Incident response · Clinical care providers
Incident Response Planning for Mental Health & Counselling Practices
An incident response plan tells a counselling practice exactly who does what in the first hours after a breach, before panic or improvisation sets in. For this niche the plan has to cover a scenario most incident templates never anticipate: individual clients being contacted directly and extorted with their own session notes, the pattern that defined the Vastaamo breach and that no therapy practice can treat as someone else's problem.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What the plan is built to protect once something goes wrong
Response planning here is less about stopping an attacker in progress and more about protecting clients from what happens after the data is already out.
Clients facing direct extortion
A plan for what happens if clients themselves start receiving contact demanding payment over their therapy notes, separate from and more urgent than notifying them of a breach.
The clinical record's integrity
Steps to confirm which records were affected without further disturbing evidence, so the practice can give clients an accurate answer rather than a guess.
Continuity of care during the response
A path to keep sessions running, even on paper temporarily, so clients in active treatment are not abandoned while systems are locked down.
The practice's relationships with EAPs and insurers
A communication plan for third parties who referred clients to the practice and will expect a prompt, accurate account of what happened.
Regulatory map
The notification duties an incident plan has to satisfy
PHIPA's notification threshold is unusually low for this niche, which changes what a plan needs to trigger and how fast.
No harm threshold for individual notice
PHIPA sets an unusually low bar here: virtually every unauthorized use, loss or theft obligates notice to the people affected, so a plan built around waiting to gauge severity first is already the wrong design.
IPC notification under O. Reg. 329/04
Certain breaches must also be reported to the Information and Privacy Commissioner, on a timeline the plan needs to name explicitly rather than leave to memory during a crisis.
Ransomware still triggers notification
A 2024 decision trilogy confirmed that encryption-only ransomware, where nothing is proven exfiltrated, still requires notification, closing off the assumption that a locked-but-not-stolen file is a non-event.
Quebec's 72-hour-capable duty
Law 25 expects a practice to be able to notify the CAI within 72 hours of confirming a risk-of-harm incident, which means the plan's timeline needs to be workable, not aspirational.
What goes wrong
The scenarios a therapy practice's plan has to rehearse
These are not hypothetical categories; each maps to a documented incident pattern in this exact type of practice.
Individual patient extortion
Finland's Vastaamo case is the reference point: a psychotherapy provider's database, left with no root password, was emptied of roughly 36,000 patients' session notes, and attackers then contacted patients one by one demanding payment in the hundreds of euros.
A breach at the practice-management vendor
When the incident originates at the platform rather than the practice, the plan has to define who confirms the scope, who drafts client communication, and how quickly the vendor is expected to respond.
A stolen laptop holding process notes
Portable devices carrying downloaded notes or supervision recordings remain one of the simplest ways a breach happens, and a plan needs a fast path from theft report to encryption verification to notification decision.
Misdirected records
A note sent to the wrong lawyer, school or physician is a recurring, quieter incident type, and a plan should treat it with the same clarity as a larger breach rather than as an embarrassing exception.
Our incident response for mental health & counselling practices
What the incident response plan covers
The deliverable is a usable document, not a binder that sits unread until it is too late to help.

A defined incident response team
Named roles, likely the owner-clinician, a designated privacy contact and, where relevant, a clinical lead for continuity of care, each with clear authority during a response.
Scenario-specific playbooks
Separate, concrete steps for a platform breach, a lost device, and direct client extortion, since each demands a different first move and a different message.
Client communication templates
Draft notification language for individuals, written in plain terms appropriate for people who are also, in many cases, currently in active therapy with the practice.
A notification decision tree
Clear criteria for when PHIPA notice to individuals is triggered, when the IPC must be told, and how March 1 statistics tracking captures the event.
A tested contact list
Current numbers and escalation paths for the practice-management vendor, legal counsel, cyber-insurance carrier and, where applicable, law enforcement.
How the engagement runs
How we build the plan with your practice
Step 1
Map the realistic scenarios
We start from your actual systems and staffing, a solo clinician on one platform looks nothing like a thirty-clinician virtual group, and identify which incidents are plausible.
Step 2
Draft the playbooks and roles
Each scenario gets a specific sequence of actions and a named owner, including the extortion scenario most generic templates skip entirely.
Step 3
Build notification materials in advance
Client letters, IPC notification drafts and vendor-contact scripts are prepared before they are needed, so nothing is written for the first time under pressure.
Step 4
Walk through the plan with your team
A tabletop exercise tests whether the plan actually works with your real staff and systems, and surfaces gaps while the stakes are still theoretical.
What it costs
What affects incident response planning cost for a practice
Pricing depends mainly on how many systems and locations need scenario coverage, whether the practice operates across provinces with different notification regimes, and how much of the underlying documentation, an asset inventory, a vendor list, already exists. A solo practitioner on a single platform needs a leaner plan than a multi-site group running its own video infrastructure.
For practices that want this handled on an ongoing basis rather than as a one-time document, incident planning is folded into the Virtual Privacy Officer retainer. Tell us your setup and we will scope the work.
Mental Health & Counselling Practices: Incident response questions, answered
Legally, the notification obligation to your clients stays with you as the custodian, even when the breach originates at the vendor. Your plan should specify that you will confirm scope with the vendor first, then issue notice yourselves rather than waiting for or relying solely on the vendor's own communication, since their notice may not satisfy your specific PHIPA obligations or reach clients in the way your practice needs to.
The immediate steps are to confirm whether the device was encrypted and whether notes were stored locally versus only accessed through the cloud platform, report the theft, and assess based on those facts whether notification is triggered, which under PHIPA's low threshold it usually will be. A good plan has this sequence, and the encryption-status question specifically, written down in advance so it does not get skipped in the first frantic hour.
This needs its own playbook, separate from a standard breach notice. It typically includes urgent, direct outreach to affected clients before they receive the extortion contact if timing allows, clear guidance not to pay or engage with the extortionist, coordination with law enforcement, and, given the clinical stakes, involvement of a colleague or supervisor to support clients through what is itself a significant harm. Generic incident templates rarely address this, which is exactly why this niche needs its own.
A written plan matters even more for a solo practitioner, because there is no colleague to catch a missed step under pressure. The plan does not need to be long, but it should specify the notification threshold, who gets called first, and where client contact information is stored if the primary system is the thing that is compromised.
Review it whenever the practice changes platforms, adds a clinician, expands telepractice into a new province, or adopts a new tool like an AI scribe, and otherwise at least annually. A plan built around last year's systems and staff will not hold up when it is actually needed, and stale contact information is one of the most common reasons a real response starts slower than it should.
More for mental health & counselling practices
Other services for this niche
About this service
Answers & guides
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.