A Data Breach at Your Practice - You Have 72 Hours

A lost laptop, an email sent to the wrong patient, a ransomware attack - when it counts as a data breach, when you must report it to UODO within 72 hours, and when a register entry is enough.
Krzysztof is riding the subway home from work. He gets off at his stop, reaches into his bag for his phone -- and can't find it. He left it on the seat. The mail app on it is logged in without a password, and the inbox holds a dozen emails with test results and treatment plans sent to patients over the past week. Krzysztof stands on the platform for a moment, trying to process what just happened. Is this a "personal data breach"? Does he have to do something about it today? Or can he just block the SIM card and forget about it?
Most practice owners only ask themselves this question once it's already too late to calmly read up on the rules. The GDPR leaves little room here -- from the moment the practice becomes aware of the breach, the clock starts running. It has 72 hours to assess the risk and, if necessary, report the incident to the Personal Data Protection Office (UODO). In this article we explain what actually counts as a breach, how to assess whether reporting it is mandatory, and what happens if you fail to do so.
What is a personal data breach -- a broad definition
Many practice owners picture a data breach only as something spectacular -- a hacker attack or a database published online. In reality, the GDPR definition is much broader: it covers any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In the everyday life of a physiotherapy practice, that's a surprisingly wide range of situations.
Breaches that are easy to underestimate
- A lost or stolen laptop or phone with access to the EDM system, work email, or the patient calendar -- regardless of whether the device was encrypted.
- An email with test results or a treatment plan sent to the wrong recipient -- the classic mistake of an autocompleted address in your inbox.
- A hack or ransomware attack on the EDM system -- encrypting the patient database with malware is a breach even if the data wasn't stolen, only locked away.
- Theft of a binder with paper medical records -- e.g. from the practice, a car, or during transport between locations.
- Accidental deletion of data without a backup -- loss of availability of data is also a breach under the GDPR, even if no third party ever gained access to it.
The common thread in all of these situations is loss of control over personal data -- whether it concerns confidentiality (someone unauthorized sees the data), integrity (the data was altered), or availability (the data is gone for good). We cover the basics of keeping and securing medical records more broadly in the article GDPR at a physiotherapy practice.
The three-step risk assessment -- what you need to establish
As soon as you learn about an incident, you need to work through three questions, in this order. The answer to each one determines what happens next.
Step 1: Is this actually a breach
Not every technical incident is a personal data breach. A server failure that didn't result in loss of, or unauthorised access to, data (e.g. because a backup was in place and the data was restored with no trace of third-party interference) doesn't qualify as a breach under the GDPR. So the first question is: has there been a breach of confidentiality, integrity, or availability of personal data. If not -- the matter ends there, though it's still worth logging internally.
Step 2: Do you need to report it to UODO
If it is a breach, the next question is: is there a risk to the rights or freedoms of natural persons. The obligation to report to UODO arises exactly when such a risk exists -- which in practice is nearly always the case whenever patients' health data (special category data under Article 9 GDPR) is involved. The only exception is when the breach is unlikely to result in a risk to the rights or freedoms of the affected individuals -- a rare scenario when it comes to medical records.
Step 3: Do you need to notify the patients themselves
The third question no longer concerns UODO but the data subjects themselves. The obligation to directly notify patients arises only when the risk is high -- a higher threshold than the "ordinary" risk that justifies reporting to UODO. An example would be a leak of health data combined with data that allows identification, where there's a real probability the data will end up in the wrong hands (e.g. published online, sold as a database). Where the risk is high, the controller must inform patients without undue delay, in clear and plain language, about what happened and what steps they should take.
| Assessment step | Question | Consequence if YES |
|---|---|---|
| 1. Is it a breach | Has confidentiality/integrity/availability of data been breached | Move to step 2 |
| 2. Report to UODO | Is there a risk to rights or freedoms of individuals | Report to UODO within 72h |
| 3. Notify patients | Is the risk HIGH | Direct notification of patients without undue delay |
When a log entry in the internal register is enough
Not every breach requires reporting to UODO. If the risk assessment shows the incident was minor, quickly fixed, and doesn't pose a real threat to patients' rights, it's enough to record it in an internal breach register -- without informing the authority. A typical example is a situation where an employee accidentally opened another patient's record in the EDM system, noticed immediately, closed the view, and neither copied nor saved any data. In such a case the risk to the rights and freedoms of the data subject is negligible -- but the incident itself still needs to be documented.
How to count the 72 hours -- the most common mistake
This is one of the areas where practices make the most mistakes. The 72-hour deadline runs from the moment the breach is discovered, not from the moment it actually occurred. If a laptop went missing on Friday evening but the practice only found out about it on Monday morning (because nobody checked the equipment over the weekend), the clock starts ticking on Monday -- not on Friday.
The second trap: the deadline is counted in hours, not business days. A weekend, a public holiday, or the practice owner's vacation doesn't pause the clock. If a breach is discovered on Saturday afternoon, the 72-hour deadline expires on Tuesday afternoon -- regardless of the fact that the practice is closed on Sunday. That's why it's worth deciding in advance who at the practice is responsible for monitoring such situations and who has access to the reporting procedure even outside normal working hours.
What happens if you conceal a breach
The consequences of failing to report a breach that should have been reported are severe on two levels. Formally, under Article 83(4) GDPR, the controller faces an administrative fine of up to EUR 10 million or up to 2% of its total worldwide annual turnover -- whichever is higher. For a small physiotherapy practice, an amount calculated from turnover may sound abstract, but the mere fact that UODO opens proceedings and imposes an administrative fine at all carries real cost and time.
The second level of consequences is often more painful in practice than the fine itself: loss of patient trust. A physiotherapy practice runs on relationships and recommendations -- news that a facility concealed a leak of health data can effectively destroy a reputation built over years. On top of that comes the risk of individual damages claims from patients whose data was affected and who found out about the incident late, or from a third party rather than from the practice itself.
Real-life practice scenarios -- report or not
The examples below show how differently seemingly similar situations can be assessed.
Scenario 1: a lost phone with email access. A phone with no screen lock, logged into a mailbox containing emails with patients' test results, is lost in a public place. The risk of unauthorized access to health data is real -- this is a breach requiring notification to UODO, and with a larger number of affected patients, likely also direct notification of the patients themselves.
Scenario 2: an encrypted laptop with an up-to-date backup. A laptop with full disk encryption and an enforced strong password is stolen from a car, but patients' data is simultaneously available from a current backup, and the encryption practically prevents an unauthorized person from reading the data. This is still formally a breach (loss of control over a data-carrying device), but the risk analysis may show that the probability of a risk to patients' rights is low -- the decision and its justification still need to be documented in the register.
Scenario 3: a test result email sent to the wrong patient. An employee made a mistake entering an address, and a test result reached a person with a similar surname. This is a confidentiality breach of special category data concerning a specific, identifiable person -- in practice it almost always requires notification to UODO, and often notifying both affected patients as well.
[SP] Example -- Solo practice: Ewa, who runs a one-person practice, notices in the morning that her phone with access to her mailbox went missing the previous evening. She immediately blocks the SIM card and changes her email password, but knows this doesn't end the matter -- within 72 hours of discovering the incident, she must assess the risk and, if it's real, report the breach to UODO, following a ready-made step-by-step procedure.
[GR] Example -- Group practice: At a practice employing several physiotherapists, the system administrator notices unusual login activity to the EDM system in the middle of the night. The team immediately cuts off access, resets passwords, and launches its internal incident response procedure, while counting the deadline from the moment of detection -- not from the presumed moment of the intrusion, which can't be pinpointed exactly.
Why keep a breach register even when you report nothing
Many practice owners assume that if a given incident didn't require reporting to UODO, there's no need to record it anywhere. That's a mistaken assumption. Article 33(5) GDPR explicitly requires the controller to document all personal data breaches -- including those that weren't subject to the reporting obligation -- along with the facts relating to the breach, its effects, and the remedial action taken.
This register serves a specific practical purpose: it allows UODO to verify compliance with the regulation during a potential inspection. A practice that can show a complete, consistently maintained register -- even with entries like "incident with no risk, not reported" -- positions itself as an entity that manages data security consciously. A practice without such a register, even if it never suffered a serious leak, can still be sanctioned purely for lacking the documentation.
Frequently asked questions
From when does the 72-hour deadline for reporting a breach to UODO run?
The deadline runs from the moment the controller (the practice owner) became aware of the breach, not from the moment it actually occurred. It's counted in full hours, not business days, so weekends and days off don't pause it. If missing equipment is discovered several days after the fact, the clock only starts running from the moment of discovery.
Does every data breach have to be reported to UODO?
No. Reporting is mandatory only when there's a risk to the rights or freedoms of the data subjects. If the risk assessment shows the incident is unlikely to cause such a risk -- e.g. it was minor and quickly fixed, with no actual third-party access -- it's enough to record it in the internal breach register, without notifying the authority.
Do you have to inform patients about every breach reported to UODO?
Not always. The obligation to directly notify the data subjects only arises when the breach is likely to result in a high risk to their rights or freedoms -- a higher threshold than the one that justifies reporting to UODO alone. So some breaches get reported to the authority without patients being informed directly, if the risk doesn't reach the high level.
Is there a penalty if a breach is reported after the deadline?
Yes, missing the 72-hour deadline can in itself be treated as a violation of GDPR obligations and result in an administrative fine under Article 83(4) GDPR, regardless of how serious the underlying data breach was. That's why it's crucial to have a ready-made procedure that lets you act quickly from the very first hour, rather than only once all the details of the case have been established.
CTA: Don't want to be counting hours under pressure, wondering exactly what to write in your report to UODO? The PREMIUM package includes a ready-made data breach procedure -- step by step, together with a breach register template for ongoing documentation of incidents, including those that don't require reporting. See FizjoReady packages →
Related articles:
- GDPR at a physiotherapy practice -- a complete guide
- GDPR privacy notice at a physiotherapy practice
- Practice website and GDPR