Effective Date: August 18, 2026
My Whole Picture Health, LLC, (MWPH) will respond promptly to any suspected loss, unauthorized access, disclosure, alteration, or acquisition of client information.
This procedure applies to electronic and physical client information, including medical records, completed or draft Medical Snapshots, contact information, account information, and other identifiable information provided by a client.
A potential privacy or security incident includes, but is not limited to:
A client document sent to the wrong person
A lost or stolen computer, phone, storage device, or paper record containing client information
Unauthorized access to an email, cloud-storage, payment, or business account
Malware, ransomware, phishing, or other suspected compromise
A shared link or file accidentally made accessible to an unauthorized person
Client information entered into or disclosed to an unauthorized third-party service
Paper records lost, stolen, or viewed by an unauthorized person
Any other situation in which client information may have been accessed, acquired, used, or disclosed without authorization
As soon as an incident is discovered:
Stop the disclosure or unauthorized access if possible.
Disable or revoke affected sharing links.
Remove public access to affected files.
Change compromised passwords and revoke active sessions.
Enable or verify multi-factor authentication.
Lock, remotely secure, or wipe a lost device when available.
Disconnect an infected device from networks if malware is suspected.
Contact the relevant service provider if account or platform assistance is required.
Do not delete logs, emails, files, or other evidence related to the incident.
Containment should occur immediately, even if the full scope of the incident is not yet known.
Create an incident record documenting:
Date and time the incident occurred, if known
Date and time the incident was discovered
How the incident was discovered
Systems, devices, accounts, or files involved
Individuals whose information may be affected
Types of information potentially involved
Whether the information was encrypted
Who may have received or accessed the information
Actions taken to contain the incident
Any communications with vendors, clients, law enforcement, insurers, attorneys, or regulators
Preserve relevant evidence and continue updating the incident record as new information becomes available.
Determine, as accurately as reasonably possible:
What information was involved
Whether the information could identify an individual
How many individuals may be affected
Whether the information was actually accessed or acquired, or merely exposed
Whether an unauthorized recipient opened, downloaded, copied, forwarded, or retained the information
Whether affected information was encrypted or otherwise secured
Whether access is ongoing
Whether other systems or client records may also be affected
Do not assume that an incident is harmless simply because it appears accidental.
For any incident involving actual or reasonably possible unauthorized access to identifiable client health information, MWPH will promptly determine whether professional guidance is necessary.
Depending on the circumstances, this may include contacting:
Legal counsel
Cybersecurity or forensic professionals
Cyber/data-breach insurance carrier
Relevant technology or storage provider
Law enforcement when theft, fraud, extortion, or other criminal activity is suspected
The applicable federal and state notification requirements will be evaluated before determining that no notification is required.
MWPH will determine whether notification is required under applicable federal or state law, including where applicable:
The FTC Health Breach Notification Rule
Wyoming data-breach notification law
Breach-notification laws of other states in which affected clients reside
Contractual or insurance requirements
Required notification deadlines will be calculated from the appropriate discovery date.
If notification is legally required, it will be made without unreasonable delay and within all applicable deadlines.
Any client notification will be clear, factual, and written in plain language.
When appropriate or legally required, the notice will explain:
What happened
When the incident occurred, if known
When it was discovered
What types of information were involved
What MWPH has done to contain and investigate the incident
What steps are being taken to prevent recurrence
Reasonable actions the client can take to protect themselves
How the client can contact MWPH with questions
The notice will not speculate about facts that have not yet been established or minimize a known risk.
If applicable law requires notification to a government agency, regulator, media organization, or other entity, MWPH will complete that notification within the required timeframe and retain documentation showing when and how it was submitted.
After immediate response and notification requirements have been addressed, MWPH will identify and correct the cause of the incident.
Corrective actions may include:
Changing passwords or credentials
Reconfiguring access permissions
Replacing insecure sharing methods
Updating software or devices
Changing storage or communication providers
Revising internal procedures
Restricting unnecessary access to client information
Improving encryption, authentication, backup, or device security
Updating client or vendor agreements
The incident will not be considered closed until:
Unauthorized access has been stopped
The scope has been reasonably determined
Required notifications have been completed
Corrective measures have been implemented or documented
Relevant records have been retained
The final incident record should include the investigation, decisions made, reasoning for those decisions, notifications completed, corrective actions taken, and any professional advice received.
When in doubt, preserve the evidence, contain the exposure, document what happened, and determine the legal notification requirements before deciding that an incident requires no further action.