Totus Life ServicesTelePort

Breach Notification Procedure

How we detect, assess, and report privacy breaches involving personal health information

Last updated: July 2026

This Breach Notification Procedure outlines the step-by-step process TelePort follows when a privacy breach occurs involving personal health information. It is designed to comply with PIPEDA, BC PIPA, Ontario PHIPA, Alberta PIPA, Quebec Law 25, and all provincial health information statutes across Canada. While BC PIPA does not currently require mandatory breach notification for private-sector organizations, we follow voluntary notification best practices and are prepared for anticipated legislative amendments.

Breach Notification Requirements by Province

ProvinceNotification RequirementRegulator
Federal (PIPEDA)Mandatory — report as soon as feasibleOffice of the Privacy Commissioner of Canada
British Columbia (PIPA)Voluntary (recommended) — mandatory notification pending legislative amendmentOIPC BC
Ontario (PHIPA)Mandatory — at first reasonable opportunityIPC Ontario
Alberta (PIPA/HIA)Mandatory — without unreasonable delayOIPC Alberta
Quebec (Law 25)Mandatory — promptlyCAI Quebec
Manitoba (PHIA)Mandatory — as soon as practicableManitoba Ombudsman
Nova Scotia (PHIA)Mandatory — as soon as practicableNS OIPC
New Brunswick (PHIPAA)Mandatory — as soon as practicableNB OIPC
Saskatchewan (HIPA)Mandatory — as soon as reasonably possibleSK OIPC
Newfoundland (PHIA)Mandatory — as soon as practicableNL OIPC

Step 1: Detection & Initial Assessment

When a potential privacy breach is detected — whether by our automated monitoring systems, a staff member, a healthcare provider, or a patient — it must be reported immediately to the Privacy Officer at privacy@totus.ca. Our monitoring systems include:

- Automated intrusion detection and alerting on all infrastructure

- Audit log analysis for unusual access patterns

- Endpoint monitoring for unauthorized access attempts

- User-reported incidents via the platform or direct contact

The initial assessment determines whether personal health information (PHI) was involved and the potential scope of the breach. This initial triage must be completed within 2 hours of detection.

Step 2: Containment

Immediate steps are taken to contain the breach and prevent further unauthorized access:

1. Isolate affected systems from the network if necessary

2. Revoke compromised credentials or access tokens

3. Temporarily disable affected user accounts

4. Block suspicious IP addresses at the firewall level

5. Preserve logs and evidence for forensic investigation

6. Take affected services offline if the breach is active and ongoing

Containment actions are documented with timestamps for the incident record.

Step 3: Investigation & Risk Assessment

The Privacy Officer leads a thorough investigation to determine:

- What personal information was accessed, used, or disclosed

- When the breach occurred and how long it lasted

- Who was responsible (internal or external actor)

- How the breach happened (vulnerability exploited, human error, etc.)

- Whether encryption or other safeguards were in place

- How many individuals are affected

Each breach is assessed against the Real Risk of Significant Harm (RROSH) test, as required by PIPEDA and provincial privacy laws. The RROSH test considers:

- The sensitivity of the information involved

- The nature and extent of the breach

- Whether the information was encrypted or otherwise protected

- Who accessed the information

- The likelihood that the information could be misused

Step 4: Notification (as required by law)

If the RROSH test determines there is a real risk of significant harm, we provide notification as follows:

To the Privacy Commissioner:

- Under PIPEDA (Federal): Report to the Office of the Privacy Commissioner of Canada as soon as feasible

- Under Ontario PHIPA: Report to the Information and Privacy Commissioner of Ontario at the first reasonable opportunity

- Under Alberta PIPA: Report to the Office of the Information and Privacy Commissioner of Alberta without unreasonable delay

- Under Quebec Law 25: Report to the Commission d'accès à l'information du Québec promptly

- BC PIPA (Voluntary): While BC PIPA does not currently mandate breach notification for private sector organizations, we voluntarily notify the BC OIPC of breaches involving significant harm, in accordance with best practices and pending legislative amendments

- All other provinces: We follow PIPEDA standards, reporting as soon as feasible

To Affected Individuals:

- Notify directly by the most appropriate channel (email, phone, or in-person)

- Provide sufficient information for individuals to understand the breach and take steps to protect themselves

- Include a description of the incident, the type of information involved, what we have done to contain it, and steps the individual should take

- Contact information for the Privacy Officer for follow-up questions

To Other Organizations:

- Notify law enforcement if criminal activity is suspected

- Notify regulatory colleges if a healthcare provider is involved

- Notify other organizations that can help mitigate the risk

Notification occurs as soon as feasible — within 72 hours for PIPEDA-reportable breaches, and at the first reasonable opportunity for PHIPA-reportable breaches.

Step 5: Remediation & Prevention

After the immediate response is complete, we take steps to prevent recurrence:

- Identify and patch the root cause of the breach

- Update security controls and access policies

- Provide additional training to staff and providers

- Review and update the Incident Response Plan

- Conduct a post-incident review within 30 days

- Implement any recommendations from the review

- Update risk assessments and security documentation

Step 6: Documentation & Record-Keeping

All privacy breaches are documented in a permanent incident register. For each breach, we record:

- Date and time of detection

- Date and time of containment

- Nature and scope of the breach

- Personal information involved

- Number of affected individuals

- Results of the RROSH assessment

- Notifications sent (to whom and when)

- Remediation actions taken

- Post-incident review findings

This register is maintained for the duration required by applicable law and is available for inspection by privacy commissioners upon request.

Reporting a Breach

If you believe a privacy breach has occurred involving TelePort, please report it immediately:

Privacy Officer: privacy@totus.ca

Security Team: security@totus.ca

Emergency: support@totus.ca (24/7 monitoring)

Please include as much detail as possible: what happened, when it happened, what information was involved, and how you became aware of it.