Data Breach Response Plan
Last updated: January 6, 2026
Our Commitment to Data Security
Miles Ahead Charter School takes the security of student and family data very seriously. This Data Breach Response Plan outlines how we will respond in the event of a data security incident to protect your information and ensure transparency.
What Constitutes a Data Breach?
A data breach is an incident where unauthorized individuals gain access to personal or sensitive information. This may include:
- Unauthorized access to student or family records
- Theft or loss of devices containing personal information
- Cyberattacks or hacking incidents
- Accidental disclosure of sensitive information
- System vulnerabilities that expose data
Prevention Measures
We employ multiple layers of security to prevent data breaches:
- Encrypted data transmission (HTTPS/SSL)
- Secure authentication and access controls
- Regular security audits and vulnerability assessments
- Staff training on data security best practices
- Limited access to sensitive information (role-based permissions)
- Regular backups and disaster recovery procedures
- Secure hosting infrastructure with enterprise-grade security
Immediate Response (0-24 Hours)
Upon discovery or notification of a suspected breach, we will immediately:
1. Contain the Breach
- Isolate affected systems to prevent further unauthorized access
- Secure compromised accounts
- Preserve evidence for investigation
2. Assess the Incident
- Determine what information was accessed or compromised
- Identify affected individuals
- Evaluate the severity and scope of the breach
3. Activate Response Team
- Notify school administration and IT security team
- Contact Base44 platform security team if needed
- Document all actions taken
Short-Term Response (24-72 Hours)
Investigation
- Conduct thorough forensic investigation
- Identify vulnerabilities exploited
- Determine root cause of the breach
Notification
- Notify affected families via email and phone
- Provide clear information about what happened and what data was affected
- Comply with legal notification requirements (FERPA, state laws)
- Report to relevant authorities if required
Remediation
- Patch security vulnerabilities
- Reset passwords and credentials
- Implement additional security measures
Communication with Affected Parties
If your information is affected by a breach, we will:
- Contact you within 72 hours of confirming the breach
- Explain what information was compromised
- Detail the steps we're taking to address the issue
- Provide guidance on protecting your information
- Offer support resources (identity monitoring if applicable)
- Provide a dedicated contact for questions and concerns
Long-Term Response
Post-Incident Review
We will conduct a comprehensive review of the incident to identify lessons learned and prevent future occurrences.
Enhanced Security Measures
Based on the review, we will implement enhanced security protocols and update our systems as needed.
Staff Training
All staff will receive updated training on data security and breach prevention.
Policy Updates
We will update our policies and procedures to address any identified weaknesses.
Your Rights Following a Breach
If your information is compromised in a breach, you have the right to:
- Receive timely notification
- Understand what information was affected
- Request detailed information about the incident
- Know what steps are being taken to protect you
- Request additional support or resources
- File a complaint with relevant authorities
Reporting Suspected Breaches
If you suspect a security incident or data breach:
Report Immediately:
Destiny Lowe
Infinity Care Program Coordinator
Miles Ahead Charter School
destiny.lowe@milesaheadcharter.orgTime is critical in breach response. Early detection and reporting help minimize damage.
Legal and Regulatory Compliance
Our breach response procedures comply with:
- Family Educational Rights and Privacy Act (FERPA)
- State data breach notification laws
- Federal Trade Commission (FTC) guidelines
- Other applicable federal and state regulations
Third-Party Vendors
We work with trusted third-party vendors (Base44 platform, Square for payments) who maintain their own security standards and breach response procedures. In the event of a breach involving a third party, we will coordinate the response and keep you informed.
Questions and Support
For questions about our data security practices or this response plan:
Destiny Lowe
Infinity Care Program Coordinator
Miles Ahead Charter School
destiny.lowe@milesaheadcharter.orgNote: This plan is reviewed and updated annually or as needed following security incidents or changes in technology and regulations.
