Risk Management

HIPAA Breach Notification Letter Generator

Build a patient breach letter that covers all five elements required by 45 CFR §164.404(c), written in plain language. Enter the discovery date to see your 60-day countdown, and let the headcount switch on substitute, media, and HHS notices.

Cyanotype of a sealed envelope with a security tint showing through its torn corner, beside a wet-ink stampFIG · 01
An envelope, a folded blank sheet and an ink pad.

What Is a HIPAA Breach Notification Letter?

It is the written notice a covered entity must send to every person whose unsecured protected health information was compromised in a reportable breach. The Breach Notification Rule, 45 CFR §§164.400–414, sets what the letter must say, how it must be delivered (first-class mail, or email if the patient agreed), and the 60-calendar-day ceiling from discovery.

The letter is only step three of the process. First you decide whether the incident is a breach at all using the four-factor risk assessment in §164.402, which our incident report form walks through. Then you identify everyone affected. Only then do you write this letter.

The Five Required Elements (§164.404(c)(1))

OCR checks breach letters against this list. Missing one is a separate compliance failure on top of the breach itself. The generator maps every element to a field.

ElementWhat the rule requiresWhere it lives in this tool
(c)(1)(A)

What happened

A brief description, including the date of the breach and the date of discovery (if known).“What happened” section + the two dates
(c)(1)(B)

PHI involved

The types of unsecured PHI involved: name, SSN, DOB, address, account number, diagnosis, and so on.PHI checklist
(c)(1)(C)

Steps individuals should take

What the person can do to protect themselves from potential harm.“What you can do” list (adapts to the PHI selected)
(c)(1)(D)

What you are doing

Your investigation, mitigation of harm, and protection against further breaches.Investigation, mitigation, and prevention fields
(c)(1)(E)

Contact procedures

A toll-free number, email address, website, or postal address for questions.Contact Procedures card

Plain language is a requirement, not a style choice. §164.404(c)(2) says the notice “shall be written in plain language.” Write for a worried patient, not for a regulator. The sample letter reads at roughly an eighth-grade level on purpose.

How to Use This Breach Letter Generator

  1. 1

    Enter the two dates firstDiscovery date starts the 60-day countdown at the top of the tool. If you are unsure when the breach occurred, use the earliest plausible date.

  2. 2

    Describe the incident in plain factsTwo to five sentences. Say what happened, what device or system was involved, and whether you have evidence the data was viewed or misused.

  3. 3

    Tick every PHI type involvedSelecting SSN, insurance ID, or financial data adds credit-report and fraud-alert steps to the letter automatically.

  4. 4

    Fill in what you did, are doing, and will changeThree separate boxes so the letter covers investigation, mitigation, and prevention without you having to remember all three.

  5. 5

    Set the headcountsTotal individuals, the largest number in any single state, and how many have no usable address. The substitute and media notice switches follow these numbers.

  6. 6

    Print, copy, or paste into your mail-mergeThe bracketed patient name and address fields are left for your mail-merge. Have counsel review before it goes out.

State law may add to this. Most states have their own breach statutes with shorter deadlines, attorney-general notice, or specific wording for SSN breaches. HIPAA is the floor. Check your state before mailing, and keep a copy of every letter for six years per your documentation policy (§164.530(j)).

Substitute, Media, and HHS Notices

The individual letter is the baseline. Three more obligations switch on depending on headcount and address quality, which is why the tool asks for those numbers.

Substitute notice

§164.404(d)(2)

Trigger: Contact information is insufficient or out of date

Fewer than 10 people: any alternative written notice, phone call, or other means. 10 or more: a conspicuous posting on your website home page for 90 days, or a notice in major print or broadcast media where the affected people likely live. Either way, include a toll-free number that stays active for at least 90 days.

Media notice

§164.406

Trigger: More than 500 residents of a single state or jurisdiction

Notify prominent media outlets serving that state or jurisdiction, usually by press release. Same 60-day ceiling from discovery, same five content elements as the individual letter. A breach of 1,200 people spread thinly across 40 states may not trigger it; 600 people in one county does.

HHS Secretary report

§164.408

Trigger: Every breach, but the timing depends on size

500 or more individuals: report through the HHS breach portal at the same time you send individual notices, within 60 days of discovery. Fewer than 500: log it and submit all of the year's small breaches within 60 days after the calendar year ends (March 1 in a non-leap year). Large breaches are posted publicly on the OCR breach portal.

Late or missing notices are penalized under the same tiers as any other violation. See HIPAA violation penalties or run the numbers in the fine calculator.

The 60-Day Timeline, Day by Day

Day 0

Discovery. Any workforce member knows, or should have known. Open an incident record.

Days 1–5

Contain the incident. Complete the four-factor risk assessment. Decide: breach or low probability of compromise.

Days 5–20

Build the affected list. Confirm PHI types per person. Line up a toll-free line and, if needed, credit monitoring.

Days 20–30

Draft the letter with this tool. Counsel review. State-law check. Prepare press release if media notice applies.

Days 30–45

Mail letters first-class. File the HHS portal report (500+). Post the substitute notice if required.

Day 60

Absolute ceiling for individual, media, and HHS (500+) notices.

Law enforcement can ask you to delay notice if it would impede an investigation (§164.412). Get the request in writing; a verbal request only buys 30 days. Document the delay in your risk assessment file.

Six Mistakes That Turn One Violation Into Two

Starting the clock at the end of the investigation

The 60 days run from discovery, meaning the first day anyone in your workforce knew or should have known. Investigation happens inside the window, not before it.

Treating 60 days as the target

The standard is “without unreasonable delay.” OCR has penalized entities that waited until day 59 with no reason. Aim for two to three weeks once the affected list is confirmed.

Alarmist or legalistic wording

A letter that opens with “pursuant to 45 CFR” fails the plain-language test. Lead with what happened and what it means for the reader.

Listing PHI types that were not involved

Over-disclosing (“may have included SSN” when it did not) scares patients and inflates your risk. Be precise. Say plainly what was not involved.

Forgetting the toll-free number

Element (E) requires a toll-free number, email, website, or postal address. If substitute notice applies, the toll-free line is mandatory and must run 90 days.

Mailing before the business associate loop closes

If a BA caused the breach, its notice to you under §164.410 starts your clock. Get the affected list and facts from the BA in writing before drafting.

Most breaches trace back to a handful of common HIPAA violations: unencrypted laptops, misdirected fax or email, and snooping. Fixing the root cause is what the “prevention” paragraph should describe, and encrypting devices to NIST standards means a lost laptop is not a breach at all. See HIPAA encryption requirements and add breach drills to your annual training. Patients who are unhappy with your response can file a complaint with OCR, so the letter should tell them how.

Related Tools & Guides