Pharmacy AI · Module 1 · Unit 3 · Practical 2

Data Breach Response Simulation

Aim — To respond to a live personal data breach in a hospital pharmacy — containing it, assessing its scope, deciding notifiability under the Digital Personal Data Protection Act, and handling the requests and pressures that arrive while you do so.

The incident

You are the pharmacy lead and the department’s data protection point of contact. It is Monday morning. Something has gone wrong over the weekend, and by the end of the exercise you will have had to make six decisions under time pressure.

  1. Containment comes before investigation. Every hour the exposure continues, the breach grows.
  2. Not every incident is notifiable — but you do not get to decide that on convenience. The test is risk to the individuals.
  3. Two of the six decisions are things people will ask you to do that you must refuse. Pressure is part of the exercise.
  4. A Containment Index tracks how much exposure remains, and a Compliance Index tracks whether your response would survive scrutiny.

Assessment rubric

Assessment criteriaMarks
Immediate containment — correct actions in the correct order25
Scope and risk assessment15
Notifiability decision20
Handling the subject access request15
Refusing improper disclosure15
Preventive action10
Total100

Pass 50. The Containment and Compliance indices are reported separately.

Achievement badges

🚨 Fast Containment📏 Correct Assessment 📨 Notified Properly🛑 Held the Line🏅 Incident Lead

Open the incident

Alizon Teaching Hospital · Pharmacy Department · data protection point of contact

Incident report & regulatory outcome

Complete the incident to generate your report, then write and submit it below.