Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Incident response · Clinical care providers

Incident Response Planning for Mental Health & Counselling Practices

An incident response plan tells a counselling practice exactly who does what in the first hours after a breach, before panic or improvisation sets in. For this niche the plan has to cover a scenario most incident templates never anticipate: individual clients being contacted directly and extorted with their own session notes, the pattern that defined the Vastaamo breach and that no therapy practice can treat as someone else's problem.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What the plan is built to protect once something goes wrong

Response planning here is less about stopping an attacker in progress and more about protecting clients from what happens after the data is already out.

Clients facing direct extortion

A plan for what happens if clients themselves start receiving contact demanding payment over their therapy notes, separate from and more urgent than notifying them of a breach.

The clinical record's integrity

Steps to confirm which records were affected without further disturbing evidence, so the practice can give clients an accurate answer rather than a guess.

Continuity of care during the response

A path to keep sessions running, even on paper temporarily, so clients in active treatment are not abandoned while systems are locked down.

The practice's relationships with EAPs and insurers

A communication plan for third parties who referred clients to the practice and will expect a prompt, accurate account of what happened.

Regulatory map

The notification duties an incident plan has to satisfy

PHIPA's notification threshold is unusually low for this niche, which changes what a plan needs to trigger and how fast.

No harm threshold for individual notice

PHIPA sets an unusually low bar here: virtually every unauthorized use, loss or theft obligates notice to the people affected, so a plan built around waiting to gauge severity first is already the wrong design.

Primary source →

IPC notification under O. Reg. 329/04

Certain breaches must also be reported to the Information and Privacy Commissioner, on a timeline the plan needs to name explicitly rather than leave to memory during a crisis.

Primary source →

Ransomware still triggers notification

A 2024 decision trilogy confirmed that encryption-only ransomware, where nothing is proven exfiltrated, still requires notification, closing off the assumption that a locked-but-not-stolen file is a non-event.

Primary source →

Quebec's 72-hour-capable duty

Law 25 expects a practice to be able to notify the CAI within 72 hours of confirming a risk-of-harm incident, which means the plan's timeline needs to be workable, not aspirational.

Primary source →

What goes wrong

The scenarios a therapy practice's plan has to rehearse

These are not hypothetical categories; each maps to a documented incident pattern in this exact type of practice.

  • Individual patient extortion

    Finland's Vastaamo case is the reference point: a psychotherapy provider's database, left with no root password, was emptied of roughly 36,000 patients' session notes, and attackers then contacted patients one by one demanding payment in the hundreds of euros.

    Source →

  • A breach at the practice-management vendor

    When the incident originates at the platform rather than the practice, the plan has to define who confirms the scope, who drafts client communication, and how quickly the vendor is expected to respond.

  • A stolen laptop holding process notes

    Portable devices carrying downloaded notes or supervision recordings remain one of the simplest ways a breach happens, and a plan needs a fast path from theft report to encryption verification to notification decision.

  • Misdirected records

    A note sent to the wrong lawyer, school or physician is a recurring, quieter incident type, and a plan should treat it with the same clarity as a larger breach rather than as an embarrassing exception.

Our incident response for mental health & counselling practices

What the incident response plan covers

The deliverable is a usable document, not a binder that sits unread until it is too late to help.

Studying with video online lesson at home
  1. A defined incident response team

    Named roles, likely the owner-clinician, a designated privacy contact and, where relevant, a clinical lead for continuity of care, each with clear authority during a response.

  2. Scenario-specific playbooks

    Separate, concrete steps for a platform breach, a lost device, and direct client extortion, since each demands a different first move and a different message.

  3. Client communication templates

    Draft notification language for individuals, written in plain terms appropriate for people who are also, in many cases, currently in active therapy with the practice.

  4. A notification decision tree

    Clear criteria for when PHIPA notice to individuals is triggered, when the IPC must be told, and how March 1 statistics tracking captures the event.

  5. A tested contact list

    Current numbers and escalation paths for the practice-management vendor, legal counsel, cyber-insurance carrier and, where applicable, law enforcement.

How the engagement runs

How we build the plan with your practice

  1. Step 1

    Map the realistic scenarios

    We start from your actual systems and staffing, a solo clinician on one platform looks nothing like a thirty-clinician virtual group, and identify which incidents are plausible.

  2. Step 2

    Draft the playbooks and roles

    Each scenario gets a specific sequence of actions and a named owner, including the extortion scenario most generic templates skip entirely.

  3. Step 3

    Build notification materials in advance

    Client letters, IPC notification drafts and vendor-contact scripts are prepared before they are needed, so nothing is written for the first time under pressure.

  4. Step 4

    Walk through the plan with your team

    A tabletop exercise tests whether the plan actually works with your real staff and systems, and surfaces gaps while the stakes are still theoretical.

What it costs

What affects incident response planning cost for a practice

Pricing depends mainly on how many systems and locations need scenario coverage, whether the practice operates across provinces with different notification regimes, and how much of the underlying documentation, an asset inventory, a vendor list, already exists. A solo practitioner on a single platform needs a leaner plan than a multi-site group running its own video infrastructure.

For practices that want this handled on an ongoing basis rather than as a one-time document, incident planning is folded into the Virtual Privacy Officer retainer. Tell us your setup and we will scope the work.

Mental Health & Counselling Practices: Incident response questions, answered

Legally, the notification obligation to your clients stays with you as the custodian, even when the breach originates at the vendor. Your plan should specify that you will confirm scope with the vendor first, then issue notice yourselves rather than waiting for or relying solely on the vendor's own communication, since their notice may not satisfy your specific PHIPA obligations or reach clients in the way your practice needs to.

The immediate steps are to confirm whether the device was encrypted and whether notes were stored locally versus only accessed through the cloud platform, report the theft, and assess based on those facts whether notification is triggered, which under PHIPA's low threshold it usually will be. A good plan has this sequence, and the encryption-status question specifically, written down in advance so it does not get skipped in the first frantic hour.

This needs its own playbook, separate from a standard breach notice. It typically includes urgent, direct outreach to affected clients before they receive the extortion contact if timing allows, clear guidance not to pay or engage with the extortionist, coordination with law enforcement, and, given the clinical stakes, involvement of a colleague or supervisor to support clients through what is itself a significant harm. Generic incident templates rarely address this, which is exactly why this niche needs its own.

A written plan matters even more for a solo practitioner, because there is no colleague to catch a missed step under pressure. The plan does not need to be long, but it should specify the notification threshold, who gets called first, and where client contact information is stored if the primary system is the thing that is compromised.

Review it whenever the practice changes platforms, adds a clinician, expands telepractice into a new province, or adopts a new tool like an AI scribe, and otherwise at least annually. A plan built around last year's systems and staff will not hold up when it is actually needed, and stale contact information is one of the most common reasons a real response starts slower than it should.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.