Practice Manager Live
Back to resources
Legal & Contractstemplate

Data Breach Response Procedure

A clear procedure for identifying, containing, and reporting personal data breaches in a GP practice setting, including ICO notification criteria.

## Data Breach Response Procedure

### Definition

A personal data breach is any security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

### Common Breach Examples in GP Practices

- Misdirected fax or email containing patient information

- Lost or unencrypted USB drive

- Ransomware or cyberattack on clinical systems

- Verbal disclosure to an unauthorised third party

- Paper records found in non-secure waste

### Immediate Response (within 24 hours)

1. Contain the breach — retrieve misdirected data if possible, isolate affected systems

2. Assess scope — how many records affected, what data types, what is the likely impact?

3. Report internally — notify the DPO and Practice Manager immediately

### ICO Notification Assessment

You must notify the ICO within **72 hours** if the breach is likely to result in a risk to individuals' rights and freedoms. Factors to consider:

- Sensitivity of the data involved

- Volume of records affected

- Whether the data has been accessed by an unauthorised person

- Whether harm to individuals is likely (financial loss, discrimination, physical harm)

### ICO Reporting

Report at: ico.org.uk/report-a-breach. Keep a record of the breach and your assessment regardless of whether you notify.

### Individual Notification

If the breach is likely to result in high risk to individuals, you must notify affected individuals without undue delay.

### Documentation

All breaches, including those not reported to the ICO, must be logged in your Data Breach Register.

Sign in to save this resource.

Added 9 July 2026 · 0 views