Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Breach Notification Template for Small Healthcare PracticesIncident & Breach Response
6 min readFor GRC Leaders

Breach Notification Template for Small Healthcare Practices

When your practice discovers unauthorized system access, you're immediately on the clock for regulatory deadlines. Small healthcare organizations face the same HIPAA Security Rule and HIPAA Privacy Rule obligations as large health systems, but often with fewer resources to manage a compliant response.

This template provides a structured approach to patient notification, addressing the HHS' Office for Civil Rights reporting requirements while maintaining the clinical trust your practice relies on.

Purpose of This Template

This notification letter template helps meet the HIPAA Breach Notification Rule's requirement to notify affected individuals within 60 days of breach discovery. It's tailored for small practices (under 15 providers) that have confirmed unauthorized access to protected health information but lack dedicated compliance staff.

The template includes:

  • Individual notification content requirements under 45 CFR § 164.404(c)
  • Recommended actions that reduce patient anxiety without creating liability
  • Language that satisfies regulatory obligations without over-promising remediation

This is not: A substitute for legal review, a media statement template, or guidance on the separate HHS notification required for breaches affecting 500 or more individuals.

Prerequisites

Before customizing this template, ensure you have:

  1. Incident timeline confirmation: Date of unauthorized access, date of discovery, date access was terminated.
  2. Data elements identified: Completed review showing which specific data types were exposed (names, SSNs, treatment records, payment information).
  3. Affected individual count: Final or preliminary count from your data review.
  4. Third-party validation: Forensic report confirming scope and containment (even a preliminary report).
  5. Legal clearance: Attorney review confirming you're ready to notify (notification can trigger litigation).

If your investigation is ongoing and you cannot confirm data types or individual counts, you're not ready to send this letter. The HIPAA Breach Notification Rule requires notification "without unreasonable delay and in no case later than 60 calendar days" from discovery, but sending incomplete information creates more risk than waiting for accurate details.

The Template


[Practice Letterhead]

[Date]

[Patient Name]
[Patient Address]

Re: Notice of Data Security Incident

Dear [Patient Name]:

We are writing to inform you of a data security incident that may have involved your protected health information. [Practice Name] takes the privacy and security of patient information seriously, and we want to provide you with information about the incident, the data potentially involved, and steps you can take to protect yourself.

What Happened

On [Discovery Date], we identified suspicious activity within our [email system / electronic health record system / network]. We immediately secured the affected systems and engaged third-party cybersecurity specialists to investigate. The investigation confirmed that an unauthorized party accessed our systems between [Start Date] and [End Date].

What Information Was Involved

Our review determined that the following types of your information may have been accessed:

[Check all that apply] ☐ Name and contact information (address, phone number, email)
☐ Date of birth
☐ Social Security number
☐ Driver's license or state ID number
☐ Medical record number
☐ Diagnosis and treatment information
☐ Prescription records
☐ Health insurance information
☐ Payment or financial account information

What We Are Doing

We have taken the following steps to address this incident and strengthen our security:

  • Terminated unauthorized access and secured affected systems
  • Engaged [Forensic Firm Name] to conduct a thorough investigation
  • Implemented additional monitoring and security controls
  • [If applicable: Reported the incident to law enforcement]
  • Notified the U.S. Department of Health and Human Services as required by federal law

To date, we are not aware of any actual misuse of your information resulting from this incident.

What You Can Do

We recommend you remain vigilant by:

  1. Reviewing your accounts: Monitor your explanation of benefits statements from your health insurer for services you did not receive. Contact your insurer immediately if you identify unfamiliar claims.

  2. Monitoring your credit: You are entitled to one free credit report annually from each of the three major credit bureaus at annualcreditreport.com. Consider staggering your requests every four months.

  3. Placing a fraud alert: Contact one of the three credit bureaus to place a fraud alert on your file. The bureau you contact must notify the other two.

    • Equifax: 1-800-525-6285
    • Experian: 1-888-397-3742
    • TransUnion: 1-800-680-7289
  4. Considering a credit freeze: A security freeze restricts access to your credit file, making it harder for identity thieves to open accounts in your name. Contact each bureau directly to request a freeze.

[If offering credit monitoring services]
Complimentary Credit Monitoring

We are offering you [12/24] months of complimentary credit monitoring and identity theft protection services through [Provider Name]. To enroll, visit [URL] and use enrollment code [CODE] by [Deadline Date].

For More Information

If you have questions about this incident, please contact us at [Phone Number] between [Hours]. Additional information is available on our website at [URL].

We sincerely apologize for this incident and any concern it may cause. Protecting your information is a responsibility we take seriously.

Sincerely,

[Provider Name]
[Title]


How to Customize It

Section 1: What Happened
Be specific about discovery date and access period. Vague language ("recently discovered") fails the regulatory requirement for transparency. If your investigation is ongoing and you cannot confirm the exact access period, state "between approximately [earliest possible date] and [discovery date]."

Section 2: What Information Was Involved
List only data elements your review confirmed were in the accessed systems. Do not check boxes for data types you "might have stored there." If different patients had different data exposed, you need individualized letters or a statement like "the specific information varied by individual and may have included one or more of the following."

Section 3: What We Are Doing
Name your forensic firm if you engaged one (it demonstrates due diligence). Do not promise future security measures you haven't budgeted for or implemented. "We are evaluating additional security enhancements" is safer than "we will implement multi-factor authentication" if you lack the budget or vendor support.

Section 4: What You Can Do
The Federal Trade Commission recommends this four-step approach. Do not tell patients to "contact the credit bureaus if they have concerns" without providing the actual phone numbers (it creates friction that reduces protective action). If Social Security numbers were exposed, credit monitoring is expected. If only clinical data was exposed, monitoring recommendations without paid services are typically sufficient.

Credit Monitoring Decision
If you're offering complimentary services, specify the enrollment deadline (typically 90 days from letter date) and make the enrollment process as simple as possible. Patients who receive a code but face a complex enrollment process rarely activate the service, which increases your liability if fraud occurs later.

Validation Steps

Before you mail notifications:

  1. Count accuracy: Cross-reference your mailing list count with the number you'll report to HHS' Office for Civil Rights. Discrepancies raise red flags during investigations.

  2. Address validation: Run your patient address list through USPS address verification. Returned mail for patients you cannot locate must be handled differently (substitute notice on your website for 90 days if you cannot reach 10 or more individuals).

  3. Timing coordination: If you're notifying 500 or more individuals, you must notify HHS and prominent media outlets in your service area simultaneously with or before individual notifications go out. Schedule your HHS breach portal submission and press release for the same day you mail letters.

  4. Documentation: Keep copies of the final letter, mailing list, proof of mailing date, and any bounce-backs. HHS audits frequently request evidence that notification occurred within the 60-day window.

  5. Staff briefing: Your front desk will receive calls. Prepare a two-sentence script: "We discovered unauthorized access to our systems on [date]. The letter explains what happened and what steps you can take. I can transfer you to [designated contact] if you have specific questions about your account."

Recent breach reports show practices took between two and 22 months to notify patients after discovery. This range reflects investigation complexity, but it also shows how quickly a small practice can fall out of compliance without a pre-planned incident response. This template won't prevent a breach, but it gives you a head start on the notification obligation that follows.

Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."

You Might Also Like