TelePortHow we detect, assess, and report privacy breaches involving personal health information
Last updated: July 2026
This Breach Notification Procedure outlines the step-by-step process TelePort follows when a privacy breach occurs involving personal health information. It is designed to comply with PIPEDA, BC PIPA, Ontario PHIPA, Alberta PIPA, Quebec Law 25, and all provincial health information statutes across Canada. While BC PIPA does not currently require mandatory breach notification for private-sector organizations, we follow voluntary notification best practices and are prepared for anticipated legislative amendments.
| Province | Notification Requirement | Regulator |
|---|---|---|
| Federal (PIPEDA) | Mandatory — report as soon as feasible | Office of the Privacy Commissioner of Canada |
| British Columbia (PIPA) | Voluntary (recommended) — mandatory notification pending legislative amendment | OIPC BC |
| Ontario (PHIPA) | Mandatory — at first reasonable opportunity | IPC Ontario |
| Alberta (PIPA/HIA) | Mandatory — without unreasonable delay | OIPC Alberta |
| Quebec (Law 25) | Mandatory — promptly | CAI Quebec |
| Manitoba (PHIA) | Mandatory — as soon as practicable | Manitoba Ombudsman |
| Nova Scotia (PHIA) | Mandatory — as soon as practicable | NS OIPC |
| New Brunswick (PHIPAA) | Mandatory — as soon as practicable | NB OIPC |
| Saskatchewan (HIPA) | Mandatory — as soon as reasonably possible | SK OIPC |
| Newfoundland (PHIA) | Mandatory — as soon as practicable | NL OIPC |
When a potential privacy breach is detected — whether by our automated monitoring systems, a staff member, a healthcare provider, or a patient — it must be reported immediately to the Privacy Officer at privacy@totus.ca. Our monitoring systems include:
- Automated intrusion detection and alerting on all infrastructure
- Audit log analysis for unusual access patterns
- Endpoint monitoring for unauthorized access attempts
- User-reported incidents via the platform or direct contact
The initial assessment determines whether personal health information (PHI) was involved and the potential scope of the breach. This initial triage must be completed within 2 hours of detection.
Immediate steps are taken to contain the breach and prevent further unauthorized access:
1. Isolate affected systems from the network if necessary
2. Revoke compromised credentials or access tokens
3. Temporarily disable affected user accounts
4. Block suspicious IP addresses at the firewall level
5. Preserve logs and evidence for forensic investigation
6. Take affected services offline if the breach is active and ongoing
Containment actions are documented with timestamps for the incident record.
The Privacy Officer leads a thorough investigation to determine:
- What personal information was accessed, used, or disclosed
- When the breach occurred and how long it lasted
- Who was responsible (internal or external actor)
- How the breach happened (vulnerability exploited, human error, etc.)
- Whether encryption or other safeguards were in place
- How many individuals are affected
Each breach is assessed against the Real Risk of Significant Harm (RROSH) test, as required by PIPEDA and provincial privacy laws. The RROSH test considers:
- The sensitivity of the information involved
- The nature and extent of the breach
- Whether the information was encrypted or otherwise protected
- Who accessed the information
- The likelihood that the information could be misused
If the RROSH test determines there is a real risk of significant harm, we provide notification as follows:
To the Privacy Commissioner:
- Under PIPEDA (Federal): Report to the Office of the Privacy Commissioner of Canada as soon as feasible
- Under Ontario PHIPA: Report to the Information and Privacy Commissioner of Ontario at the first reasonable opportunity
- Under Alberta PIPA: Report to the Office of the Information and Privacy Commissioner of Alberta without unreasonable delay
- Under Quebec Law 25: Report to the Commission d'accès à l'information du Québec promptly
- BC PIPA (Voluntary): While BC PIPA does not currently mandate breach notification for private sector organizations, we voluntarily notify the BC OIPC of breaches involving significant harm, in accordance with best practices and pending legislative amendments
- All other provinces: We follow PIPEDA standards, reporting as soon as feasible
To Affected Individuals:
- Notify directly by the most appropriate channel (email, phone, or in-person)
- Provide sufficient information for individuals to understand the breach and take steps to protect themselves
- Include a description of the incident, the type of information involved, what we have done to contain it, and steps the individual should take
- Contact information for the Privacy Officer for follow-up questions
To Other Organizations:
- Notify law enforcement if criminal activity is suspected
- Notify regulatory colleges if a healthcare provider is involved
- Notify other organizations that can help mitigate the risk
Notification occurs as soon as feasible — within 72 hours for PIPEDA-reportable breaches, and at the first reasonable opportunity for PHIPA-reportable breaches.
After the immediate response is complete, we take steps to prevent recurrence:
- Identify and patch the root cause of the breach
- Update security controls and access policies
- Provide additional training to staff and providers
- Review and update the Incident Response Plan
- Conduct a post-incident review within 30 days
- Implement any recommendations from the review
- Update risk assessments and security documentation
All privacy breaches are documented in a permanent incident register. For each breach, we record:
- Date and time of detection
- Date and time of containment
- Nature and scope of the breach
- Personal information involved
- Number of affected individuals
- Results of the RROSH assessment
- Notifications sent (to whom and when)
- Remediation actions taken
- Post-incident review findings
This register is maintained for the duration required by applicable law and is available for inspection by privacy commissioners upon request.
If you believe a privacy breach has occurred involving TelePort, please report it immediately:
Privacy Officer: privacy@totus.ca
Security Team: security@totus.ca
Emergency: support@totus.ca (24/7 monitoring)
Please include as much detail as possible: what happened, when it happened, what information was involved, and how you became aware of it.