Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
AWS Breach Notification Template for HIPAA-Covered EntitiesData Privacy
6 min readFor Data Privacy Officers

AWS Breach Notification Template for HIPAA-Covered Entities

When 3.8 million patient records leave your AWS environment over six days, you need more than an incident response plan. You need a pre-built notification framework that your team can execute under pressure. CareCloud's March breach shows the urgency of having a plan when an attacker gains access to cloud databases. You're racing against the 60-day notification clock while still investigating the scope.

This template provides the structure to draft your HIPAA breach notification letters before you need them. It's built around the Health Insurance Portability and Accountability Act requirements and designed for healthcare organizations running patient data in public cloud environments.

Purpose of This Template

You're required to notify affected individuals when protected health information is compromised. This template covers the individual notification letter, the document you'll send to patients, not the media statement or the HHS breach report.

Use this when:

  • You've confirmed unauthorized access to electronic protected health information in your cloud environment.
  • The breach affects 500 or more individuals.
  • You're operating under the 60-day notification requirement from discovery.

This template assumes you're a covered entity or business associate under the Health Insurance Portability and Accountability Act. If you're a cloud-based vendor serving multiple healthcare providers, you'll need to coordinate with your covered entity clients on who sends notifications.

Prerequisites

Before you customize this template, gather:

Technical facts from your investigation:

  • Date range of unauthorized access (e.g., March 10-16)
  • Affected systems or environments (specific AWS services, databases, S3 buckets)
  • Data elements potentially accessed (be specific: SSNs, financial account numbers, clinical data)
  • Current status of the threat (contained, ongoing monitoring, no evidence of further activity)

Legal and compliance inputs:

  • Confirmation from legal counsel that notification is required
  • State-specific breach notification requirements (some states have shorter timelines than HIPAA's 60 days)
  • Credit monitoring vendor contract (if you're offering services)
  • Contact center capacity for the call volume you'll receive

Operational readiness:

  • Dedicated phone number and hours of operation
  • Website URL for additional information
  • Mailing list validated and formatted
  • Translation requirements for non-English speakers in your patient population

The Template


[Your Organization Letterhead]

[Date]

[Patient Name]
[Patient Address]

Re: Notice of Data Security Incident

Dear [Patient Name]:

We are writing to inform you of a data security incident that may have involved your personal and health information. We take the privacy and security of your information seriously, and we are providing you with information about the incident, our response, and steps you can take to protect yourself.

What Happened

On [discovery date], we identified unauthorized access to [specific system: "one of our Amazon Web Services cloud environments" / "our electronic health records database" / "patient scheduling and billing systems"]. Our investigation determined that between [start date] and [end date], an unauthorized party accessed [describe the compromised environment without technical jargon].

We immediately [specific actions: "isolated the affected systems," "engaged cybersecurity forensic specialists," "notified law enforcement"]. As of [containment date], there is no evidence of ongoing unauthorized activity in our systems.

What Information Was Involved

The information that may have been accessed includes:

[Check all that apply and delete others:]

  • Name
  • Address
  • Date of birth
  • Social Security number
  • Driver's license or government ID number
  • Financial account or credit/debit card numbers
  • Health insurance information (policy numbers, subscriber ID)
  • Medical record number
  • Diagnosis and treatment information
  • Prescription information
  • Laboratory test results

Not all individuals were affected by all data elements listed above. We are notifying you because your information was stored in the affected system.

What We Are Doing

We have taken the following steps in response to this incident:

  • [Specific security measures: "Implemented additional access controls and monitoring in our cloud environment"]
  • [If applicable: "Engaged [forensic firm name] to conduct a comprehensive investigation"]
  • [If applicable: "Reset credentials and implemented multi-factor authentication requirements"]
  • [Ongoing: "Continuing to strengthen our security infrastructure and employee training programs"]

We have reported this incident to the U.S. Department of Health and Human Services and [state-specific regulators if applicable].

What You Can Do

We recommend you take the following steps to protect yourself:

  1. Review your accounts. Monitor your financial account statements and health insurance explanation of benefits for unusual activity.

  2. Consider a credit freeze. You can place a security freeze on your credit file at no cost by contacting each of the three major credit bureaus:

  3. Monitor your credit reports. You are entitled to one free credit report annually from each bureau at www.annualcreditreport.com.

  4. Report suspicious activity. If you identify fraudulent activity, file a report with your local police department and the Federal Trade Commission at www.identitytheftcenter.org or 1-877-ID-THEFT.

[If offering credit monitoring:]

Complimentary Credit Monitoring Services

We are offering you complimentary [12/24]-month credit monitoring and identity theft protection services through [vendor name]. To enroll, visit [URL] and use enrollment code [CODE] by [expiration date]. You must enroll by this date to take advantage of these services.

For More Information

If you have questions, please contact our dedicated assistance line at [phone number], available [days and hours]. You can also visit [website URL] for additional information and updates.

We sincerely regret any inconvenience or concern this incident may cause you.

Sincerely,

[Signatory Name]
[Title]
[Organization Name]


How to Customize It

Timeline accuracy matters. Don't round dates. If your investigation identified March 10-16 as the access window, state it exactly. Vague language erodes trust and may not satisfy state regulators.

Be specific about data elements. The checkbox list lets you tailor the letter to what was actually in the compromised environment. If you stored Social Security numbers but not financial account numbers, delete the financial line. Patients notice when you list data types you never collected from them.

Match your security response to your maturity level. If you're a small practice that didn't have multi-factor authentication before the breach, don't claim you're "implementing additional layers of advanced authentication protocols." Say you've "required multi-factor authentication for all system access", it's honest and demonstrates concrete action.

State-specific requirements override HIPAA. Some states require notification in fewer than 60 days or mandate specific language. Cross-reference this template with your state attorney general's breach notification requirements.

Credit monitoring decisions. Offering credit monitoring for a breach involving only clinical data (diagnoses, lab results) but no SSNs or financial information doesn't make sense. Tailor the offer to the actual risk. If SSNs or financial data were accessed, budget for at least 12 months of monitoring.

Translation obligations. If your patient population includes non-English speakers, you're required to provide translated versions. Don't just translate the letter, translate the call center scripts and website content too.

Validation Steps

Before you mail these letters, run through this checklist:

Legal review: Your general counsel or outside privacy counsel must approve the final version. They're checking for admissions of liability, compliance with state laws, and consistency with your SEC filings if you're publicly traded.

Data accuracy: Verify your mailing list against the investigation scope. Sending letters to unaffected patients triggers unnecessary panic and call volume. Not sending letters to affected patients violates the Health Insurance Portability and Accountability Act.

Call center readiness: Your dedicated phone line should be staffed before the first letter arrives. Train representatives on the incident facts, what information was involved, and how to handle angry or distressed callers. Script answers to predictable questions: "Was my credit card stolen?" "Do I need to change doctors?" "Are you paying for the credit monitoring?"

Website content: The URL you list in the letter must be live before letters drop. Include FAQs, the same protective steps from the letter, and contact information. Update it as you learn more.

Postage and printing: Use first-class mail, not bulk rate. This is time-sensitive information, and you want delivery confirmation. Budget for 10-15% returned mail due to outdated addresses.

HHS reporting: You must submit the breach to HHS within 60 days if it affects 500 or more individuals. File the report at HHS Breach Reporting before or concurrent with patient notification.

State attorney general notification: If the breach affects 500 or more state residents, most states require you to notify the AG's office. Some states require this notification before or concurrent with individual notices.

Media notification: Breaches affecting 500+ individuals require media notification in the affected jurisdiction. Coordinate timing with your patient letters and HHS submission.

This template won't prevent the breach, but it will help you meet your notification obligations without drafting under crisis conditions. Customize it now, store it in your incident response runbook, and review it annually as regulations evolve.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like