HIPAA Breach Notification Letter Generator
Build a patient breach letter that covers all five elements required by 45 CFR §164.404(c), written in plain language. Enter the discovery date to see your 60-day countdown, and let the headcount switch on substitute, media, and HHS notices.
Pre-filled with a realistic stolen-laptop example from a family medicine practice. Edit any field and the letter updates as you type.
Individual notice deadline
—enter a discovery date
60 calendar days from discovery: October 9, 2026
“Without unreasonable delay” is the standard. 60 days is the ceiling, not the target. §164.404(b)
HHS Secretary report
Same 60-day window
1,240 individuals is 500 or more. File through the HHS breach portal at the same time you mail the letters. §164.408(b)
Your Organization
What Happened
§164.404(c)(1)(A)–(B)
If unknown, use the earliest date it could have happened.
First day it was known, or should have been known. Starts the 60-day clock.
Plain facts. Say whether you have evidence of access or misuse.
Types of Unsecured PHI Involved
What You Are Doing
§164.404(c)(1)(C)–(D)
Contact Procedures
§164.404(c)(1)(E)
Must stay active at least 90 days if substitute notice is used.
Scope & Additional Notices
§164.404(d)(2) · §164.406 · §164.408
Fewer than 10 unreachable individuals: an alternative written notice, phone call, or other means is enough. Toggle on if you want the letter to reference a web posting anyway.
More than 500 residents of one state or jurisdiction. Notify prominent media outlets serving that area within the same 60 days. The letter will mention the press notice.
Both switches follow your numbers by default. Override them if counsel advises a different approach, but document why.
Lakeside Family Medicine, P.C.
480 Harbor View Road, Suite 210, Traverse City, MI 49684
August 24, 2026
[Patient Name]
[Street Address]
[City, State ZIP]
RE: Notice of a Privacy Incident Involving Your Health Information
Dear [Patient Name],
We are writing to let you know about an incident that involved some of your health information. We take the privacy of your information seriously, and we want to explain what happened, what information was involved, what we are doing about it, and what you can do. This notice is provided as required by the HIPAA Breach Notification Rule (45 CFR §164.404).
What happened
On August 7, 2026, a laptop computer belonging to our practice was taken from a locked vehicle while a staff member was traveling between our two office locations. We learned of the theft on August 10, 2026, when the staff member reported it. The laptop was password-protected but was not encrypted. It contained a spreadsheet used to track appointment reminders for patients seen between January and July 2026. We have no evidence that anyone has accessed or misused the information, but we cannot rule it out.
The incident occurred on or about August 7, 2026. We discovered it on August 10, 2026.
What information was involved
The information involved may have included your full name, date of birth, home address / phone, medical record number, diagnosis or treatment information, and health insurance id / claims information. Your Social Security number and financial account information were not involved.
What we are doing
We filed a police report the same day the theft was reported and are cooperating with the Traverse City Police Department. We reviewed the laptop's backup to confirm exactly which files it contained and which patients were included.
We remotely disabled the laptop's access to our network and reset the credentials of the affected staff member. We have also reported this incident to the U.S. Department of Health and Human Services.
We have enabled full-disk encryption on every practice laptop, updated our policy so that patient information is never stored on portable devices, and retrained all staff on securing devices during travel.
Because of the number of people affected, we have also issued a notice to local news outlets, as federal law requires.
What you can do
- Review the statements you receive from your health insurer or from us. If you see a visit, service, or charge you do not recognize, contact the insurer or call us at the number below.
- Keep this letter with your records in case you have questions later.
- Order a free copy of your credit report from each of the three national credit bureaus at www.annualcreditreport.com or by calling 1-877-322-8228, and look for accounts you did not open.
- Consider placing a free fraud alert or security freeze on your credit file. You can do this by contacting Equifax, Experian, and TransUnion directly.
- You can learn more about protecting yourself from identity theft from the Federal Trade Commission at www.identitytheft.gov or 1-877-438-4338.
For more information
If you have questions, please call our dedicated toll-free line at 1-855-555-0142, Monday through Friday, 8:00 a.m. to 6:00 p.m. Eastern. You can also email privacy@lakesidefamilymed.example or write to us at the address above. Updates about this incident are posted at www.lakesidefamilymed.example/notice.
You also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr/complaints or 1-800-368-1019.
We sincerely regret that this happened and any concern it may cause you. Protecting your information is part of caring for you, and we are committed to doing better.
Sincerely,
Maria Delgado
Privacy Officer, Lakeside Family Medicine, P.C.
FIG · 01What Is a HIPAA Breach Notification Letter?
It is the written notice a covered entity must send to every person whose unsecured protected health information was compromised in a reportable breach. The Breach Notification Rule, 45 CFR §§164.400–414, sets what the letter must say, how it must be delivered (first-class mail, or email if the patient agreed), and the 60-calendar-day ceiling from discovery.
The letter is only step three of the process. First you decide whether the incident is a breach at all using the four-factor risk assessment in §164.402, which our incident report form walks through. Then you identify everyone affected. Only then do you write this letter.
The Five Required Elements (§164.404(c)(1))
OCR checks breach letters against this list. Missing one is a separate compliance failure on top of the breach itself. The generator maps every element to a field.
| Element | What the rule requires | Where it lives in this tool |
|---|---|---|
| (c)(1)(A) What happened | A brief description, including the date of the breach and the date of discovery (if known). | “What happened” section + the two dates |
| (c)(1)(B) PHI involved | The types of unsecured PHI involved: name, SSN, DOB, address, account number, diagnosis, and so on. | PHI checklist |
| (c)(1)(C) Steps individuals should take | What the person can do to protect themselves from potential harm. | “What you can do” list (adapts to the PHI selected) |
| (c)(1)(D) What you are doing | Your investigation, mitigation of harm, and protection against further breaches. | Investigation, mitigation, and prevention fields |
| (c)(1)(E) Contact procedures | A toll-free number, email address, website, or postal address for questions. | Contact Procedures card |
Plain language is a requirement, not a style choice. §164.404(c)(2) says the notice “shall be written in plain language.” Write for a worried patient, not for a regulator. The sample letter reads at roughly an eighth-grade level on purpose.
How to Use This Breach Letter Generator
- 1
Enter the two dates first — Discovery date starts the 60-day countdown at the top of the tool. If you are unsure when the breach occurred, use the earliest plausible date.
- 2
Describe the incident in plain facts — Two to five sentences. Say what happened, what device or system was involved, and whether you have evidence the data was viewed or misused.
- 3
Tick every PHI type involved — Selecting SSN, insurance ID, or financial data adds credit-report and fraud-alert steps to the letter automatically.
- 4
Fill in what you did, are doing, and will change — Three separate boxes so the letter covers investigation, mitigation, and prevention without you having to remember all three.
- 5
Set the headcounts — Total individuals, the largest number in any single state, and how many have no usable address. The substitute and media notice switches follow these numbers.
- 6
Print, copy, or paste into your mail-merge — The bracketed patient name and address fields are left for your mail-merge. Have counsel review before it goes out.
State law may add to this. Most states have their own breach statutes with shorter deadlines, attorney-general notice, or specific wording for SSN breaches. HIPAA is the floor. Check your state before mailing, and keep a copy of every letter for six years per your documentation policy (§164.530(j)).
Substitute, Media, and HHS Notices
The individual letter is the baseline. Three more obligations switch on depending on headcount and address quality, which is why the tool asks for those numbers.
Substitute notice
§164.404(d)(2)Trigger: Contact information is insufficient or out of date
Fewer than 10 people: any alternative written notice, phone call, or other means. 10 or more: a conspicuous posting on your website home page for 90 days, or a notice in major print or broadcast media where the affected people likely live. Either way, include a toll-free number that stays active for at least 90 days.
Media notice
§164.406Trigger: More than 500 residents of a single state or jurisdiction
Notify prominent media outlets serving that state or jurisdiction, usually by press release. Same 60-day ceiling from discovery, same five content elements as the individual letter. A breach of 1,200 people spread thinly across 40 states may not trigger it; 600 people in one county does.
HHS Secretary report
§164.408Trigger: Every breach, but the timing depends on size
500 or more individuals: report through the HHS breach portal at the same time you send individual notices, within 60 days of discovery. Fewer than 500: log it and submit all of the year's small breaches within 60 days after the calendar year ends (March 1 in a non-leap year). Large breaches are posted publicly on the OCR breach portal.
Late or missing notices are penalized under the same tiers as any other violation. See HIPAA violation penalties or run the numbers in the fine calculator.
The 60-Day Timeline, Day by Day
Day 0
Discovery. Any workforce member knows, or should have known. Open an incident record.
Days 1–5
Contain the incident. Complete the four-factor risk assessment. Decide: breach or low probability of compromise.
Days 5–20
Build the affected list. Confirm PHI types per person. Line up a toll-free line and, if needed, credit monitoring.
Days 20–30
Draft the letter with this tool. Counsel review. State-law check. Prepare press release if media notice applies.
Days 30–45
Mail letters first-class. File the HHS portal report (500+). Post the substitute notice if required.
Day 60
Absolute ceiling for individual, media, and HHS (500+) notices.
Law enforcement can ask you to delay notice if it would impede an investigation (§164.412). Get the request in writing; a verbal request only buys 30 days. Document the delay in your risk assessment file.
Six Mistakes That Turn One Violation Into Two
Starting the clock at the end of the investigation
The 60 days run from discovery, meaning the first day anyone in your workforce knew or should have known. Investigation happens inside the window, not before it.
Treating 60 days as the target
The standard is “without unreasonable delay.” OCR has penalized entities that waited until day 59 with no reason. Aim for two to three weeks once the affected list is confirmed.
Alarmist or legalistic wording
A letter that opens with “pursuant to 45 CFR” fails the plain-language test. Lead with what happened and what it means for the reader.
Listing PHI types that were not involved
Over-disclosing (“may have included SSN” when it did not) scares patients and inflates your risk. Be precise. Say plainly what was not involved.
Forgetting the toll-free number
Element (E) requires a toll-free number, email, website, or postal address. If substitute notice applies, the toll-free line is mandatory and must run 90 days.
Mailing before the business associate loop closes
If a BA caused the breach, its notice to you under §164.410 starts your clock. Get the affected list and facts from the BA in writing before drafting.
Most breaches trace back to a handful of common HIPAA violations: unencrypted laptops, misdirected fax or email, and snooping. Fixing the root cause is what the “prevention” paragraph should describe, and encrypting devices to NIST standards means a lost laptop is not a breach at all. See HIPAA encryption requirements and add breach drills to your annual training. Patients who are unhappy with your response can file a complaint with OCR, so the letter should tell them how.
Related Tools & Guides
HIPAA Breach Notification Requirements
Full guide to §§164.400–414: definitions, four-factor assessment, timelines, and penalties.
HIPAA Incident Report Form
Document the incident and run the four-factor risk assessment that decides whether this letter is required.
HIPAA Risk Assessment Tool
Find the gaps that cause breaches before they happen, across administrative, physical, and technical safeguards.
HIPAA Fine Calculator
Estimate 2026 penalty exposure by tier for late or missing breach notices.
Risk Management Hub
All risk assessment, incident response, and breach tools in one place.