Breach Policy
What we do, and what you should expect from us, if your protected health information is exposed in an incident.
Last updated July 24, 2026. DiveSlip is a service of SickSlip P.A.
1. What counts as a breach
A breach is any acquisition, access, use, or disclosure of protected health information not permitted under our privacy practices that compromises the security or privacy of that information. Examples:
- An unauthorized person gains access to your questionnaire answers, records, or evaluation.
- A vendor that processes data for us discloses that they had a breach affecting our data.
- A device containing PHI is lost or stolen.
- A workforce member accesses information beyond what their role requires.
- Credentials such as passwords or API keys are compromised.
2. What we do when a breach occurs
- Contain it. Identify the vector and patch immediately; rotate compromised credentials.
- Preserve forensics. Capture logs and database state for the affected window before cleanup.
- Determine scope. Whose records, what categories of information, whether data left our systems, whether exposure is ongoing.
- Engage counsel when exposure is confirmed.
- Notify you in writing without unreasonable delay and within the timelines of the HIPAA Breach Notification Rule (45 CFR 164.404) and your state’s breach notification statute.
- Notify regulators as required, including the HHS Office for Civil Rights and applicable state authorities.
- Remediate. Depending on what was exposed: credit monitoring at our expense, free record export, refunds, or free re-issuance of your evaluation if integrity was affected.
- Prevent recurrence. Add the check, alert, or code constraint that stops the same class of incident from happening again.
3. What the notification letter contains
- What happened, in plain language
- When it happened
- What categories of your information were involved
- What we are doing in response
- What you can do
- Our contact information for questions
4. Record integrity incidents
If an incident affects the integrity of a medical record itself, for example corrupted answers or an unauthorized modification, we additionally restore from point-in-time backups, mark any affected evaluation as under review on the public verification endpoint until a corrected document is re-issued, and contact you directly.
5. Contact
Incident or breach concerns: privacy@sickslip.co or support@diveslip.co · (855) 346-3483.