January 20, 2026 The First Hours After a Data Breach: What an Ontario Dental Practice Must Do Under PHIPA
Most of the coverage a dental practice sees about data breaches is about someone else – a manufacturer, a software vendor, a hospital network in another province. This one is about you, and specifically about the hours after you discover that patient information in your own practice has been lost, stolen, or exposed. A ransomware note on the reception screen, a laptop gone from a car, an email of X-rays sent to the wrong address, a former team member who took a patient list: in Ontario, each of these starts the same set of legal duties under the Personal Health Information Protection Act (PHIPA). The practices that come through it well are the ones that decided what to do before it happened.

PHIPA does not read like an emergency plan, so this article translates it into one. It follows the response protocol the Information and Privacy Commissioner of Ontario (IPC) publishes for health organizations – contain, notify, investigate, prevent – and points out the specific decisions a dental practice has to make at each step.
First, know that the duty is yours
Under PHIPA, a dentist who collects and holds patient records is a health information custodian. That single legal label is what makes the rest of this non-negotiable: the obligations to safeguard personal health information, to notify patients when it is breached, and in defined cases to report to the IPC rest on the practice itself. Your IT company, your practice-management vendor, and your cloud backup provider are agents acting on your behalf – useful and often essential in a response, but they do not inherit your statutory duty. When a breach happens, the buck stops at the practice, not the help desk.

That is worth internalizing on a calm day, because it changes who needs to understand this playbook. It is not only the IT contact. The dentist-owner and the privacy officer – in a small practice, often the same person or the office manager – need to know these steps well enough to act on the morning they matter.
Step one: contain the breach
Before anything else, stop the bleeding. Containment means limiting how much information is exposed and preventing the breach from spreading: isolate the affected computer or system from the network, disable the compromised account, retrieve the misdirected file or device if you can, and change the credentials that were involved. If ransomware is active, disconnecting affected machines from the network – rather than powering them off – is usually the right first move, and it is the point at which you call for expert help rather than improvising.

One instinct to resist: do not wipe, reimage, or “clean up” the affected systems yet. You will need to understand what happened, and the evidence – system logs, access records, the malware itself – lives on those machines. Preserve it. A useful discipline here is to note the time of discovery and keep a running log of every action your team takes from that point forward. It costs nothing in the moment and is invaluable later.
A word on timing, because it is widely misunderstood. PHIPA does not impose a fixed countdown the way Europe’s GDPR sets a 72-hour deadline. Its standard is that you act “at the first reasonable opportunity.” That is not a licence to be slow – it is a duty to move promptly – but it means the goal is a prompt, competent response, not beating an arbitrary clock while getting the facts wrong.
Step two: notify the affected patients
PHIPA requires a custodian to notify the individuals whose personal health information was lost, stolen, or accessed without authority, and to do so at the first reasonable opportunity. The Act does not dictate the method – depending on the circumstances, notification might be a phone call, a letter, or another appropriate channel – but the substance matters. Affected patients should be told, in plain language, what happened, what information was involved, what you are doing about it, and what steps they can take to protect themselves. Crucially, PHIPA also requires that you tell them they are entitled to complain to the Information and Privacy Commissioner of Ontario.

It is tempting to soften or delay this conversation, and understandable – no one enjoys telling a patient their information was exposed. Resist that too. A prompt, honest, specific notification protects your patients and, frankly, protects the practice’s credibility far better than a discovery months later that you knew and stayed quiet. Transparency, done early, is the reputational strategy as well as the legal one.
Step three: decide whether you must also report to the IPC
Notifying patients and notifying the regulator are two separate obligations, and not every breach reaches the second. Since October 2017, PHIPA regulations require custodians to report a breach to the IPC when it falls into defined categories – among them information that was stolen; information used or disclosed without authority, such as an employee snooping in records they had no business viewing; breaches where significant harm to a patient has resulted or is likely to; and a pattern of similar breaches suggesting a systemic problem. When one of these applies, the report to the IPC is likewise made at the first reasonable opportunity.

Because that judgment call carries real consequences, it is one to make carefully and, when the exposure is serious or the answer is unclear, with professional advice. There is also a second, quieter IPC obligation that catches practices off guard: every health information custodian must file an annual statistical report of the breaches they experienced in the previous calendar year, submitted to the IPC by March 1. Even breaches too minor to report individually are counted there – which is one more reason to keep an internal log of every incident as it happens.
Step four: investigate, document, and prevent a repeat
Once the immediate response is done, close the loop. Investigate how the breach happened and how far it reached: what was the root cause, which safeguard failed or was missing, and could it happen again tomorrow. Write it down – a short internal record of the timeline, the information involved, the notifications made, and the decisions taken – both because you may have to account for it and because memory fades. Then fix the underlying gap, whether that is a missing patch, an over-broad access permission, an unencrypted laptop, or a staff member who needs retraining. A breach you learn nothing from is a breach you have half-invited to return.
The readiness that makes all of this possible
Every step above is easier – or only possible at all – when the groundwork is in place before the bad morning. You cannot preserve logs you never enabled, cannot tell patients exactly what was exposed without knowing what data lived where, and cannot recover from ransomware without backups the attacker could not reach. Practical readiness for an Ontario dental practice means a handful of things kept in good order: reliable, tested, offline or immutable backups so encryption is a recoverable event rather than a catastrophe; access logging and monitoring so you can reconstruct who touched what; an up-to-date inventory of the systems and vendors that hold patient data; and a written incident-response plan naming who does what, with the IPC’s protocol built in, so no one is reading the statute for the first time under pressure.
Compudent Systems helps dental practices across the GTA and Ontario put exactly that readiness in place – hardened and tested backups, access logging, an accurate map of where patient data lives, and a written breach-response plan aligned to PHIPA and the IPC’s protocol so your team knows the steps before it needs them. If your practice does not have a documented plan for the first hours after a breach, or you are not certain your backups would survive a ransomware attack, contact Compudent Systems for a security and breach-readiness assessment. The first reasonable opportunity to prepare is the one before anything goes wrong.
Sources & further reading:
- Report a health privacy breach – Information and Privacy Commissioner of Ontario
- Health privacy breach protocol – Information and Privacy Commissioner of Ontario