Data Breach Response Plan

Last updated: January 6, 2026

Our Commitment to Data Security

Miles Ahead Charter School takes the security of student and family data very seriously. This Data Breach Response Plan outlines how we will respond in the event of a data security incident to protect your information and ensure transparency.

What Constitutes a Data Breach?

A data breach is an incident where unauthorized individuals gain access to personal or sensitive information. This may include:

  • Unauthorized access to student or family records
  • Theft or loss of devices containing personal information
  • Cyberattacks or hacking incidents
  • Accidental disclosure of sensitive information
  • System vulnerabilities that expose data

Prevention Measures

We employ multiple layers of security to prevent data breaches:

  • Encrypted data transmission (HTTPS/SSL)
  • Secure authentication and access controls
  • Regular security audits and vulnerability assessments
  • Staff training on data security best practices
  • Limited access to sensitive information (role-based permissions)
  • Regular backups and disaster recovery procedures
  • Secure hosting infrastructure with enterprise-grade security

Immediate Response (0-24 Hours)

Upon discovery or notification of a suspected breach, we will immediately:

1. Contain the Breach

  • Isolate affected systems to prevent further unauthorized access
  • Secure compromised accounts
  • Preserve evidence for investigation

2. Assess the Incident

  • Determine what information was accessed or compromised
  • Identify affected individuals
  • Evaluate the severity and scope of the breach

3. Activate Response Team

  • Notify school administration and IT security team
  • Contact Base44 platform security team if needed
  • Document all actions taken

Short-Term Response (24-72 Hours)

Investigation

  • Conduct thorough forensic investigation
  • Identify vulnerabilities exploited
  • Determine root cause of the breach

Notification

  • Notify affected families via email and phone
  • Provide clear information about what happened and what data was affected
  • Comply with legal notification requirements (FERPA, state laws)
  • Report to relevant authorities if required

Remediation

  • Patch security vulnerabilities
  • Reset passwords and credentials
  • Implement additional security measures

Communication with Affected Parties

If your information is affected by a breach, we will:

  • Contact you within 72 hours of confirming the breach
  • Explain what information was compromised
  • Detail the steps we're taking to address the issue
  • Provide guidance on protecting your information
  • Offer support resources (identity monitoring if applicable)
  • Provide a dedicated contact for questions and concerns

Long-Term Response

Post-Incident Review

We will conduct a comprehensive review of the incident to identify lessons learned and prevent future occurrences.

Enhanced Security Measures

Based on the review, we will implement enhanced security protocols and update our systems as needed.

Staff Training

All staff will receive updated training on data security and breach prevention.

Policy Updates

We will update our policies and procedures to address any identified weaknesses.

Your Rights Following a Breach

If your information is compromised in a breach, you have the right to:

  • Receive timely notification
  • Understand what information was affected
  • Request detailed information about the incident
  • Know what steps are being taken to protect you
  • Request additional support or resources
  • File a complaint with relevant authorities

Reporting Suspected Breaches

If you suspect a security incident or data breach:

Report Immediately:

Destiny Lowe

Infinity Care Program Coordinator

Miles Ahead Charter School

destiny.lowe@milesaheadcharter.org

Time is critical in breach response. Early detection and reporting help minimize damage.

Legal and Regulatory Compliance

Our breach response procedures comply with:

  • Family Educational Rights and Privacy Act (FERPA)
  • State data breach notification laws
  • Federal Trade Commission (FTC) guidelines
  • Other applicable federal and state regulations

Third-Party Vendors

We work with trusted third-party vendors (Base44 platform, Square for payments) who maintain their own security standards and breach response procedures. In the event of a breach involving a third party, we will coordinate the response and keep you informed.

Questions and Support

For questions about our data security practices or this response plan:

Destiny Lowe

Infinity Care Program Coordinator

Miles Ahead Charter School

destiny.lowe@milesaheadcharter.org

Note: This plan is reviewed and updated annually or as needed following security incidents or changes in technology and regulations.