RxMart Inc.
Incident Response Plan
Response to security, fraud, and product safety incidents — including the statutory notification deadlines that apply to RxMart
Version 1.0 — DRAFT — July 30, 2026 | Complete the contact table in Section 3 before this plan is of any use
1. Purpose and Scope
This Plan governs RxMart’s response to incidents affecting the confidentiality, integrity, or availability of its systems and data, to fraud and misappropriation affecting company or member funds, and to product safety events involving Product transacted through its platforms.
It applies to all personnel and to all incidents regardless of source, including those originating with a vendor, a member, or an insider.
2. Severity Classification
Level | Definition | Response |
|---|---|---|
SEV-1 Critical | Confirmed breach of Restricted data; funds misappropriated; platform down; confirmed illegitimate Product distributed to members; confirmed counterfeit in the supply chain | Immediate. Full response team activated. CEO notified within 1 hour. Counsel engaged before any external communication. |
SEV-2 High | Suspected breach; account takeover; suspected diversion or suspect Product; significant vendor compromise; recall affecting Product transacted on platform | Response team activated within 4 hours. CEO notified same day. |
SEV-3 Moderate | Isolated account compromise contained; failed intrusion attempt with evidence of targeting; single-member data exposure; listing integrity failure | Assigned owner, response within 1 business day. |
SEV-4 Low | Policy violation without data impact; phishing attempt reported and blocked; minor misconfiguration | Logged and handled in normal operations. |
3. Response Team and Contacts
COMPLETE THIS TABLE. An incident response plan with blank contacts fails at the moment it is needed, and a reviewer will notice immediately.
Role | Name | Mobile | |
|---|---|---|---|
Incident Commander (default: CEO) | |||
Technical lead | |||
Compliance Officer | |||
Finance / Controller | |||
Outside counsel — privacy and cyber | |||
Outside counsel — FDA and regulatory | |||
Cyber insurance carrier / broker hotline | |||
Payment processor — escalation contact | |||
Cloud hosting provider — support escalation | |||
Forensic vendor (pre-engaged) | |||
Public relations / communications |
- Pre-engage the forensic vendor and confirm the insurer’s panel requirements before an incident. Many cyber policies will not cover a forensic firm you appointed without approval, and finding this out mid-incident is expensive.
- Keep an offline copy of this contact table. If the incident affects email or single sign-on, the online copy will be unreachable.
4. Response Phases
4.1 Detect and report
- Any person detecting a suspected incident reports immediately to [SECURITY NOTICE EMAIL] and to the Incident Commander. Do not investigate alone and do not attempt remediation before reporting.
- Member reports arrive through the same channel, as published in the Terms & Conditions.
- The Incident Commander opens an incident record with a unique identifier and begins the timeline log.
4.2 Triage and classify
- Assign severity per Section 2. When in doubt, classify higher; downgrading later is straightforward, escalating late is not.
- Determine preliminary scope: which systems, which data classes, how many members, whether funds are involved, whether Product is involved.
- Engage counsel at SEV-1 and SEV-2 before external communication. Where practical, direct the investigation through counsel so that findings are covered by privilege.
4.3 Contain
- Isolate affected systems, revoke compromised credentials, force password reset and re-authentication, and suspend affected accounts.
- Where funds are implicated, freeze disbursements immediately, notify the payment processor, and notify the bank.
- Where Product is implicated, quarantine listings, halt in-flight transactions, and hold related settlement.
- Preserve evidence before remediation: capture memory and disk images, export logs, and record timestamps. Do not wipe or rebuild a system until preservation is confirmed.
4.4 Eradicate and recover
- Remove the cause, patch the exploited weakness, and validate that access has been removed.
- Restore from clean backup where integrity is in question, and verify restored data.
- Return to normal operations only on the Incident Commander’s decision, with monitoring elevated for a defined period.
4.5 Notify
See Section 5. Notification decisions are made with counsel and are not delegated.
4.6 Post-incident review
- Conduct a documented review within [ten (10) business days] of closure, covering timeline, root cause, what worked, what failed, and corrective actions with owners and dates.
- Reviews are blameless as to individuals and specific as to controls.
- Track corrective actions to completion and report status to the CEO.
5. Notification Obligations
These deadlines run from determination, not from the completion of your investigation. The product safety deadline in particular is short and absolute.
Trigger | Notify | Deadline |
|---|---|---|
Illegitimate Product determination, or an FDA request for verification | FDA via Form 3911, and immediate trading partners | Within 24 hours — statutory |
Suspect Product identified | Quarantine, investigate, notify affected counterparties | Immediately on determination |
Recall or market withdrawal affecting transacted Product | All members who purchased the affected NDC or lot | Without delay; track response rate |
Breach of personal information | Affected individuals and state authorities per applicable state breach notification law | Varies by state; several require notice without unreasonable delay and some within 30 to 60 days |
Any security incident affecting payment data or platform integrity | Payment processor | Per processor agreement — confirm the contractual deadline |
Any incident likely to give rise to a claim | Insurance carrier or broker | Per policy — usually prompt notice; late notice can void coverage |
Suspected criminal conduct or insider theft | Counsel first, then law enforcement as counsel advises | Counsel decides sequencing |
Incident affecting a member’s licensure obligations | Affected members | Promptly |
Board of pharmacy or FDA inquiry received | Compliance Officer and counsel before any response | Same day |
- No one outside the response team communicates externally about an incident. All member, regulator, media, and partner communication is approved by the Incident Commander and counsel.
- Do not speculate about cause, scope, or attribution in any written communication, internal or external. Early written speculation that turns out wrong becomes an exhibit.
6. Playbooks
6.1 Account takeover or credential compromise
- Lock the account, revoke all sessions and API tokens, force credential reset with step-up verification.
- Freeze all disbursements on the account immediately. Review disbursement destination history for unauthorized changes.
- Review all activity since the earliest plausible compromise, including listings created, orders placed, and data accessed.
- Contact the member out of band using details already on file — never details recently changed on the account.
- Determine whether other accounts share indicators, and check for lateral movement.
6.2 Payment fraud or funds misappropriation
- Freeze disbursements platform-wide if the mechanism is unclear. A brief operational outage is cheaper than continuing losses.
- Notify the payment processor and the bank immediately; recall or reverse where the window is still open, which is often measured in hours.
- Engage counsel before internal interviews. Where an employee or insider is implicated, do not confront before counsel advises.
- Preserve all logs, approvals, and communications relating to the disbursement path.
- Notify the crime or fidelity insurer promptly — late notice is a common reason these claims are denied.
6.3 Data breach affecting member information
- Determine which data classes are affected. Restricted data — identification documents, banking details, beneficial ownership, screening results — escalates severity and notification obligations.
- Engage counsel to determine notification obligations, which vary by the state of residence of each affected individual.
- Preserve evidence and engage the pre-approved forensic vendor.
- Prepare member notification with counsel; do not send before scope is established.
- Notify the cyber insurer at the point of suspicion, not at the point of confirmation.
6.4 Ransomware
- Isolate affected systems from the network immediately; do not power down where memory evidence may be needed.
- Do not communicate with the threat actor without counsel and the insurer. Payment raises sanctions screening obligations.
- Assess backup integrity before assuming recovery is possible.
- Assume data exfiltration occurred until evidence shows otherwise, and handle notification on that basis.
6.5 Suspect or illegitimate Product
- Quarantine the listing and suspend the account. Halt in-flight transactions and freeze related settlement.
- Notify both transacting parties and instruct the holder to quarantine and not dispense.
- Support the investigating party and coordinate with the manufacturer or its authorized distributor for verification.
- On an Illegitimate Product determination, ensure FDA Form 3911 notification within twenty-four hours, and notify all downstream recipients identifiable from platform records.
- Engage regulatory counsel before any communication with FDA or a state board.
- Open a look-back review of all prior transactions by the implicated member.
6.6 Recall
- Identify all members who purchased the affected NDC or lot through the platform.
- Remove affected listings and halt in-flight transactions where possible.
- Notify affected members with the recall notice and the manufacturer’s instructions, and track acknowledgment.
- Produce a downstream recipient list on request from the manufacturer or a regulator.
- Record the event with dates, scope, notifications sent, and response rate.
6.7 Vendor or third-party compromise
- Determine what RxMart data the vendor holds and whether platform access is implicated.
- Rotate any credentials or API keys shared with that vendor.
- Require written incident detail from the vendor, including scope and remediation.
- Assess whether RxMart has independent notification obligations arising from the vendor’s breach. Usually it does.
7. Evidence and Records
- Maintain a contemporaneous timeline log for every SEV-1 and SEV-2 incident: what was observed, when, by whom, and what action was taken.
- Preserve system images, logs, and communications. Do not delete anything relating to an incident, including messages, even where embarrassing.
- Incident records, investigations, and notifications are retained for not less than six (6) years.
- Where counsel directs the investigation, mark work product accordingly and route findings through counsel.
8. Testing and Maintenance
- Conduct a tabletop exercise at least [annually], rotating scenarios across the playbooks in Section 6. Include at least one product safety scenario, not only cyber.
- Verify the Section 3 contact table [quarterly].
- Update this Plan after every SEV-1 or SEV-2 incident and at least annually.
- Confirm insurer notification requirements and panel vendor lists at every policy renewal.
Plan owner: [NAME / TITLE]
Approved by: [CEO]
Effective date: [EFFECTIVE DATE]
Review cycle: Annually, after any SEV-1 or SEV-2, and at insurance renewal
Version: 1.0