How to report a personal data breach
The first hour after you spot a leak or a mistake — what to do immediately, whom to tell, and which deadlines start running from the moment you found out.
A personal data breach is any event through which personal data reached the wrong hands, was altered, or became unavailable. From the moment you learn of it, the GDPR deadlines start running — which is why the first hour matters more than the whole of the following week.
How to do it
Stop and write down what you can see
Before you click anything else:
- take a screenshot of whatever alarmed you,
- note the date, the time, the device, and exactly what you did before the event,
- do not click suspicious links, do not reply to suspicious messages, do not give data out over the phone.
Stop it spreading
What to do depends on what happened:
- Suspected access to your account — change the password and sign out on every device you use. Settings → Account → Sign out ends the current session; for a lost device, report it to Heltio support so that access can be revoked at the authentication provider.
- Records sent to the wrong person — write to the recipient asking them not to open the message, to delete it, and to confirm that they have.
- A lost laptop or phone with Heltio signed in — change the password immediately from another device and turn on the PIN lock on the others.
Tell whoever is responsible in the clinic
If you are neither the clinic administrator nor the data protection officer, your job is to pass the matter on, not to report it yourself. A report has legal consequences for the clinic as controller.
Report the matter to Heltio
Write to iod@heltio.pl — the address of Heltio's data protection officer, published in the privacy policy and in the site footer. In the message give:
- the date and time you noticed the event,
- what it consists of,
- how many patients it may concern,
- which data it concerns (contact, medical, billing),
- what you have already done,
- who in the clinic knows about it.
Do not paste PESEL numbers, the text of notes, or any other patient data into the message. A description and identifiers we can find the records by are enough.
Record the event in the clinic's breach register
The breach register is kept by the clinic as controller — the GDPR requires it whether or not the event has to be reported to the supervisory authority. Heltio does not keep it for you and does not supply a template; use the one in your clinic's GDPR documentation.
In the settings you will find what Heltio does provide: Settings → GDPR & Privacy with the Records of Processing Activities to download, the Deletion Requests list, the Data subject requests and the GDPR contact email field the patients can see.
Judge whether the authority and the patients have to be told
The notification to the supervisory authority is filed by the clinic, through the form on the authority's website, within the deadline counted from becoming aware of the breach. Separately, you judge whether the breach poses a high risk to the patients — if it does, they have to be told as well.
With medical data the answer to that question is almost always yes. If you are in doubt, take it to the data protection officer before the deadline runs out, not after.
What is not a breach
Not every unpleasant event is a personal data breach. A patient who turned up at the wrong hour, a wrong amount on a receipt, a mistake in the calendar — those are errors, not breaches. A breach is what touches the confidentiality, integrity or availability of personal data.
When in doubt, ask iod@heltio.pl rather than deciding on your own. Classifying an event is five minutes of conversation; an unreported breach is a problem of a different order.
Who has access
Clinic AdminThe GDPR settings are opened by the clinic owner or administrator — other roles see Access denied. Spotting and reporting a breach, on the other hand, is open to anyone working in the clinic.
Related
- Incident reporting procedure — the full procedure on Heltio's side.
- What data we store and where — the range of data a breach can concern.
- Audit log — where to look for traces of activity.