Notice
Pharmacy suffers ransomware attack (2021-12-02)
Issued 2021-12-02View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data breach investigation involving a pharmacy. It illustrates how the Ombudsman applies the Data Protection Act (DPA) to breach notifications and enforcement decisions, rather than creating new rules.
- Incident: A pharmacy discovered in October 2019 that emails sent to it, many containing sensitive personal data of about 242 individuals, had been diverted to an external address for three months.
- Response: The data controller and its IT service provider took immediate technical and organizational measures to mitigate the breach and prevent recurrence.
- Notification: The Ombudsman and affected data subjects were notified of the breach, as required under the DPA.
- Outcome: After an extensive investigation into the controller's security measures and remediation, the Ombudsman decided not to impose a financial penalty, citing the breach's timing (largely before the DPA came into force) and the thoroughness and timeliness of the response.
This notice is informational and does not itself impose new obligations; it demonstrates the Ombudsman's application of existing DPA breach-notification and enforcement provisions to a specific case.
Key obligations
- Data controllers must notify the Ombudsman and affected data subjects of personal data breaches as required under the DPA.
Applies to
data controllers, pharmacies, IT service providers
Topics
Version history
2026-07-30