Security Operations
Incident Response and Breach Notification Policy
Security incident triage, containment, investigation, customer notice, and breach escalation framework.
Last updated May 31, 2026
Status: Draft for legal and security review Document key: incidentResponsePolicy Version: 2026-05-31
This policy outlines how Happy Light Tech should respond to suspected security incidents, privacy incidents, and potential breaches involving Happy Light AI.
1. Goals
- Protect clinics, patients, partners, and Happy Light Tech.
- Contain security risk quickly.
- Preserve evidence.
- Determine scope and impact.
- Notify affected parties when required.
- Improve controls after the incident.
2. Incident Categories
Potential incidents include:
- unauthorized tenant access;
- suspected PHI exposure;
- recording or transcript access by unauthorized users;
- Open Dental CustomerKey exposure;
- payment or Stripe webhook abuse;
- admin account compromise;
- public data leak;
- credential stuffing;
- telephony abuse;
- referral fraud;
- email misrouting; and
- infrastructure compromise.
3. Intake
Incidents may be reported through support tickets, support email, monitoring alerts, audit logs, vendor notifications, customer reports, or internal review.
All suspected incidents should be assigned an incident ID, severity, owner, timestamp, and initial summary.
4. Triage
Triage should determine:
- affected tenant(s);
- affected branch(es);
- affected systems;
- whether PHI may be involved;
- whether raw secrets or payment data may be involved;
- whether patient safety could be affected;
- whether service should be paused or restricted; and
- whether legal counsel should be engaged immediately.
5. Containment
Containment may include:
- disabling accounts;
- revoking sessions;
- rotating secrets;
- disabling Open Dental connection;
- disabling phone number routing;
- pausing AI answering;
- blocking API tokens;
- restricting admin access;
- disabling a subprocessor integration; or
- deploying a security patch.
6. Investigation
Investigation should rely on audit logs, access records, infrastructure logs, provider logs, support records, and configuration history. Investigators should avoid copying PHI unless necessary and should store evidence securely.
7. Notification
If a potential Breach of Unsecured PHI is identified, Happy Light Tech should follow the applicable BAA and HIPAA breach notification process. Counsel should determine notification obligations, timing, content, and whether law enforcement delay or regulatory notice is required.
Customer-facing statements should be reviewed by counsel.
8. Recovery
Recovery may include restoring service, validating configuration, confirming secret rotation, notifying customers, monitoring for recurrence, and closing temporary mitigation controls.
9. Post-Incident Review
After resolution, document:
- timeline;
- root cause;
- affected data;
- affected tenants;
- decisions made;
- notifications sent;
- control gaps;
- corrective actions;
- owner and due dates.
10. Retention
Incident records should be retained as compliance evidence according to the retention policy and legal requirements.
