Writing Breach Notification Letters Families Can Understand

When protected health information is breached, the legal clock starts and a difficult task follows: writing to the people affected. Many organizations hand this to a lawyer or a template and send out a letter that is technically compliant but unreadable. For residents and their families, often older adults or adult children already worried about care, clarity matters as much as compliance.

This article covers what a notification letter must contain, how to write it in plain language, and the tone choices that make the difference between reassurance and alarm. It is general information, not legal advice. Your counsel should review any letter before it goes out.

What the rule requires

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach. The notice must be written in plain language and generally include:

A brief description of what happened, including the date of the breach and the date of discovery, if known

The types of information involved, such as names, Social Security numbers or diagnoses

Steps individuals should take to protect themselves

What your organization is doing to investigate, reduce harm and prevent recurrence

Contact information for questions

State laws may add requirements or shorter deadlines, so your attorney should confirm what applies to residents in each state you serve.

Writing in plain language

Use short sentences and everyday words

Aim for a reading level that most adults handle comfortably. Replace "unauthorized actor" with "someone who should not have had access." Replace "exfiltrated" with "copied." Avoid acronyms, or spell them out.

Lead with what matters most

Open with the single most important fact: that information about the recipient was involved in a security incident. Do not bury it under apologies or background. People should understand within the first two sentences why they received the letter.

Be specific about what was involved

Vague statements like "some personal information" raise anxiety. Say exactly which categories were affected. If you are still investigating, say that, and promise a follow-up when you know more.

Give clear, practical steps

Tell readers what they can do, in a short numbered list. Typical steps include watching statements and explanation-of-benefits notices, placing a fraud alert or credit freeze, and reporting suspicious activity. If you are offering credit monitoring or identity protection services, explain how to sign up.

Tone choices

Be direct and accountable

Take responsibility without drama. A sentence such as "We are sorry this happened, and we take our responsibility to protect your information seriously" is enough. Avoid blaming the attacker as an excuse or minimizing the event with phrases like "out of an abundance of caution," which can read as dismissive.

Do not overpromise

Never write "your information is completely safe now" unless you can prove it. It is better to describe what you have done: closed the access, brought in outside specialists, and strengthened controls.

Be human

Letters signed by the administrator or executive director, with a real phone number answered by a real person, feel different from anonymous legal notices. Consider that many recipients are elderly, so use a readable font size and avoid dense blocks of text.

Practical considerations

Authorized representatives. Residents with cognitive impairment may have a family member or legal representative who should receive the letter.

Accessibility. Consider large print and translations for the languages your community speaks.

Call center readiness. Prepare staff and a script before letters arrive. Families will call, and they should receive consistent, kind answers.

Consistency. Make sure the letter, your website notice if one is required, and any media statement all say the same thing.

Record keeping. Keep copies of what was sent, when, and to whom.

A simple outline to follow

What happened, in two or three sentences

What information was involved

What we are doing

What you can do

How to reach us

If your draft cannot be summarized on those five lines, it is probably too complicated.

Prepare before you need it

The worst time to write a notification letter is during an incident. Draft a template now, have counsel review it, and decide who signs and who answers the phone. UnityCare IT helps healthcare organizations build incident response plans that include communication steps like these, so the technical response and the human one move together.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172