Notice

ODPA sanctions First Contact Health for phishing attack breach (2026-02-12)

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Issued 2026-02-12

Current version last checked: 2026-07-30

Summary

This is a public enforcement notice from the Guernsey Office of the Data Protection Authority (ODPA) describing the outcome of an Inquiry into a phishing-related data breach at First Contact Health, a controller processing health data. It explains the security failings found, the resulting enforcement order, and lessons for other organisations handling special category data.

  • What happened: In May 2024 an employee email account was compromised via phishing, exposing personal data including health information; First Contact Health notified the Authority as required under the Data Protection (Bailiwick of Guernsey) Law, 2017.
  • Failings identified: No Multi Factor Authentication (MFA) on the account, no conditional access policies (e.g. geo-blocking), no monitoring tools so the breach went undetected for at least five months, and no regular security audits or penetration testing.
  • Outcome: The Authority found a breach of the Law and issued an enforcement order requiring First Contact Health to take specified steps to improve its security safeguards; further enforcement action may follow if the order is not complied with.
  • Guidance for others: Organisations handling health or other special category data are expected to implement MFA, conditional access policies, suspicious-activity monitoring, and regular security audits or penetration tests.

This notice is primarily informational for the wider sector, though it confirms a binding enforcement order against First Contact Health specifically; the full determination is referenced but not reproduced here.

Key obligations

  • First Contact Health must implement the security safeguard improvements specified in the Authority's enforcement order.
  • Controllers must notify the Authority of personal data breaches in line with obligations under the Data Protection (Bailiwick of Guernsey) Law, 2017.
  • Organisations processing special category data (e.g. health information) are expected to implement enhanced security measures such as MFA, conditional access policies, monitoring for suspicious authentication activity, and regular security audits or penetration testing.

Applies to

controllers, organisations processing health data / special category data

Topics

Version history

2026-07-30

source file (current)