Dealing with Data Breaches on Patients' EMR Sensitive Data: A Comprehensive Approach
What to do in the first hours of a breach — and what to have done beforehand.
Dr. Raphael Akangbe (Ph.D)
Co-Founder, Xeventy2.0 Health Limited | Digital Health & Health Informatics Expert

A breach of patient Electronic Medical Record data puts two things at risk at once: the privacy of the individual, and the standing of the institution holding the record. This paper sets out the sequence for managing one.
Respond promptly
Notify the appropriate people inside the organisation, isolate the affected systems, and limit access to the sensitive data. Speed here bounds everything that follows.
Investigate thoroughly
Establish the cause and the extent. Forensic analysis, system log review, and examination of access and audit trails are what identify the vulnerability and the point of entry — and an audit trail that was not being kept before the breach cannot be consulted after it.
Notify those affected
This is both a legal and an ethical obligation. The communication needs to be clear about what happened, what the risks are, and what the individual can do to protect themselves.
Enhance security measures
After a breach: stronger access controls, encryption, and staff training in security practice.
Support the people affected
Offer resources — credit monitoring, fraud detection assistance, identity theft protection — that reduce the harm the breach can still do.
Learn from it
Identify the gaps and weaknesses in information systems security, and implement improvements by reviewing and reworking existing records and the data management strategy. A breach that changes nothing will be repeated.
Comply
Adhere to national and global regulatory requirements, and stay current with changes to breach reporting and management obligations, which move.
Prevention remains the best approach
Regularly reviewing and updating security measures, conducting risk assessments and staying vigilant is what minimises the likelihood of a breach in the first place. Handled comprehensively, healthcare organisations can manage breaches and protect patient privacy within the realm of sensitive EMR data.
Co-authored with Tyna Charles-Chinkata, AIIM-CIP, MSc. ISM.
The full paper
This is a summary. The complete paper, with its methodology and references, is available in full.
Written by Dr. Raphael Akangbe (Ph.D) · 28 August 2026





