The situation
The number Niloufar gave us in the first call was roughly nine thousand customer records: names, phone numbers, appointment history, and for a portion of them, partial health information tied to physiotherapy treatment plans. The estimated cost of doing notification properly, letters, a call centre, credit monitoring for the records that included anything sensitive, sat in the range of sixty to ninety thousand dollars before regulatory or reputational cost was even counted. That was the figure that made the breach real in a way the vendor's apologetic email had not.
Niloufar was a practicing physiotherapist who had built a single clinic into a group of three wellness and physiotherapy locations across Guelph over nearly two decades, structured under a family trust that also held the clinic real estate and a smaller adjacent business. Combined revenue sat in the high single digits of millions. Cherise, the group's accountant and a co-trustee of the family trust, managed the financial side and first noticed the breach notice among routine correspondence, three days after it had apparently been sent.
The vendor was a scheduling and patient-communication software platform the clinics had used for six years, holding the full customer database that made daily operations possible. A misconfigured server setting, the kind of error a routine security review would ordinarily catch, had left a portion of that database accessible without authentication for an estimated eleven days before an outside security researcher discovered it and alerted the vendor. Keisha, the vendor's account manager, called Niloufar directly once the investigation confirmed the clinic group's data was among what had been exposed.
What made the call land harder than a first-time breach might have was that this was not the clinic group's first time confronting this exact vendor relationship. Two years earlier, during a general contract review, our office had flagged no signed data processing agreement with this vendor, no contractual commitment on security standards, breach notification timelines, or liability if something went wrong. The recommendation was straightforward: get one in place before it mattered. It had not been signed.
Niloufar remembered the recommendation when Cherise brought it up again that Tuesday. It had not been rejected or forgotten; it had simply been deprioritized behind a clinic expansion, a staffing shortage, and a year that, in hindsight, had no shortage of reasons that felt more urgent at the time. That is a common enough pattern with advice about risks that have not yet materialized, and it was about to become a considerably more expensive one.
The problem
Without a signed data processing agreement, the clinic group's leverage over the vendor in the moment of crisis was far weaker than it should have been. A proper agreement would have specified how quickly the vendor had to notify of a breach, what security standards it committed to, and who bore financial responsibility for notification costs, regulatory exposure, and resulting claims. None of that existed here. The clinics were operating on the vendor's standard terms of service, written entirely in the vendor's favour, disclaiming liability for data loss beyond a narrow refund of recent fees.
That gap mattered immediately. The eleven-day delay between the misconfiguration and its discovery was itself serious, and the additional three days before the clinic group saw the notice compounded it. Every day of that gap was a day the exposed data sat accessible with no way to know who, beyond the researcher who flagged it, might already have found it. Without a contractual notification deadline to point to, there was no clear basis to argue the vendor had breached its obligations by taking as long as it did to say what happened.
There was also the question of what Ontario privacy law required of the clinic group itself, separate from whatever the vendor owed it. Physiotherapy clinics are health information custodians under Ontario's health privacy legislation, and for records carrying health information tied to a patient's care, the notification duty was not something to weigh against a harm threshold the way an ordinary commercial breach is; a custodian must notify an affected individual at the first reasonable opportunity once it learns their health information was accessed without authority, largely regardless of the resulting harm's severity. Only the portion of the data that was pure contact information, with nothing health-related attached, left room for the more familiar risk-of-harm approach used outside the health sector. Either way, the obligation did not depend on the vendor's contract; it existed regardless, and needed to be discharged promptly, not whenever the vendor relationship got sorted out.
Niloufar's frustration ran toward the vendor and toward the advice that had gone unacted on two years earlier. Both were fair points, but neither changed what needed to happen next: run a proper breach response now, on the facts as they existed, while separately addressing why the contractual gap was still open.
Keisha's role added its own complication. As the vendor's account manager, her instinct was to reassure Niloufar and keep the relationship warm, offering informal apologies and vague assurances without committing to anything specific in writing. That goodwill is not worthless, but it is not a substitute for a documented commitment on costs, and treating a warm phone call as a binding agreement would have left the clinic group with nothing enforceable once the crisis passed and the relationship cooled.
What we did
- Assessed the scope and sensitivity of the exposed data together with Niloufar's clinical staff, distinguishing basic contact information from the smaller subset of records that included treatment-related health details, because the two categories are governed by different rules and the appropriate response differs depending on what kind of information was actually exposed, to how many people, and for how long it sat unsecured.
- Determined that notification to affected individuals was required, treating the records that included health information as governed by the clinic's duty as a health information custodian under Ontario's health privacy legislation, which calls for notice at the first reasonable opportunity rather than a discretionary weighing of harm, while applying the more familiar risk-of-harm assessment used for ordinary commercial data to the smaller set of records that held only contact information.
- Drafted the notification letters and call centre materials in plain language explaining what happened, what information was involved, and what steps affected customers could take to protect themselves, avoiding both alarmist language that would generate unnecessary panic and vague language that would understate a genuinely real risk, and having clinical staff review the health-related sections before anything went out, a step that mattered because a poorly worded notice generates more anxious calls than it prevents and can leave people unsure whether they were actually affected.
- Assessed whether the breach met the threshold for mandatory reporting to Ontario's privacy regulator, concluding it did given that health information had been left accessible without authorization for eleven days, and prepared that regulatory notification alongside the customer-facing one rather than waiting to see whether anyone complained first, which would have left the clinic group looking reactive rather than responsible.
- Sent a formal written demand to the vendor for a full accounting of the misconfiguration, the eleven-day gap before discovery, and the additional delay before notifying the clinic group, seeking contribution toward notification costs despite the absence of a signed data agreement that would have made that claim considerably stronger, harder to resist, and faster to resolve, framing the demand around the vendor's own admitted misconfiguration, since without a signed agreement the strongest available argument rested on its conduct, not on terms that were never put in writing.
- Declined to rely on Keisha's informal reassurances and insisted any cost contribution from the vendor be documented in writing before notification costs were incurred, since a verbal apology from an account manager carries no weight once a dispute over payment actually arrives at the vendor's finance or legal department months later, well after the goodwill of the first phone call has faded.
- Negotiated a partial cost-sharing arrangement with the vendor covering a meaningful portion of the notification and credit monitoring expenses, reflecting the vendor's operational fault in the misconfiguration itself even though its standard contract terms limited what it was formally obligated to pay under the existing terms of service the clinic group had never renegotiated, accepting a negotiated figure rather than a longer dispute that risked costing more in delay and fees than the extra recovery was worth, given the weak footing the missing agreement had left.
- Drafted and finalized the data processing agreement recommended two years earlier, this time with Niloufar's direct sign-off, setting concrete breach notification timelines, minimum security standards, and clearer allocation of liability for any future incident involving this vendor going forward, so the next breach, if there is one, would not start from the same contractual blank slate this one did, and so the leverage the clinic group had been missing this time would already be in place before it was needed again.
- Reviewed the clinic group's other vendor relationships for the same gap, identifying two additional vendors handling customer data without any comparable data agreement in place, and flagged them for the same fix before a second breach, with a different vendor, made the pattern impossible to keep ignoring or explaining away as a one-time lapse, producing a short list Niloufar and Cherise could act on immediately rather than treating this breach as an isolated incident tied only to one vendor's mistake.
The outcome
Notification went out to affected customers within a reasonable window of the clinic group learning the full scope of the breach, and the regulatory notification was filed alongside it. No formal regulatory action followed, though that outcome reflects the promptness and adequacy of the response rather than any certainty about how a regulator might have reacted to a slower or thinner one. A small number of customers raised concerns directly with the clinics; none escalated into a claim.
The vendor's cost-sharing contribution covered a meaningful portion of the notification expense, but not all of it, and the gap between what it paid and what the response actually cost sat with the clinic group. That gap was larger than it would have been with a signed data agreement in place from the start, a point that was not lost on Niloufar, who had approved the recommendation two years earlier and simply never circled back to sign it.
What changed permanently was the clinic group's posture toward vendor data relationships generally. The agreement with this vendor is now in place, and so are agreements with the two others the review surfaced. Niloufar has said plainly, in the months since, that the lesson was not about this particular vendor's failure but about her own delay in acting on advice that had cost nothing to follow at the time and cost considerably more to ignore. The breach was contained. The exposure that made containment necessary in the first place was not something the response could undo.
Keisha's employer, for its part, made no formal commitment beyond the negotiated cost-sharing figure, and the informal reassurances offered in the first calls were never mentioned again once the written agreement was signed. That was expected rather than disappointing; it was precisely why the arrangement had been put in writing rather than left as a handshake between an account manager and a client trying to make sense of a bad week.
What you can learn from this
- A signed data processing agreement with any vendor holding customer data is not paperwork for its own sake; it is the difference between having real contractual leverage during a breach and having none at all when it matters most.
- Your own notification obligations to affected customers and regulators exist independently of what a vendor's contract says or does not say, and they run on their own timeline regardless of how the separate dispute with the vendor eventually unfolds.
- Advice that costs nothing to follow when it is first given can become genuinely expensive the moment the risk it addressed actually materializes; a recommendation left unsigned is not the same thing as a risk that was avoided.
- Assess the sensitivity of exposed data carefully before deciding how to notify: health information usually carries a stricter, closer-to-automatic notification duty than ordinary contact data, and treating the two the same in either direction costs credibility with the people you are trying to inform and protect.
- One vendor's gap in data protections is rarely unique in a company's vendor list; use a breach as the occasion to check every other vendor holding similar data, and treat any apology or verbal reassurance from an account manager as worthless until it is in writing.
This is a corporate problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.