Notice

Determination - ODPA sanctions First Contact Health for phishing attack breach (2026-02-12)

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Issued 2026-02-12

Current version last checked: 2026-07-30

Summary

This is a published enforcement determination by the Guernsey Office of the Data Protection Authority (ODPA) against First Contact Health, a healthcare data controller, following a phishing related email account compromise reported in May 2024. The Authority found that First Contact Health breached the security obligations in sections 6 and 41 of the Data Protection (Bailiwick of Guernsey) Law, 2017 by failing to implement multi factor authentication and other reasonable security safeguards for an email account handling patient health data.

  • Findings: First Contact Health relied on single factor (password only) authentication for an email account processing special category health data, despite MFA being widely regarded as basic industry best practice for several years.
  • Breach cause: A threat actor compromised an employee email account via phishing, gaining access to patient health data and attempting fraud; the absence of MFA, activity monitoring, and conditional access controls contributed to the breach.
  • Legal basis: The Authority found breaches of section 6 (integrity and confidentiality principle) and section 41 (duty to take reasonable steps to ensure security) of the Data Protection Law, following an Inquiry opened under section 69.
  • Enforcement outcome: Under section 73 of the Law, the Authority issued an enforcement order requiring First Contact Health to take specific action to bring its security measures into compliance with sections 6 and 41.

The determination itself does not specify a compliance deadline for the required remedial actions within the extracted text, but it signals that ODPA expects controllers handling health or other special category data to implement MFA, authentication monitoring, and regular security audits or penetration testing as baseline safeguards.

Key obligations

  • First Contact Health must take specific action, as directed in the enforcement order, to comply with section 6 (integrity and confidentiality) and section 41 (duty to take reasonable steps to ensure security) of the Data Protection (Bailiwick of Guernsey) Law, 2017.
  • Controllers processing personal data, particularly special category data, should implement multi-factor authentication and monitoring/conditional access controls to meet the reasonable security steps standard under section 41.
  • Controllers should conduct regular security audits or penetration testing to identify and remedy authentication and other security weaknesses.

Applies to

data controllers, healthcare data controllers, processors

Topics

Version history

2026-07-30

source file (current)