Skip to main content
Breach Notification Script for Healthcare Data IncidentsSecurity & Breach Notification
6 min readFor IT & Security Teams

Breach Notification Script for Healthcare Data Incidents

When unauthorized access affects millions of patient records and the forensic investigation takes months, your notification script can't be a placeholder. It needs to be a comprehensive communication framework that your incident response team can execute under pressure.

This template offers a structured approach for notifying affected individuals after a healthcare data breach. It's aligned with HIPAA notification requirements and incorporates lessons from real incidents where delayed detection complicated the response.

Purpose of This Template

Use this script to notify individuals that their protected health information has been accessed or acquired without authorization. The template includes:

  • Individual notification letters (mail and email)
  • Substitute notice for cases where contact information is missing
  • Media notice for breaches affecting 500 or more residents of a state
  • Regulatory filing content for the Department of Health and Human Services (HHS)

Ensure your forensic investigation is complete and you know what information was involved before using this template. If you're still investigating, you're not ready to proceed.

Prerequisites

Before customizing this template, ensure you have:

From your forensic investigation:

  • Confirmed dates of unauthorized access (first and last)
  • Internal confirmation date of the breach
  • Complete inventory of data elements involved
  • Count of affected individuals
  • Whether data was accessed, acquired, or both

From your legal and compliance review:

  • Determination that this meets HIPAA's breach threshold (low probability of compromise test failed)
  • Identification of all covered entities whose patients are affected
  • State-specific notification requirements that may exceed HIPAA's baseline

From your remediation plan:

  • Steps taken to secure systems
  • Services offered to affected individuals (credit monitoring duration, provider, enrollment deadline)
  • Dedicated contact channels for questions

Without these elements, your notification will raise more questions than it answers.

The Template

Individual Notification Letter

Subject: Notice of Data Security Incident

[Date]

Dear [Name / Resident],

We are writing to inform you of a data security incident that may have affected your protected health information maintained by [Your Organization Name].

What Happened

Between [First Date of Access] and [Last Date of Access], an unauthorized individual gained access to a portion of our [specify system: cloud infrastructure, network, application]. We discovered this activity on [Discovery Date] and immediately engaged external forensic specialists to investigate.

On [Internal Confirmation Date], we confirmed that the following types of information may have been accessed or acquired:

[List specific data elements, grouped by sensitivity:]

  • Identification information: [full names, dates of birth, driver's license numbers, Social Security numbers]
  • Medical information: [diagnosis codes, treatment records, prescription information]
  • Financial information: [health insurance policy numbers, financial account numbers]
  • [Other categories as applicable]

What We Are Doing

We have taken the following steps in response to this incident:

  • [Specific technical remediation: "Terminated the unauthorized access and implemented additional access controls"]
  • [Specific monitoring: "Deployed enhanced monitoring across all systems handling patient data"]
  • [Specific review: "Conducted a comprehensive review of access logs and security configurations"]
  • [Notification to authorities: "Reported this incident to the U.S. Department of Health and Human Services"]

What You Can Do

We recommend you take the following precautions:

  1. Enroll in complimentary credit monitoring and identity theft protection. We have arranged for [Provider Name] to provide [Duration]-month monitoring services at no cost to you. To enroll, visit [URL] or call [Phone Number] by [Enrollment Deadline]. Your activation code is [Code].

  2. Review your Explanation of Benefits statements from your health insurer for services you did not receive.

  3. Monitor your financial accounts for unauthorized activity.

  4. Consider placing a fraud alert or credit freeze on your credit files. Instructions for doing so are included in the enclosed reference guide.

For More Information

If you have questions about this incident, please contact our dedicated response line at [Phone Number], Monday through Friday, [Hours] [Time Zone]. You can also write to us at [Mailing Address].

We take the security of your information seriously and sincerely regret any concern this incident may cause.

Sincerely,

[Name]
[Title]
[Organization Name]


Media Notice (for breaches affecting 500+ state residents)

FOR IMMEDIATE RELEASE

[Organization Name] Notifies Individuals of Data Security Incident

[CITY, STATE], [Date], [Organization Name] is notifying approximately [Number] individuals that their protected health information may have been accessed without authorization between [Date Range].

[Organization Name] discovered unauthorized access to [specify system] on [Discovery Date]. Following a forensic investigation, we confirmed on [Confirmation Date] that the incident may have involved [brief description of data types].

We have no evidence that any information has been misused. However, out of an abundance of caution, we are offering affected individuals [Duration]-month complimentary credit monitoring and identity theft protection services through [Provider Name].

Individuals seeking more information should call [Phone Number] or visit [Website].


Regulatory Filing (HHS Breach Portal)

Breach Information

  • Date of breach: [First Date of Unauthorized Access]
  • Date breach discovered: [Discovery Date]
  • Type of breach: Unauthorized Access/Acquisition [select applicable]
  • Location of breached information: [Network Server, Cloud, Other]
  • Number of individuals affected: [Exact Count]
  • Business associate involved: [If applicable]

Description of Incident

Between [Date Range], an unauthorized individual accessed [Your Organization Name]'s [system description]. The breach was discovered on [Discovery Date] during [how it was discovered]. We engaged [Forensic Firm Name] to conduct an investigation, which confirmed on [Confirmation Date] that protected health information may have been accessed or acquired.

Types of Information Involved

[Check all that apply and provide detail:]

  • Demographic information
  • Clinical information
  • Financial information
  • Other [specify]

Actions Taken

[Describe technical remediation, notification timeline, and services offered]

How to Customize It

Timing precision matters. HIPAA requires notification without unreasonable delay and no later than 60 days after discovery of the breach. Count from your discovery date, not your confirmation date. If you're approaching day 50 and still finalizing details, send interim notice rather than miss the deadline.

Match your data inventory exactly. Don't use generic categories like "medical information" if your forensic report identified specific data elements. If the investigation found that diagnosis codes were accessed but clinical notes were not, say so. Vague descriptions create unnecessary anxiety and invite regulatory questions.

Customize remediation by root cause. If the breach resulted from compromised credentials, your remediation section should address authentication controls. If it stemmed from misconfigured cloud storage, address configuration management. Generic statements like "we take security seriously" tell affected individuals nothing about whether you've fixed the actual problem.

Scale your support infrastructure. For a breach affecting 9,540,683 individuals, you need dedicated phone lines with trained staff, not your standard customer service queue. Budget for call volume that peaks in the first two weeks after notification and tapers over 60 days. Your forensic and legal teams should prepare FAQ documents that cover the questions call center staff can't answer on their own.

Coordinate with covered entities. If you're a business associate and this breach affects multiple covered entities' patients, each covered entity remains responsible for notification. Provide them with templated content, but expect them to customize it with their own branding and contact information. Build a shared timeline so notifications go out in a coordinated window.

Validation Steps

Before you send anything:

Legal review checkpoint. Your outside counsel should review every customer-facing document. They're checking for admissions of negligence, compliance with state laws that exceed HIPAA (like Massachusetts's requirement for regulatory filing within 10 days), and consistency across all notification channels.

Data accuracy verification. Have someone outside the incident response team spot-check the affected individual count, date ranges, and data element lists against the forensic report. Errors in these details create regulatory exposure and erode trust.

Test your enrollment process. Before you mail 9.5 million letters, verify that the credit monitoring enrollment URL works, activation codes are valid, and the provider's call center is staffed to handle volume. Send test notifications to your own team and walk through the entire enrollment flow.

Regulatory filing confirmation. After you submit to the HHS Breach Portal, verify that your entry appears in the public database with the correct information. Discrepancies between your portal filing and your individual notifications will trigger supervisory authority questions.

Archive everything. Keep copies of every version of every notification document, along with mailing lists, email logs, media placement confirmations, and call center transcripts. If HHS or a state attorney general investigates, you'll need to demonstrate exactly who was notified, when, and how.

The difference between a contained breach response and a cascading compliance failure often comes down to whether your team had a tested script ready to execute. This template gives you that foundation, but only if you customize it with the specifics of your incident and your investigation's findings.

You Might Also Like