Incident response plan
A clear, repeatable process for detecting, containing and learning from security incidents — including our GDPR Article 33 commitment to notify the supervisory authority within 72 hours of a confirmed personal data breach.
Maintained by Preventa Health. This document is editable content, not an independent certification.
Last reviewed: July 2026 · Reviewed at least annually
1. What counts as a security incident
- Unauthorised access (or attempted access) to customer or clinical data.
- Loss, corruption or accidental disclosure of personal data.
- Compromise of a production credential, key or sub-processor.
- Significant availability disruption affecting customers.
- Malware, ransomware or sustained intrusion attempts against production systems.
2. Detection and reporting
- Internal channel: anyone at Preventa Health reports a suspected incident immediately to the engineering on-call lead.
- External channel: security@preventa-health.com and the responsible-disclosure policy on the security page.
- Automated signals: error monitoring, audit-log review and dependency scanner alerts.
3. Triage
Within one business day, the on-call lead assigns a severity (Critical / High / Medium / Low) based on data sensitivity, blast radius and customer impact. Critical and High incidents trigger immediate containment and notification preparation.
4. Containment, eradication and recovery
- Contain — isolate affected systems, revoke compromised credentials, block malicious access paths.
- Eradicate — remove root cause (patch, configuration change, code fix, sub-processor action).
- Recover — restore service from clean backups when needed, verify integrity, monitor for recurrence.
5. Notification — GDPR Art. 33 / 34
- If a confirmed personal data breach is identified, the supervisory authority (Autoriteit Persoonsgegevens) is notified within 72 hours of becoming aware.
- Affected data subjects are notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
- Affected customers (controllers) are notified in line with the data processing agreement, with enough detail to meet their own notification obligations.
6. Post-incident review
Within 10 business days of closure, the response team produces a written post-mortem covering timeline, root cause, customer impact, what worked, what did not, and concrete corrective actions with owners and due dates. Corrective actions are tracked through to completion.
7. Contacts
- Security reports: security@preventa-health.com
- General contact: contact@preventa-health.com
- Machine-readable policy: /.well-known/security.txt
