Legal & Compliance Centre

AIAH Health Limited · Company No. 17322326

Data Breach Response Plan

How AIAH.Health identifies, contains, investigates and reports personal data breaches under UK GDPR.

Last updated: 7 July 2026

This Plan defines the actions AIAH Health Limited takes when a personal data breach is suspected or confirmed. It ensures we meet the 72-hour notification obligation to the Information Commissioner's Office (ICO) under Article 33 UK GDPR and, where required, notify affected individuals under Article 34.

1. Definitions

A 'personal data breach' is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

2. Incident identification

  • Automated alerts from monitoring, WAF, EDR and cloud provider controls.
  • Staff reports through the internal incident reporting channel.
  • External reports from users, partners, security researchers or regulators.

3. Internal reporting and escalation

Any suspected incident must be reported immediately to the Security Incident Lead at [security@aiah.health]. The Incident Lead convenes the response team (Engineering, DPO, Legal, Communications) and starts an incident log.

4. Triage and initial containment

  • Isolate affected systems (revoke credentials, rotate keys, quarantine hosts).
  • Preserve evidence (logs, memory captures, disk images).
  • Prevent further exposure while investigation proceeds.

5. Risk assessment

The DPO assesses the likelihood and severity of risk to individuals' rights and freedoms, considering: type and volume of data affected; identifiability; ease of exploitation; special category data involvement; and potential consequences (financial, reputational, safeguarding, physical).

6. ICO notification (within 72 hours)

If the breach is likely to result in a risk to individuals, the DPO notifies the ICO without undue delay and, where feasible, within 72 hours of becoming aware. Notification includes: nature of the breach, categories and approximate number of individuals and records, contact for the DPO, likely consequences, and measures taken or proposed. Where information is not immediately available it is provided in phases.

7. Notification to individuals

Where the breach is likely to result in a high risk to individuals, we notify affected people without undue delay in clear and plain language, describing what happened, likely consequences, measures taken and steps they can take to protect themselves. Where direct notification is disproportionate we make a public communication or equivalent measure.

8. Documentation

Every incident (whether or not notifiable) is recorded in the personal data breach register with: facts, effects, remedial action, decisions taken and rationale. Records are retained for 6 years.

9. Investigation and root cause analysis

Engineering leads a technical investigation to establish root cause. The DPO documents findings and required remediation. Where a third-party processor is involved, we require them to co-operate and provide evidence.

10. Business continuity

  • Restore services from clean, verified backups following our disaster recovery playbook.
  • Maintain a communications plan for customers, partners and regulators.
  • Test business continuity annually.

11. Lessons learned

A post-incident review is completed within 30 days of closure and its actions tracked to completion. Lessons feed into policy, controls and training updates.

12. Testing this plan

We test this plan through a tabletop exercise at least annually and after any material change in systems or team.