Incident Response Plan
Version 1.1 — Last updated: 15 July 2026
1. Purpose and scope
Where CareLedgerPro becomes aware of a personal data breach affecting a Controller's data, CareLedgerPro will notify the Controller without undue delay. The Controller remains responsible for assessing the breach, notifying the ICO within 72 hours where required, and communicating with affected individuals.
This plan sets out how CareLedgerPro responds to security incidents and personal data breaches affecting the Service or its Controllers.
It is designed to support:
- UK GDPR Articles 33 and 34
- the Data Protection Act 2018
- the Controller's CQC financial-safeguarding evidence work
This plan applies to all CareLedgerPro systems, environments, staff, and sub-processors.
2. Definitions
- Security incident — any event that compromises the confidentiality, integrity, or availability of the Service.
- Personal data breach — accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- Reportable breach — a personal data breach likely to result in a risk to individuals’ rights and freedoms, requiring notification to the ICO.
3. Roles
- Incident Lead — coordinates the response, communications, timeline management, and closure.
- Data Protection Officer (Natasha Dhliwayo) — assesses reportability and liaises with the ICO and Controllers.
- Engineering On-Call — handles technical containment, remediation, and recovery.
- Customer Communications — manages notifications to Controllers and affected individuals.
4. Severity levels and response times
- SEV-1 — major outage or confirmed personal data breach
- Acknowledged within 30 minutes, with 24/7 active response until resolved
- SEV-2 — degraded service or suspected breach
- Acknowledged within 2 hours, with response during working hours until resolved
- SEV-3 — minor issue with no data impact
- Acknowledged by the next working day
5. Incident lifecycle
Detect and log
The on-call engineer records the incident with the detection timestamp, source, initial severity, and a summary of what occurred.
For personal data breaches, the ICO’s 72-hour clock begins at detection.
Triage
The team assesses the scope and affected systems, categories and volume of data, likelihood of harm, severity level, and assignment of the Incident Lead.
Contain
Immediate steps are taken to prevent further impact, including revoking access, rotating credentials, isolating affected systems, blocking malicious traffic, and recovering misdirected data.
All containment actions are logged.
Eradicate and recover
The root cause is removed, affected components are patched or reconfigured, service is restored safely, and the integrity of financial and audit records is verified before writes are reopened.
Notify
For reportable personal data breaches, the DPO notifies affected Controllers without undue delay.
Controllers use this information to meet the ICO 72-hour deadline. Where high risk exists, CareLedgerPro assists Controllers in notifying affected individuals.
Close and review
Within 10 working days, a blameless post-incident review is completed, including root-cause analysis, lessons learned, and updates to controls, policies, or infrastructure.
6. Reporting an incident
Anyone may report a suspected incident by emailing Natasha@litaniahealthcareps.com.
Controllers with confirmed incidents affecting their data may also report via the in-app Breach Register.
7. Records and evidence
Each incident maintains a complete timeline covering detection, containment, triage, ICO notification, affected-individual notification, and closure.
All timelines and evidence are exportable as CSV for ICO, CQC, or Controller audits.
8. Plan review
This plan is reviewed at least annually and after every SEV-1 incident.
Updates are documented and published.
Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.