Security Incident Process

Connecting to the EHR solution requires that your organization follows an information security incident management process, in which all incidents are reported to eHealth Ontario. Security incidents are rare, but they do happen and must be acted on quickly. The stages of this process are depicted below for your quick reference in the event that a security incident occurs.

1. Identification and Triage

  • Notify your point of contact
  • Appoint an incident response lead or team
  • Notify eHealth Ontario

2. Response

  • Limit the scope and magnitude of an incident

3. Recovery

  • Remediate affected information systems so that they return to full and normal operations

4. Follow-up

  • Identify the root cause
  • Complete the incident report, and archive for a minimum of 24 months


Telephone: 1-866-250-1554