Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Incident response · Clinical care providers

Incident Response Planning for Home & Community Care Agencies

An incident response plan for a home and community care agency answers two questions at once: how five hundred visits scheduled for tomorrow still happen if the scheduling system goes down tonight, and who coordinates notification when Ontario Health atHome, an OHT partner and the agency itself all have a stake in the same incident. The plan usually gets built after a near-miss, before a contract renewal asks for one, or in direct response to how slowly a recent sector-wide vendor incident was disclosed to patients.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What the plan has to keep running, not just secure

A home-care incident plan carries an operational burden most office-based plans do not: visits cannot simply pause while the investigation happens.

Visit continuity when scheduling goes down

A documented fallback, paper schedules, phone trees, or a backup export, so tomorrow's visits still happen even if the primary platform is unavailable or under investigation.

Notification order across every affected party

A defined order for looping in Ontario Health atHome, any OHT partner and affected clients, so nobody is notified twice, contradicted, or missed.

Field-worker communication during an incident

A way to reach personal support workers and nurses already in clients' homes with instructions, without relying solely on the system that may itself be compromised.

Evidence preservation from mobile devices

A procedure for isolating or imaging a field device involved in an incident without disrupting the worker's ability to complete their shift or reach their next client.

Vendor-originated incident triage

A process for assessing exposure quickly when the incident starts at a vendor, equipment supplier or platform provider rather than inside the agency's own systems.

Regulatory map

The notification duties the plan has to satisfy on time

Several statutory clocks can start from the same incident, and the plan exists to track them from the first hour rather than the first week.

PHIPA's first-reasonable-opportunity standard

Section 12(2) requires notifying affected individuals at the first reasonable opportunity, a standard the plan has to operationalize into a specific internal timeline, not leave as an abstract legal phrase.

Read our guide →

O. Reg. 329/04's IPC reporting duty

Section 6.3 sets out mandatory circumstances for reporting a breach to the IPC, which the plan should flag automatically once an incident meets the defined thresholds.

Primary source →

The financial stakes of getting the response wrong

PHIPA fines of up to $200,000 for an individual and $1,000,000 for an organization raise the cost of a response that misses deadlines or under-documents what happened.

Primary source →

Alberta HIA's mandatory breach notice

Section 60.1 requires custodians to notify the Commissioner and affected individuals where a reasonable risk of harm exists, a parallel clock for any agency operating continuing-care services in Alberta.

Primary source →

What goes wrong

The scenarios the plan is written to answer

These are not hypothetical exercises for this sector; each has a documented precedent the plan has to be tested against.

  • A vendor incident with a slow, public disclosure

    A ransomware attack on a contracted equipment supplier stayed undisclosed for weeks before political pressure forced it into the open, the exact delay a rehearsed plan is meant to prevent from repeating.

    Source →

  • Direct compromise with extortion pressure

    A prior attack on a national provider saw attackers attempt to pressure the organization through media contact, a scenario the plan should address with a defined communications and legal response, not an improvised one.

  • Scheduling system failure the night before visits

    Whether caused by an attack or an ordinary outage, a down scheduling platform threatens same-day care delivery in a way most office-based incident plans never have to consider.

  • A missing or stolen field device

    A lost phone holding care plans and lockbox codes needs an immediate remote-wipe or access-revocation step, distinct from a slower-moving system breach.

Our incident response for home & community care agencies

What our incident response plan covers for an agency

The plan is written around your actual contracts, platform and workforce structure, not a generic breach template with your name added.

Senior couple on a walk in an autumn nature
  1. Custom incident procedures

    Detection, escalation and containment steps built around your scheduling platform, field workforce structure and existing vendor relationships.

  2. Multi-party notification sequencing

    A documented order for notifying Ontario Health atHome, any OHT partner, affected clients and the IPC, agreed in advance rather than negotiated mid-incident.

  3. Visit-continuity procedures

    A fallback plan for keeping scheduled visits running if the primary platform is unavailable during containment or investigation.

  4. Roles, responsibilities and vendor coordination

    Clear ownership across leadership, IT, the vCISO or VPO if engaged, and defined points of contact at key vendors and Ontario Health atHome.

  5. A review schedule that keeps pace with the agency

    Scheduled review as contracts renew, the platform changes, or the regulatory environment shifts, so the plan reflects the agency you actually are this year.

How the engagement runs

How the plan gets built and kept current

Building the plan starts with the operational question of visit continuity, then layers in the regulatory and vendor coordination pieces.

  1. Step 1

    Map the real incident scenarios

    We identify the events most likely to hit your agency specifically: a vendor breach, a platform outage, a lost device, a direct compromise, rather than a generic list.

  2. Step 2

    Build the notification and continuity procedures

    We draft the multi-party notification sequence and the visit-continuity fallback together, since both have to work under the same time pressure.

  3. Step 3

    Assign roles and vendor contacts

    Every step gets an owner, and key vendors and Ontario Health atHome contacts are documented so the first call during an incident is not a search.

  4. Step 4

    Test the plan

    A tabletop exercise walks leadership and field-operations staff through a realistic scenario, surfacing gaps before a real incident does.

  5. Step 5

    Review and update

    The plan is revisited on a set schedule and after any contract, platform or vendor change that would alter who needs to be notified.

What it costs

What shapes incident response plan cost for a home-care agency

Cost tracks the number of funding contracts and provinces involved, how many vendors and platforms need a defined notification path, and whether a tabletop exercise is included alongside the written plan. An agency with a single contract needs a simpler plan than one coordinating across several OHTs and a subcontracted staffing partner.

Existing documentation, an older breach procedure or a platform vendor's own incident runbook, can shorten the work if it is current and accurate. Tell us your contract and vendor footprint and we will scope a tailored quote.

Home & Community Care Agencies: Incident response questions, answered

The plan needs a documented fallback before the outage happens: an exported or printed schedule, a phone tree to reach field staff directly, and a defined threshold for when to activate it rather than waiting to see if the system comes back on its own. Building this into the incident plan, rather than treating it as a separate IT problem, keeps care delivery and the privacy response coordinated.

The agency typically coordinates its own notification to affected clients, while a shared incident touching the CHRIS system or another SPO's contract needs an agreed sequence with Ontario Health atHome and any OHT partner so nobody duplicates or contradicts the other's message. The plan should name who owns that coordination role before an incident forces the question.

That waiting for a vendor to fully confirm scope before saying anything to patients created weeks of exposure and, ultimately, public and political scrutiny. A rehearsed plan sets an internal timeline for at least acknowledging an incident is under investigation, rather than staying silent until every fact is confirmed.

Yes. A lost or misplaced paper file follows a different containment path than a system breach, no remote wipe is possible, so the plan should include a specific procedure for assessing what the document contained, notifying the affected client, and documenting the loss for the IPC statistics filing.

A home-care plan has to account for care continuity, keeping visits happening despite the incident, and coordination with external parties like Ontario Health atHome that most businesses never have to loop in. A generic template built for a single-office company misses both of these entirely.

At least annually, with a tabletop exercise that includes both leadership and someone from field operations, since the visit-continuity steps only work if the people managing schedules know their role. Testing again after any material change to contracts, vendors or the care-management platform keeps the plan realistic rather than theoretical.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.