Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Incident response · Clinical care providers

Incident Response Planning for Dental Practices

An incident response plan tells your dental practice exactly what to do the morning the practice-management system won't open: who isolates what, who is called first, and how patients get treated while the PMS is down. Dental offices need their own version because the fallout runs through PHIPA, the IPC, RCDSO and often an insurer and a claims switch all at once. We build the plan around your PMS, your imaging setup and your provinces, then keep it current.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What a dental incident plan has to hold together

The plan exists to stop a bad morning from becoming a worse week, by deciding in advance what would otherwise be improvised under pressure.

Continuity of patient care

The plan sets out how the front desk and clinical team keep the day's schedule running on paper when the PMS, imaging server or claims connection is unavailable.

The notification sequence

Who gets told, and in what order, among patients, the IPC, RCDSO, the cyber insurer and, where relevant, CDCP's Sun Life billing contact, is decided before an incident rather than argued about during one.

Evidence and the incident record

PHIPA and RCDSO both expect a documented account of what happened, and the plan builds that record as the response unfolds instead of reconstructing it from memory weeks later.

Vendor and IT coordination

Contacts and expectations for your PMS vendor, imaging support and MSP are set out in advance, so isolating a system doesn't stall on finding the right phone number.

Regulatory map

The notification duties a dental practice's plan has to encode

Which obligations fire, and how fast, depends on where the practice operates and what was affected. The plan maps each one to its trigger.

PHIPA's first-reasonable-opportunity duty

Section 12(2) requires notifying affected individuals at the first reasonable opportunity following a breach, a standard the plan turns into a concrete timeline rather than a vague intention.

Read our guide →

IPC reporting triggers under O. Reg. 329/04

Section 6.3 sets out when a breach must be reported to the IPC, including theft, unauthorized use or disclosure, and situations reportable to a College, each mapped in the plan to what would trigger it at your practice.

Primary source →

Encryption-only incidents still require notice

IPC decisions now treat a ransomware-encrypted chart as a reportable loss on its own, regardless of whether the attacker actually copied anything out, so waiting for proof of theft before acting is no longer defensible.

Primary source →

RCDSO's expectations after an incident

RCDSO's guidance on electronic records assumes the dentist retains ultimate control of patient data, which shapes what the College expects to see documented after an incident involving a cloud or third-party system.

Primary source →

What goes wrong

The scenarios a dental practice's plan is written against

These are drawn from incidents that have actually hit Canadian dental practices and the vendors around them, not hypothetical worst cases.

  • Ransomware locking the PMS

    Ryuk ransomware took a Toronto practice's systems offline in a real Canadian case, and the office ultimately fell back on backups to recover, which is the scenario this plan's ransomware runbook is written for.

    Source →

  • A compromise at a billing or benefits partner

    Patient data can be exposed without a single office ever being touched directly, which is what happened when ransomware hit the Alberta Dental Service Corporation, the company Alberta relies on to process dental benefit claims.

    Source →

  • A lost device carrying patient images

    A laptop or camera holding intraoral photos or radiographs, lost or stolen unencrypted, has long been an IPC concern and triggers a different, faster branch of the plan than a network incident.

Our incident response for dental practices

What the incident response planning engagement delivers

This produces documents your staff can actually follow during a bad morning, built around your systems rather than adapted from a generic template.

Luxury and minimalist hospital reception counter area in white and wood style with counter
  1. The core response plan

    Roles, decision authority and escalation steps for the principal dentist, office manager, MSP and PMS vendor, kept short enough to use while the office is disrupted.

  2. A paper-fallback protocol

    Step-by-step guidance for keeping the day's patients moving on paper charting and manual scheduling while systems are down, and for reconciling paper records back into the PMS once it's restored.

  3. A notification matrix

    Every obligation, from PHIPA and the IPC through RCDSO to your cyber insurer and, where relevant, Sun Life's CDCP billing contact, with its trigger and owner on one page.

  4. Ransomware and lost-device runbooks

    Separate step-by-step sequences for a network-wide ransomware event and for a lost device, since the two demand different first moves and different notification timelines.

  5. A working session with your team

    We walk your named responders through the plan against a realistic scenario, then update the documents as your systems, provinces or staff change.

How the engagement runs

Building the plan with your practice

  1. Step 1

    Map your systems and obligations

    We inventory your PMS, imaging setup, claims connections and provinces of operation against the specific regulators and colleges each would involve.

  2. Step 2

    Draft with your team

    The plan is written with your office manager, MSP and PMS vendor contact, so the steps match how mornings actually work at your practice.

  3. Step 3

    Test it

    A tabletop session runs your team through a ransomware or lost-device scenario, surfacing gaps in contacts or authority before a real incident does.

  4. Step 4

    Keep it current

    Annual reviews, plus updates whenever you change PMS vendors or add a location, keep the plan usable rather than shelved.

What it costs

Pricing an incident response plan for a dental office

Effort depends on how many provinces the practice operates in, how many systems and vendors are in scope, whether a multi-location paper-fallback protocol is needed, and whether a facilitated tabletop session is included. A single Ontario office is a compact project compared to a DSO with locations in three provinces.

Practices on the Virtual Privacy Office retainer already receive an incident management protocol as part of the monthly service, so it's worth checking which route fits before commissioning a standalone plan. A short scoping call is enough to price the work accurately.

Dental Practices: Incident response questions, answered

Containment comes first: isolate affected systems so the damage stops spreading, without turning off backups that might be needed for recovery. The plan then moves the front desk to a documented paper-fallback protocol so patients can still be seen, while a designated person contacts the insurer and begins the notification analysis. Knowing this sequence in advance is the entire point of having a plan rather than deciding it that morning.

The plan's notification matrix sets this out by trigger rather than leaving it to guesswork. Typically the insurer is contacted early because coverage decisions and approved response support flow from that call, patients are notified at the first reasonable opportunity once the scope of the breach is understood, and IPC reporting follows where O. Reg. 329/04's triggers are met. RCDSO involvement depends on the nature and severity of the incident.

Yes, and the plan's paper-fallback protocol exists specifically to make this workable rather than improvised. It covers manual scheduling, paper charting for the day's appointments, and a defined process for reconciling those paper records back into the PMS once it's restored, so nothing gets lost or duplicated in the transition back to normal operations.

It can. If the workstation or connection submitting claims through CDAnet and ITRANS is affected, predeterminations and claims may need to be held or submitted manually once systems are restored. The plan accounts for this by identifying which claims processes depend on which systems, so billing continuity is addressed alongside patient care during the outage.

Recent IPC decisions treat encryption of any patient records, including radiographs and imaging data, as a loss requiring notification even if the core chart system wasn't affected and no data was confirmed stolen. The plan doesn't wait for proof of exfiltration before starting the notification analysis, because that standard no longer holds up under current IPC guidance.

The plan's lost-device runbook starts by determining whether the device was encrypted and whether remote wipe is possible, which changes the entire analysis. An encrypted device with a successful remote wipe often means limited exposure; an unencrypted device holding patient images points toward notification and IPC reporting. Either way, the incident is logged and documented as part of your ongoing record.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.