Data Breach Policy
Data Breach Policy
Helen Ward Therapy
Trading name of ResolvedRM Ltd
Version: 1.0
Effective Date: 30/05/26
Review Date: 30/05/27
1. Purpose
Helen Ward Therapy is committed to protecting the confidentiality, integrity and security of all personal information processed within the practice.
This Data Breach Policy sets out the procedures to be followed where a personal data breach is suspected or confirmed.
The purpose of this policy is to ensure that any breach is:
-
identified promptly;
-
contained effectively;
-
assessed appropriately;
-
recorded accurately;
-
reported where legally required;
-
managed in a way that reduces risk and prevents recurrence.
-
This policy has been developed in accordance with:
-
the UK General Data Protection Regulation (UK GDPR);
-
the Data Protection Act 2018;
-
the BACP Ethical Framework for the Counselling Professions.
-
2. Scope
This policy applies to all personal information processed by Helen Ward Therapy, including:
-
client records;
-
clinical notes;
-
assessment information;
-
contact details;
-
appointment information;
-
emails and electronic communications;
-
financial information;
-
safeguarding information;
-
any other personal or confidential information held by the practice.
-
3. What is a Personal Data Breach?
A personal data breach is a security incident that results in:
-
accidental or unlawful destruction of personal data;
-
loss of personal data;
-
alteration of personal data;
-
unauthorised disclosure of personal data;
-
unauthorised access to personal data.
A breach can occur through:
-
cyber incidents;
-
human error;
-
loss or theft of devices;
-
sending information to the wrong person;
-
unauthorised access;
-
accidental disclosure;
-
insecure disposal of records.
NB Accidental or unlawful destruction of personal data means any event, whether caused by human error, system failure, or intentional misconduct, that results in the permanent loss, irretrievable corruption, or unauthorised disposal of personal data. This includes:
-
Unintentional deletion or overwriting of records without adequate backup or recovery;
-
Misconfigured systems or retention rules that cause premature deletion of personal data;
-
Physical destruction or damage to media or paper records containing personal data where appropriate safeguards were not applied; and
-
Any deliberate or reckless act that destroys personal data in breach of legal, regulatory, contractual, or organisational requirements, including attempts to conceal wrongdoing or avoid accountability.
4. Examples of Potential Data Breaches
Examples may include:
-
sending an email containing client information to the wrong recipient;
-
losing a device containing client information;
-
leaving confidential paperwork accessible to unauthorised persons;
-
a client record being accessed without authorisation;
-
a password being compromised;
-
inappropriate disposal of confidential records;
-
a third-party service provider experiencing a security incident.
-
5. Immediate Response to a Suspected Breach
Where a suspected breach occurs, Helen Ward Therapy will take immediate steps to:
-
identify and contain the breach;
-
prevent further unauthorised access;
-
secure affected information;
-
establish what information has been affected;
-
record the details of the incident.
-
The priority is to reduce any potential harm while preserving relevant information required for investigation.
6. Assessment of Risk
Each breach will be assessed to determine:
-
what personal information has been affected;
-
whose information has been affected;
-
the sensitivity of the information involved;
-
the likelihood of harm occurring;
-
the severity of any potential impact;
-
whether action is required to protect affected individuals.
-
Special consideration will be given to breaches involving:
-
mental health information;
-
safeguarding information;
-
clinical records;
-
other Special Category Data under UK GDPR.
-
7. Notification Requirements
Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, Helen Ward Therapy will notify the Information Commissioner's Office (ICO) without undue delay and, where possible, within 72 hours of becoming aware of the breach.
Where a breach is likely to result in a high risk to individuals, affected individuals will also be informed without undue delay.
Notifications will include, where appropriate:
-
the nature of the breach;
-
the type of information affected;
-
likely consequences;
-
measures taken to address the breach;
-
steps individuals can take to protect themselves.
-
8. Confidentiality and Professional Considerations
Where a breach involves client information, Helen Ward Therapy will consider both legal data protection requirements and professional ethical responsibilities.
Any response will prioritise:
-
protecting client confidentiality;
-
reducing potential harm;
-
acting transparently and appropriately;
-
maintaining professional integrity.
-
9. Breaches Involving Third-Party Services
Where a breach involves a third-party service provider, Helen Ward Therapy will:
-
establish the nature and extent of the breach;
-
assess the impact on client information;
-
follow advice and procedures provided by the relevant provider;
-
take additional steps where necessary.
Appropriate consideration will be given when selecting service providers to ensure they provide appropriate security protections.
10. Client Notification
Where notification to clients is required, communication will be:
-
clear;
-
factual;
-
proportionate;
-
sensitive to the nature of the information involved.
Clients will be informed of:
-
what happened;
-
what information was affected;
-
what actions have been taken;
-
what they can do to protect themselves.
-
11. Recording Breaches
All suspected and confirmed breaches will be documented.
Records will include:
-
date of breach or discovery;
-
description of the incident;
-
information affected;
-
individuals affected (where known);
-
risk assessment;
-
actions taken;
-
decisions regarding notification;
-
outcome and learning points.
A breach record will be maintained even where notification to the ICO is not required.
12. Learning and Prevention
Following any breach, Helen Ward Therapy will review:
-
how the breach occurred;
-
whether procedures were followed;
-
whether additional safeguards are required;
-
whether policies or training need updating.
The purpose of review is improvement and prevention of future incidents.
13. Client Responsibilities
Helen Ward Therapy takes responsibility for protecting client information within its systems and processes.
Clients also share responsibility for maintaining confidentiality when using electronic communication methods.
Clients are encouraged to:
-
protect passwords and devices;
-
use secure communication methods;
-
ensure online therapy takes place in a private environment;
-
notify Helen Ward Therapy if they become aware that confidential information has been compromised.
-
14. Data Breach Contact Responsibility
As a sole practitioner, Helen Ward is responsible for:
-
managing suspected breaches;
-
assessing risks;
-
maintaining breach records;
-
deciding whether notification is required;
-
implementing remedial actions.
-
15. Policy Review
This policy will be reviewed annually or sooner where there are changes to:
-
legislation;
-
professional requirements;
-
technology;
-
practice procedures.
-
Related Documents
This policy should be read alongside:
-
Privacy Policy
-
Data Protection Policy
-
Confidentiality Policy
-
Record Keeping Policy
-
Data Retention and Secure Disposal Policy
-
Subject Access Request Procedure
-
Information Security Policy
-
Document Control
ICO Reference: ZC204139
Document Owner: Helen Ward Therapy
Approved By: Helen Ward
Version: 1.0
Effective Date: 30/05/26
Review Date: 30/05/27