Incident response · Clinical care providers
Incident Response Planning for Medical Imaging Clinics
An incident response plan for a medical imaging clinic has to answer the exact question PHIPA Decision 249 put on the record: what happens when the RIS or PACS is encrypted, the waiting room is full, and someone has to decide whether to pay a ransom. We build a plan drawn directly from that decision, covering downtime-imaging procedures, the notification math for a breach touching hundreds of thousands of records, and the decisions your team needs to make before an attacker forces them.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What the plan has to cover when imaging systems go down
A generic breach plan assumes data theft; an imaging clinic also has to keep patients moving through the building while systems are offline.
Downtime imaging procedures
How technologists continue scanning, on paper requisitions or a fallback workstation, while the RIS and PACS are unavailable, so patients already booked aren't turned away mid-crisis.
The ransom decision itself
Who has authority to decide whether to pay, what information they need before deciding, and how that decision gets documented, since Decision 249 shows the IPC will scrutinize the reasoning after the fact.
Log and backup preservation from minute one
Steps to prevent logs from being overwritten and backups from being deleted or encrypted alongside production data, the two specific failures that limited the IPC's own investigation in Decision 249.
Multi-site containment
Whether an attack at one clinic can spread to every other site's PACS, and what isolation steps a technologist or office manager can execute without waiting for IT to arrive.
Mass patient notification at scale
A process built to notify tens or hundreds of thousands of patients if needed, not a template designed for a handful of affected individuals.
Regulatory map
The notification duties an imaging clinic's plan has to reconcile
PHIPA sets the statutory clock, and Decision 249 shows exactly how a regulator evaluates the response once it starts.
PHIPA's breach notification duty
Section 12(2) and the custodian's duty to notify affected individuals at the first reasonable opportunity apply regardless of clinic size, and a plan has to operationalize what 'first reasonable opportunity' means at scale.
Decision 249's findings on the response itself
The IPC found the clinic's response adequate overall while still publishing prevention expectations, a rare case where the regulator's reasoning about what counts as a reasonable incident response is spelled out in detail.
Encryption-only events are notifiable loss
The IPC's 2024 decision trilogy confirmed that encryption alone, without confirmed exfiltration, still meets PHIPA's notification threshold, removing any ambiguity a plan might otherwise build in.
Audit-log duties that shape investigation capability
O. Reg. 329/04 section 6.3's audit-log requirements determine whether your team can actually answer the IPC's questions about scope, which is precisely what overwritten logs prevented in Decision 249.
What goes wrong
The incident this plan is written around
Decision 249 is not a hypothetical scenario; it is the documented event Ontario's imaging sector now measures every response against.
Ransomware entering through a dormant account
The clinic's December 2022 attack began with a privileged account nobody had disabled, affecting up to 550,000 patient records and 1.6 million case files before the clinic paid to restore services.
Logs overwritten mid-investigation
Short retention windows meant investigators could not fully reconstruct the attacker's path, a gap a plan closes by defining log preservation steps the moment an incident is suspected.
Backups gone at the worst possible moment
The same attacker deleted backups, leaving the ransom as the only path back to operating, which is why a plan has to specify offline, tested backups the response can actually rely on.
A waiting room full of patients mid-crisis
Unlike a back-office breach, an imaging clinic's incident happens in front of patients who are physically present, adding a communications and continuity dimension most incident plans never anticipate.
Our incident response for medical imaging clinics
What our incident response planning delivers for an imaging clinic
A working plan built from Decision 249's specifics, tested rather than filed away.

A downtime-imaging procedure
Documented steps for continuing to scan and register patients on paper or a fallback system while the RIS and PACS are unavailable, agreed with your technologists in advance.
A ransom-decision framework
Clear authority, decision criteria and documentation requirements for the ransom question, so the decision is defensible and made by the right people under pressure, not improvised.
Notification templates sized for scale
Pre-drafted language and a process built to reach a mass patient population, tested against the scale a multi-site imaging breach could realistically involve.
Roles and escalation across sites
A clear chain from the technologist who first notices a problem to the executive who approves ransom decisions and patient notification, sized for how your clinic group actually operates.
Log and backup preservation procedures
Specific steps to prevent the two failures Decision 249 identified, log overwriting and backup deletion, built into the plan's first-hour actions.
A tabletop exercise
A rehearsal run against a ransomware scenario modelled on Decision 249, so the plan is tested against your actual sites and systems before a real incident tests it for you.
How the engagement runs
How we build the plan with your clinic
Structured to produce a document your technologists and office managers will actually use, not just leadership.
Step 1
Map systems and downtime workflows
We review your RIS, PACS and modality environment across every site and document how patient flow continues if any of them go offline.
Step 2
Draft the plan and templates
Roles, the ransom-decision framework, log and backup preservation steps, and notification templates are drafted in plain language, sized to your actual team.
Step 3
Run a tabletop exercise
We walk your team through a ransomware scenario built on Decision 249's facts to test the plan's decision points and timing before a real incident does.
Step 4
Refine and keep current
The plan is updated as sites, vendors and systems change, so it stays accurate rather than becoming a document nobody trusts when it matters.
What it costs
What shapes the cost of incident response planning for an imaging clinic
Cost depends on how many sites and systems the plan needs to cover, whether a downtime-imaging procedure needs to be built from scratch, and whether a tabletop exercise is included. A single-site ultrasound clinic needs less scoping than a multi-site MRI and CT group with teleradiology links.
Incident response planning is frequently delivered as part of a broader policy set inside a Virtual Privacy Office retainer, which keeps the plan current as sites and vendors change. We quote the initial build after reviewing your systems and site count.
Medical Imaging Clinics: Incident response questions, answered
The plan splits into two simultaneous tracks: continuity, moving to a documented downtime-imaging procedure so booked patients keep being seen on paper or a fallback system, and containment, isolating affected systems while preserving logs and backups from further damage. Front-desk staff need a short, rehearsed script for patients, and the decision chain for ransom and notification runs in parallel rather than waiting for continuity to be resolved first.
Ransom authority should sit with a named individual or small group defined in the plan before an incident, not improvised during one, and their decision needs to be documented with the reasoning behind it. Decision 249 teaches that overwritten logs and deleted backups compound a ransomware event badly: the clinic paid partly because backups were gone, and investigators could not fully reconstruct the attack because logs hadn't survived, both of which a plan addresses with first-hour preservation steps.
At that scale, notification needs a process built for volume from the start: a mail or communication vendor capable of the mailing size, a call centre or web page to handle the inquiry volume that follows, and a phased approach if full scope isn't confirmed immediately. A plan built only for notifying a handful of individuals collapses under a Decision 249-sized event, which is why the notification workstream gets sized to worst case, not typical case, during planning.
The plan should name each site's specific systems and continuity workflow while sharing one escalation structure and decision framework across the group. A multi-site clinic's biggest planning risk is assuming every location has identical systems and staffing; the plan needs to reflect where a satellite site's downtime procedure genuinely differs from the flagship location's.
Generic advice doesn't account for patients physically present in your waiting room, DICOM-specific systems, or a documented regulator decision showing exactly what was scrutinized after a comparable event. This plan is built from Decision 249's specifics, downtime imaging, the ransom decision, log and backup preservation, mass notification, rather than adapted from a template written for an office breach.
Yes, and a tabletop exercise is part of building it properly. Walking your team through a ransomware scenario modelled on Decision 249 surfaces gaps, an undefined ransom authority, an untested downtime procedure, before those gaps matter, and it gives technologists and office managers practice with a plan they might otherwise only see once, during a real crisis.
More for medical imaging clinics
Other services for this niche
About this service
Answers & guides
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.