Documentation

Last reviewed: May 2026

Incident Management & Breach Notification

This page explains how we detect, respond to and learn from security incidents, and how quickly we tell you if your data is affected. It is the public summary of our internal incident-management framework.

In short

We operate a defined incident framework aligned with UK GDPR and NHS expectations. Any confirmed personal data breach is reported to your organisation within 24 hours, and every incident is followed by root-cause analysis and corrective action.

1. How incidents are handled

  • Identified and logged promptly — incidents are recorded and assessed as soon as they are detected.
  • Triaged to service levels — critical incidents are triaged within documented timeframes.
  • Contained quickly — containment actions begin as soon as reasonably practicable after identification.
  • Investigated and fixed — every incident is subject to investigation, root-cause analysis, and corrective and preventative actions.

2. Breach notification

If a confirmed personal data breach affects your organisation's data, we notify you (the Controller) within 24 hours. This is set out in our contractual obligations under the Data Processing Agreement, and is ahead of the statutory authority timelines it supports.

  • Who we tell — your organisation, as the data Controller, so you can meet your own regulatory obligations.
  • What we provide — the nature of the incident, the data affected, and the steps being taken to contain and remediate it.

3. Supported by audit and monitoring

Incident handling is underpinned by our security monitoring and audit logging. Security-relevant events raise real-time alerts, and our tamper-evident audit trail supports thorough investigation — see Audit Logging & Integrity.

The bottom line

A defined, UK GDPR- and NHS-aligned incident framework: prompt detection and containment, confirmed breaches reported to your organisation within 24 hours, and root-cause analysis with corrective action on every incident.