CORREIA CRESPO ADVOGADOS

Data breach in a clinic: what to do in the first 72 hours

An email sent to the wrong recipient, unauthorised access to clinical software, or the theft of a device holding patient records can amount to a personal data breach in a dental clinic operating in Portugal. The 72 hours in the title refer to the deadline for notifying the Portuguese data protection authority (CNPD) when that notification is actually due — not a deadline that applies to every single incident. In the first hours, the order of decisions matters as much as the decisions themselves.

This text describes, in general terms, a prudent sequence of action. It does not replace legal consultation or an internal plan tailored to the clinic. The framework for this practice area is set out in data protection (GDPR) for dental clinics.

What counts as a personal data breach

In general terms, a breach occurs when a security incident leads, accidentally or unlawfully, to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In a clinic, this can involve clinical records, radiographs, contact details, billing information or communications with patients.

Not every technical incident is automatically a breach that triggers a notification duty. The classification and its consequences depend on the facts, the type of data involved, the existing protective measures and the risk to data subjects.

First: contain and preserve

Before communicating externally, the priority is usually to contain the incident: revoking access, isolating affected systems, recovering credentials and stopping further exposure, wherever possible without destroying useful evidence.

At the same time, the timeline should be preserved: when the incident was detected, who became aware of it, which systems are involved and which categories of data may have been affected. Improvised, incomplete notes make later assessment and the demonstration of diligence more difficult.

Then: assess the risk

The assessment should consider the nature of the data (including health data), the approximate number of data subjects affected, the likelihood of misuse, the presence of encryption or other measures, and the potential impact on rights and freedoms.

This assessment underpins two separate decisions: whether there is a duty to notify the supervisory authority, and whether there is a duty to inform the data subjects. These are legal and factual judgments; they should not rest solely on the urgency of the moment.

The 72-hour deadline — what it means in practice

The GDPR provides, in certain cases, for notification to the supervisory authority without undue delay and, where applicable, within 72 hours of the controller becoming aware of the breach. If notification is not made within that period, the reasons for the delay must be given, as provided under the applicable rules.

"Becoming aware" is not the same as already having every answer. In practice, the clinic must act diligently to confirm the incident and gather essential information, without artificially delaying the start of the clock. Where notification is due, it can be updated as new elements become known.

Not every incident triggers a notification duty. If it is unlikely that the breach will result in a risk to the rights and freedoms of individuals, notifying the authority may not be required — but that conclusion should still be documented.

Communicating with patients and suppliers

Communicating with data subjects may be necessary when there is a high risk to their rights and freedoms. The content and timing of that communication should be carefully considered: clear information about the nature of the breach, useful contact details and, where possible, recommendations to mitigate adverse effects.

If the incident involves a processor (for example, the clinical software supplier), the clinic should coordinate with that supplier under the contract and the obligations set out in the GDPR, while retaining control over the timeline and the decisions that fall to the controller.

Documenting and preventing recurrence

Even when there is no notification, the internal record of the incident — facts, assessment, decision and measures — is a central element of accountability. After containment, it is important to address root causes: access controls, training, contracts, backups or the channels used to send clinical information.

Many of the mistakes that precede incidents are described in the most common GDPR mistakes in a dental clinic. The distinction between legal support and the Data Protection Officer role is set out in does your dental clinic need a Data Protection Officer?.

Frequently asked questions

To learn more about the practice area of legal consultancy and GDPR audit for dental clinics, see the dedicated page or the firm's contact details.

Related reading