
Data Breach Response Procedure
How we identify, contain and assess suspected or confirmed personal data breaches, and how to report one to us urgently.
- Version
- 3.0
- Effective
- 1 February 2026
- Last reviewed
- 1 September 2026
HOME PHYSIO AND REHAB LTD trading as Home Physio & Rehab · Company No. 17000378
1. Purpose
This procedure describes how HOME PHYSIO AND REHAB LTD, trading as Home Physio & Rehab, responds to suspected or confirmed personal data breaches involving personal data for which it is responsible. It is written to be practical and operational rather than to replace legal advice.
The procedure is intended to help us:
- identify suspected breaches promptly;
- contain incidents and mitigate potential harm;
- protect the interests of affected individuals;
- assess whether regulatory reporting is required;
- document the decisions and actions taken; and
- learn from incidents and reduce the likelihood of recurrence.
No organisation can guarantee that a personal data breach will never occur. This procedure sets out how we aim to respond appropriately and proportionately when a suspected breach is identified.
2. What is a personal data breach?
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed. A breach is not only about losing personal data — it also covers situations where data is altered, corrupted or made unavailable.
Examples relevant to a healthcare and home-care organisation can include:
- an email or letter sent to the wrong recipient;
- a lost or stolen device, notebook or paper record;
- unauthorised access to patient or appointment information;
- a compromised email, system or user account;
- accidental publication or disclosure of information;
- deletion or loss of data where its availability is affected; and
- a cyberattack affecting the confidentiality, integrity or availability of personal data.
Not every security incident is a personal data breach, and not every personal data breach is reportable to the Information Commissioner's Office (ICO). Each incident is assessed on its own facts (see sections 6 and 7).
3. Report a suspected data breach to us
Report immediately
Anyone who becomes aware of a suspected personal data breach involving Home Physio & Rehab information should report it to us immediately, without waiting to investigate it fully themselves.
This opens your email application to info@homephysioandrehab.uk with the subject line URGENT - DATA BREACH already filled in.
Where it can be provided safely and quickly, the initial report should include:
- your name and contact details;
- the date and time the breach was discovered;
- what happened, as far as you know;
- the systems or data that may be affected;
- the categories of personal data that may be involved;
- the approximate number of people who may be affected, if known;
- whether data may have been sent to, or accessed by, an unintended party;
- any immediate containment actions already taken; and
- whether the issue appears to be ongoing.
Do not email unnecessary sensitive material
Please describe the incident, but do not email copies of patient records, medical files, passwords, authentication credentials, API keys or other sensitive documents unless these are specifically requested through an appropriate secure channel. Sending sensitive data unnecessarily can increase the risk.
A suspected personal data breach should use the urgent contact above rather than the general incident process. See section 19 for how this differs from reporting a general incident or concern.
4. Immediate internal response
When a suspected breach is reported, we follow a structured response at a policy level:
- record the report and the time we became aware of it;
- escalate internally to the responsible person or team;
- contain the incident where it is possible to do so;
- preserve relevant evidence and logs;
- establish which personal data and systems are affected;
- establish whether the breach is ongoing;
- assess the possible consequences for affected individuals;
- take mitigation and remediation steps;
- assess whether any notification obligations apply; and
- maintain a documented record of the breach.
Detailed technical response steps and internal escalation contacts are held in our internal governance documentation and are not published here.
5. Containment
Containment measures are proportionate to the incident and may include:
- restricting or removing compromised access;
- securing affected accounts or systems;
- recovering or recalling information where possible;
- contacting an unintended recipient to request deletion or return;
- preserving evidence for investigation;
- involving relevant suppliers or processors; and
- taking steps to protect affected individuals from further harm.
6. Assessing the risk
We assess the likely risk to individuals' rights and freedoms on a case-by-case basis. Relevant factors can include:
- the nature and sensitivity of the data involved;
- whether health or other special category data is affected;
- the volume of data and the number of people affected;
- how easily individuals could be identified;
- the likely consequences for those individuals;
- the likelihood that the data could be misused;
- the circumstances of any individuals who may be more vulnerable to harm;
- whether the data was encrypted or otherwise protected;
- whether any unauthorised recipient can be trusted to delete or return the data; and
- the degree of containment already achieved.
This is a considered assessment. We do not rely on an automatic score to decide whether a breach is legally reportable.
7. Notifying the ICO
A personal data breach is reported to the ICO where the applicable UK GDPR reporting threshold is met — that is, where the breach is likely to result in a risk to people's rights and freedoms. Where a breach is unlikely to result in such a risk, it may not be reportable, but the reasons for that decision are documented.
Where reportable, notification is made without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
If all the information is not available immediately, we may provide it to the ICO in phases where this is permitted, rather than delaying an initial report unnecessarily. If the 72-hour period is exceeded, the reasons for the delay are documented and provided where required.
Current authoritative requirements are set out by the ICO. See Report a personal data breach and Personal data breaches: a guide for the current position.
8. Information provided to the ICO
Where a breach is reported, the information that may need to be provided includes, at a high level:
- a description of the nature of the breach;
- the categories and approximate number of individuals affected;
- the categories and approximate number of records affected;
- an appropriate contact point within the organisation;
- a description of the likely consequences of the breach; and
- the measures taken or proposed to address the breach and mitigate any adverse effects.
Not every field is available in every incident. Where information is not yet known, we provide what we can and update it as our investigation progresses.
9. Telling affected individuals
Informing affected individuals is a higher threshold than notifying the ICO. Where a breach is likely to result in a high risk to the rights and freedoms of individuals, Home Physio & Rehab will assess its obligation to communicate the breach to those individuals without undue delay.
Where notification to individuals is required, communications aim to be:
- clear, understandable and proportionate;
- a description of the nature of the breach;
- an appropriate contact point for further information;
- a description of the likely consequences; and
- a description of the measures taken or proposed, with practical steps individuals can take to protect themselves where relevant.
Not every breach requires individual notification; this depends on the outcome of the risk assessment described above.
10. Processors and suppliers
Where a processor or service provider handles personal data on behalf of Home Physio & Rehab, that provider is expected to notify us of a personal data breach without undue delay, in accordance with applicable contractual and legal requirements. We coordinate investigation, containment and regulatory assessment with relevant processors or controllers as appropriate to the incident.
11. Our breach record
We maintain an internal record of personal data breaches, including those that are not reported to the ICO. As appropriate to each incident, the record documents:
- the facts surrounding the breach;
- the date and time it was discovered or awareness was established;
- the information and people affected;
- the likely or actual effects;
- the risk assessment carried out;
- the containment and remedial action taken;
- the notification decision, and any ICO or individual notification made;
- the reasons supporting the decisions taken; and
- the lessons learned and actions to help prevent recurrence.
The internal breach register itself is not published.
12. Health and special category data
Because we operate in healthcare, incidents involving health information, rehabilitation information, patient identity or contact information, clinical information or other special category data may require particularly careful assessment, given the potential impact on individuals. This does not mean that every health-data incident is automatically reportable; each is assessed on its facts.
13. Safeguarding and physical safety
Where a data breach may create an immediate safeguarding or physical-safety risk, we may need to take additional proportionate action and involve appropriate authorities or emergency services where necessary. See our Safeguarding Statement for more on how we handle safeguarding concerns.
Immediate danger
If someone is in immediate danger, call 999.
14. Cyber incidents
For cyber incidents, we may also need to consider relevant cybersecurity reporting or escalation channels, depending on the nature and severity of the incident, the systems affected, our contractual obligations and applicable law. Not every cyber incident is required to be reported to another authority; this is assessed case by case alongside any ICO reporting obligation.
15. Post-incident review
After an incident, we consider, as appropriate:
- a root-cause review;
- how effective the response was;
- improvements to controls and processes;
- a review of access and security arrangements;
- staff training where relevant;
- a review of relevant vendors or processes;
- updates to policies and procedures; and
- follow-up monitoring.
16. Staff and contractor responsibilities
Staff, contractors and relevant service providers should report a suspected breach immediately. They should not:
- conceal the incident;
- delay reporting while attempting to investigate everything themselves;
- destroy evidence; or
- contact affected individuals or regulators on behalf of the company unless authorised to do so.
17. Prompt, good-faith reporting
Prompt reporting is encouraged so that potential risks can be assessed and contained as quickly as possible. Raising a genuine concern in good faith is the right thing to do. This procedure does not create any employment-law commitments beyond those in the company's existing policies.
18. Contact
HOME PHYSIO AND REHAB LTD trading as Home Physio & Rehab.
Data-breach contact: info@homephysioandrehab.uk
Location: Harrow, London, UK
Opens your email application with the subject line URGENT - DATA BREACH already filled in.
20. Official guidance
For authoritative and current requirements, please refer to:
- ICO — Personal data breaches: a guide
- ICO — Report a personal data breach
- GOV.UK — Data protection
- Data Protection Act 2018 (legislation.gov.uk)
Note on current law
UK data-protection law and ICO guidance continue to develop, including following recent legislative changes. The ICO has indicated that some of its breach guidance is under review. Where there is any difference, the current ICO guidance linked above sets out the authoritative reporting requirements.