Under Article 4(12) GDPR, a personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Loss of access counts exactly as much as a leak.
Who reports to whom
The division of duties follows directly from the roles described in GDPR at Heltio:
- The practice is the controller. It is the practice that notifies the supervisory authority within 72 hours of becoming aware (Art. 33(1)) and the practice that informs patients where the risk is high (Art. 34). With health data, high risk is the starting assumption, not the exception.
- Heltio is the processor. It is obliged to notify the practice without undue delay (Art. 33(2)) so that the practice's 72-hour clock can start.
The clock runs from becoming aware of the breach, whatever the hour, the day of the week or the public holiday. Failing to report on time is an independent ground for a fine.
How to do it
Report it to Heltio
Write to iod@heltio.pl. Say what happened, when it was noticed, what it concerns (which categories of data, how many patients, which practices) and what has already been done. Attach record identifiers if you have them — they make it possible to find the events in the register.
Preserve the trail before it disappears
Before you start fixing anything, export from the Audit Log the range covering the event — with the Export button, in CSV or JSON. The export carries the actor, the action, the object, the IP address and the browser identifier. This is the material on which the scope of the breach is established.
Establish the scope
Answer five questions, because those are exactly what the notification form asks: whose data, which categories, how many people are affected, when the breach happened and when it was detected, who had access to the data. An approximation is acceptable; a delay of "until we have counted precisely" is not.
Notify the supervisory authority
The notification is filed by the practice as controller, through the form on the supervisory authority's website. The required elements: a description of the nature of the breach with the categories and approximate number of people and records, contact details for the data protection officer or another contact point, a description of the likely consequences, and a description of the measures taken or proposed.
Inform patients where the risk is high
The communication has to be written in clear, plain language and contain the same elements as the notification to the authority, apart from the description of the nature of the breach. Heltio has no ready template for such a message today — the text is prepared by the practice, and Heltio helps establish the list of recipients.
What Heltio detects on its own
Three mechanisms run without human involvement, and all three send their signal to Heltio, not to the practice:
- Application errors — collected by an external error-monitoring service, anonymised before sending.
- Backup health — a watchdog running inside the main application process, deliberately outside the backup service itself. It raises the alarm when a backup was never made, when the last run ended in error, or when the last good backup is more than thirty hours old.
- Patient request deadlines — a daily review of requests due within five days and of those already overdue.
What is still missing
- A public service status page. The Status link in the footer points at an address that does not exist yet — deliberately, so that the gap is visible before the production launch.
- Published post-incident retrospectives.
- A separate, 24/7 reporting channel.
Related
- How the audit log works — the evidence and how to export it.
- Encryption and data residency — what lowers the risk when a database copy is lost.
- GDPR at Heltio — the division of roles between the practice and Heltio.