Security & Compliance

Security Incidents & Audit Logs

The Security Incident Register (?page=security-incidents) is a formal breach/incident logging tool built around India's DPDPA 2023 Section 8, which requires reporting a personal data breach within 72 hours of detection.

Step-by-step: logging an incident

  1. Go to Security Incidents.
  2. Choose Create Incident.
  3. Record the incident type, severity, a description, affected patients, data types involved, and the detected-at timestamp.
  4. The incident is logged with status "open" and the reporting staff member recorded.
  5. Track and update status as the incident is investigated/resolved.

Why the 72-hour window matters

DPDPA's breach notification requirement is time-sensitive; logging the incident promptly here (with an accurate detected-at time) supports timely compliance regardless of when the investigation concludes.

Common issues & fixes

when in doubt, log it; the register is designed to capture anything potentially relevant, and status/severity can be adjusted as more is known.
you can create the incident with partial information and update it as the investigation clarifies scope.

Was this article helpful?

Thanks for the feedback!
ESC
navigate open esc close