What Your HIPAA Breach Notification Letter to Patients Must Include
Purpose of HIPAA Breach Notification
When unsecured protected health information (PHI) is compromised, HIPAA requires you—as a covered entity or business associate—to notify affected individuals. The breach notification letter explains what happened, what information was involved, what you are doing about it, and what patients can do next.
Beyond regulatory compliance, the letter builds trust. It equips people to act quickly to reduce risk, shows transparency in your breach investigation, and demonstrates accountability through mitigation of harm and prevention steps.
Required Contents of Notification Letter
Your letter must be clear, factual, and written in plain language. Include the following elements in this order or a logical flow that keeps them together and easy to find:
- Brief description of what happened, including the date of the breach and the breach discovery date (if known).
- Description of the types of information involved, especially any personal identifiers and sensitive clinical or financial details.
- Specific steps individuals should take to protect themselves.
- What your organization is doing for breach investigation, mitigation of harm, and to prevent future incidents.
- How to reach you for questions or assistance (contact procedures and channels).
Notification timing
Send the notification without unreasonable delay and no later than 60 calendar days after the breach discovery date. If law enforcement requests a delay, state that you will notify as soon as the delay is lifted.
Description of Breach
Provide a concise, factual narrative of the event. State what occurred, how it was identified, the time frame of exposure, and whether the incident has been contained. Avoid speculation; share only what your breach investigation confirms.
Include the date of the breach and the breach discovery date if known, and indicate whether an unauthorized person viewed, acquired, or used PHI. If applicable, note whether data were encrypted, exfiltrated, or merely accessed, and clarify any systems or locations affected (for example, email, a third-party portal, or a lost device).
Clarity tips
- Use simple terms patients understand; define technical terms briefly if needed.
- Be transparent about what is still under investigation and when updates will follow.
- Avoid minimizing or alarming language; focus on verified facts and next steps.
Types of Information Involved
Describe the categories of PHI at issue so individuals can gauge potential impact. Reference the presence or absence of personal identifiers and sensitive data elements, such as:
- Full name, address, phone number, email address, or date of birth.
- Medical record number, patient account number, diagnoses, medications, treatment details, or test results.
- Health plan member ID, claim information, or Explanation of Benefits data.
- Social Security number, driver’s license number, or financial account/credit card numbers (if involved).
If certain high-risk elements (for example, Social Security or financial account numbers) were not involved, say so plainly to reduce unnecessary alarm. If they were involved, highlight the specific protective actions patients should consider.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Steps for Individuals to Take
Offer practical, prioritized actions so patients can protect themselves right away. Tailor this list to the data types involved:
- Monitor medical bills and Explanation of Benefits for unfamiliar services; report discrepancies promptly.
- Change passwords for impacted accounts and enable multi-factor authentication; avoid reusing passwords.
- Place a fraud alert or credit freeze with major credit bureaus; review free credit reports for unusual activity.
- Watch for phishing attempts referencing the incident; do not click links or share codes with unknown senders.
- Consider enrolling in any identity or credit monitoring you offer as part of mitigation of harm.
Actions by Covered Entity
Explain what you are doing now and going forward. Patients expect concrete steps that show control and progress:
- Conducting a thorough breach investigation to determine scope, root cause, and affected data.
- Containing the incident, securing systems, resetting credentials, and enhancing monitoring.
- Mitigation of harm measures, such as offering credit or identity monitoring, replacing member IDs, or coordinating with payers.
- Strengthening safeguards through policy updates, workforce training, vendor oversight, and technical controls.
- Engaging appropriate authorities or regulators when required and communicating updates as new facts are validated.
Contact Information
Provide clear, reliable ways for individuals to reach you for help. Offer multiple channels when feasible and ensure they are staffed and responsive.
- Toll-free number with hours of operation (and TTY/TDD availability, if applicable).
- Dedicated email address or secure web form for breach-related inquiries.
- Mailing address for written requests, such as copies of records or dispute letters.
- Reference or case number patients can cite to expedite assistance.
Conclusion
A strong HIPAA breach notification letter gives patients timely facts, explains the types of information involved, provides clear steps they can take, and details what your organization is doing to investigate, mitigate harm, and prevent recurrence. Precision, empathy, and prompt notification timing are essential to protect individuals and uphold trust.
FAQs.
What information must be disclosed in a HIPAA breach notification letter?
You must include a brief description of what happened (with the date of the breach and the breach discovery date, if known), the types of information involved (including relevant personal identifiers and any sensitive data), steps individuals should take to protect themselves, what your organization is doing for breach investigation and mitigation of harm, and clear contact information for questions or assistance.
When must a HIPAA breach notification letter be sent?
Send the letter without unreasonable delay and no later than 60 calendar days after the breach discovery date. If law enforcement requests a temporary delay, you may pause notification until permitted to proceed, then notify affected individuals promptly.
What steps should patients take after receiving a breach notification?
Patients should review medical and financial statements for unfamiliar activity, change passwords and enable multi-factor authentication, consider placing a fraud alert or credit freeze, watch for phishing, and enroll in any monitoring services offered to support mitigation of harm.
How should covered entities provide contact information in the notification letter?
Include at least one accessible, reliable channel—such as a toll-free number—plus a dedicated email or web form and a mailing address. State service hours, note any language or TTY/TDD support, and provide a reference number so individuals can receive fast, case-specific assistance.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.