.

  • Incident: A pharmacy discovered in October 2019 that emails sent to it, many containing sensitive personal data of about 242 individuals, had been diverted to an external address for three months.
  • Response: The data controller and its IT service provider took immediate technical and organizational measures to mitigate the breach and prevent recurrence.
  • Notification: The Ombudsman and affected data subjects were notified of the breach, as required under the DPA.
  • Outcome: After an extensive investigation into the controller's security measures and remediation, the Ombudsman decided not to impose a financial penalty, citing the breach's timing (largely before the DPA came into force) and the thoroughness and timeliness of the response.

This notice is informational and does not itself impose new obligations; it demonstrates the Ombudsman's application of existing DPA breach-notification and enforcement provisions to a specific case.

Key obligations

  • Data controllers must notify the Ombudsman and affected data subjects of personal data breaches as required under the DPA.

Applies to

data controllers, pharmacies, IT service providers

Topics

Version history

2026-07-30

source file (current)