Personal-data breach response
DRAFT — requires legal review
This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.
The detailed operational procedure is maintained internally (breach-notification runbook). This page summarises the commitments.
Timeline
| Clock (from awareness) | Action | Owner |
|---|---|---|
| 0 h | Incident declared, severity assigned, breach lead appointed; evidence preserved | On-call engineer → Incident commander |
| ≤ 6 h | Report to CERT-In if the incident is a reportable cyber-security incident | Security lead |
| ≤ 24 h | Notify affected healthcare providers (the Data Fiduciaries) with known facts | Breach lead / customer success |
| Without delay | Intimation to the Data Protection Board (by the fiduciary; we support providers as processor, and file for our own customer data) | Fiduciary |
| ≤ 72 h | Detailed report to the Board: nature, extent, timing, likely impact, measures taken, notifications made | Fiduciary with our assistance |
| Without delay | Notify affected data principals in plain language: what happened, likely consequences, mitigation, what they can do, contact | Fiduciary |
| ≤ 5 business days after closure | Post-incident review with corrective actions | Incident commander |
What counts as a breach
Any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability — including cross-tenant data exposure, lost devices with cached data, mis-sent WhatsApp messages and leaked credentials.