Incident response plan

    Incident response plan

    A clear, repeatable process for detecting, containing and learning from security incidents — including our GDPR Article 33 commitment to notify the supervisory authority within 72 hours of a confirmed personal data breach.

    Maintained by Preventa Health. This document is editable content, not an independent certification.

    Last reviewed: July 2026 · Reviewed at least annually

    1. What counts as a security incident

    • Unauthorised access (or attempted access) to customer or clinical data.
    • Loss, corruption or accidental disclosure of personal data.
    • Compromise of a production credential, key or sub-processor.
    • Significant availability disruption affecting customers.
    • Malware, ransomware or sustained intrusion attempts against production systems.

    2. Detection and reporting

    • Internal channel: anyone at Preventa Health reports a suspected incident immediately to the engineering on-call lead.
    • External channel: security@preventa-health.com and the responsible-disclosure policy on the security page.
    • Automated signals: error monitoring, audit-log review and dependency scanner alerts.

    3. Triage

    Within one business day, the on-call lead assigns a severity (Critical / High / Medium / Low) based on data sensitivity, blast radius and customer impact. Critical and High incidents trigger immediate containment and notification preparation.

    4. Containment, eradication and recovery

    • Contain — isolate affected systems, revoke compromised credentials, block malicious access paths.
    • Eradicate — remove root cause (patch, configuration change, code fix, sub-processor action).
    • Recover — restore service from clean backups when needed, verify integrity, monitor for recurrence.

    5. Notification — GDPR Art. 33 / 34

    • If a confirmed personal data breach is identified, the supervisory authority (Autoriteit Persoonsgegevens) is notified within 72 hours of becoming aware.
    • Affected data subjects are notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
    • Affected customers (controllers) are notified in line with the data processing agreement, with enough detail to meet their own notification obligations.

    6. Post-incident review

    Within 10 business days of closure, the response team produces a written post-mortem covering timeline, root cause, customer impact, what worked, what did not, and concrete corrective actions with owners and due dates. Corrective actions are tracked through to completion.

    7. Contacts