Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Incident response · Clinical care providers

Incident Response Planning for Pharmacies

An incident response plan tells your pharmacy exactly how to keep serving patients when the dispensary system is encrypted, claims cannot adjudicate, or a laptop with medication data goes missing. Pharmacies need a version built around continuity, not just notification, because a serious incident interrupts the ability to fill a prescription, not only the records describing it.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What a pharmacy's plan has to cover

A generic breach template assumes information is exposed after the fact. A pharmacy plan assumes patients are standing at the counter while the incident is still happening.

Continuity of dispensing

Steps for verifying and filling urgent prescriptions by phone or paper backup when the PMS is unavailable, so patients are not turned away mid-incident.

Claims and payer communication

A defined path for reaching ODB and private-plan contacts when real-time adjudication fails, so patients are not asked to pay out of pocket without a plan to reconcile later.

Narcotics reconciliation during recovery

A procedure for tracking controlled-substance counts manually while systems are down and reconciling them once the Narcotics Monitoring System connection is restored.

Dual notification tracks

Clear triggers for when an incident needs to go to the IPC, when it needs to go to the College, and when both apply at once, so nobody guesses under pressure.

Regulatory map

The notification stack a pharmacy plan encodes in advance

Which duties fire depends on what happened and where the store operates, so the plan maps each obligation to its trigger rather than leaving that research for the middle of an incident.

IPC reporting under O. Reg. 329/04

Ontario custodians report qualifying breaches to the IPC and file annual statistics by March 1, deadlines the plan tracks so they are never discovered late.

Primary source →

College notification for discipline-adjacent events

Where an incident involves staff conduct, OCP guidance expects the employer to report the resulting discipline or resignation to the College alongside the IPC.

Primary source →

Alberta's HIA breach clock

A licensed Alberta pharmacy reports to the Commissioner, the Minister and affected individuals where a real risk of harm exists, on a timeline distinct from Ontario's.

Primary source →

Quebec's incident register and CAI notice

A Quebec pharmacy keeps an incident register and notifies the CAI where there is a risk of serious injury, obligations the plan folds into a national response for multi-province banners.

Primary source →

What goes wrong

The scenarios this plan rehearses

We build the playbook around what has actually hit Canadian pharmacies, not generic ransomware theatre.

  • Chain-wide ransomware

    London Drugs' April 2024 attack closed stores across four provinces, with pharmacists filling urgent needs by phone while the company refused the attacker's demand and worked through recovery.

    Source →

  • An upstream claims-switch failure

    The Change Healthcare disruption showed how an upstream claims processor going down can stop dispensing at pharmacies that were never themselves breached, a scenario the plan scripts a response for.

  • A staff lookup that surfaces mid-shift

    An unauthorized lookup discovered during a shift needs immediate containment and a decision path toward the dual College and IPC reporting that OCP guidance requires.

  • A lost device holding medication data

    A missing laptop or tablet used for deliveries or clinical services forks the response depending on encryption status, a branch the plan scripts in advance.

Our incident response for pharmacies

What the incident response planning engagement delivers

This produces documents your team can run under pressure, built around your store's actual systems rather than adapted from a generic corporate template.

Photograph: Hospital Room
  1. The core response plan

    Roles, escalation and decision authority for the Designated Manager, owner, MSP and PMS vendor, formatted for use during a live outage rather than after.

  2. A dispense-through-downtime runbook

    Step-by-step guidance for verifying and filling urgent prescriptions, communicating with patients, and documenting what was dispensed manually for later reconciliation.

  3. A notification matrix

    Every reporting duty, from the College and the IPC through provincial regulators to insurers and ODB contacts, mapped with its trigger, deadline and owner.

  4. Vendor and PMS coordination steps

    Contact paths and contractual notice expectations for your PMS vendor, wholesaler and any central-fill or delivery partner involved in the response.

  5. A tabletop walkthrough

    A working session that runs your Designated Manager and store staff through a ransomware or lost-device scenario to expose gaps before a real incident does.

How the engagement runs

Building the plan with your store

  1. Step 1

    Map your systems and obligations

    We inventory your PMS, POS, claims connections and any robotics or delivery integrations against the specific regulators and payers that would be involved.

  2. Step 2

    Draft with the people who will use it

    The plan is written with the Designated Manager, owner and MSP so the steps match how the store actually operates during and after hours.

  3. Step 3

    Test it against a scenario

    A tabletop exercise runs the team through a realistic incident, such as a PMS outage during a busy afternoon, and surfaces gaps in contacts or authority.

  4. Step 4

    Keep it current

    Annual reviews, plus updates whenever a new system, vendor or store is added, keep the plan matched to how the pharmacy actually runs.

What it costs

Pricing an incident response plan for a pharmacy

Effort depends on how many provinces the store or banner operates in, how many systems and vendors are in scope, whether narcotics reconciliation and central-fill arrangements need dedicated runbooks, and whether the tabletop walkthrough is included. A single independent store is a compact project; a banner spanning Ontario, Alberta and BC carries three regulators' worth of mapping.

Stores on a Virtual Privacy Office retainer often already receive incident management support as part of that service, so ask which route fits before commissioning a standalone plan. A short scoping call is enough to price the work.

Pharmacies: Incident response questions, answered

The plan's first branch is continuity, not notification: verify the prescription by phone with the prescriber or a backup record if available, document what was dispensed manually, and flag it for reconciliation once systems are restored. Containment of the affected systems happens in parallel, and formal notification decisions follow once the immediate patient-care need is addressed, exactly the sequence London Drugs pharmacists worked through during their 2024 incident.

The plan names a specific role, usually the Designated Manager or owner, responsible for contacting Ontario Drug Benefit and private-plan representatives when real-time adjudication is unavailable, along with a script for what patients are told about paying and being reimbursed later. The insurer is notified in parallel, since business-interruption and cybercrime coverage decisions typically depend on how quickly the incident was reported.

College notification is triggered specifically by staff conduct concerns, such as an unauthorized lookup or disclosure, rather than by every technical incident. Where discipline or a resignation results from that conduct, OCP guidance requires the employer to report to the College and the IPC together. A ransomware attack with no conduct issue typically stays an IPC and, where applicable, other provincial-regulator matter without a College report.

Yes, and it should. Your pharmacy remains accountable to patients and regulators even when the failure originates at a claims switch, PMS host or delivery-app provider you do not control. The plan includes contact paths for key vendors, what evidence to request from them, and how to communicate with patients while a third party controls the underlying facts of the outage.

The runbook includes a manual reconciliation procedure: paper or backup logging of controlled-substance dispensing while the PMS or Narcotics Monitoring System connection is unavailable, followed by a defined reconciliation step once connectivity returns. This keeps the store's narcotics records defensible even through an extended outage, rather than leaving a gap regulators would later question.

The core structure is similar, but a banner plan adds a notification matrix spanning every province it operates in, plus coordination steps for a chain-wide event affecting many stores at once. A single independent's plan is more compact but no less serious, since a one-location pharmacy has just as much continuity and reporting risk concentrated in a single site.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.