When protected health information is breached, the legal clock starts and a difficult task follows: writing to the people affected. Many organizations hand this to a lawyer or a template and send out a letter that is technically compliant but unreadable. For residents and their families, often older adults or adult children already worried about care, clarity matters as much as compliance.
This article covers what a notification letter must contain, how to write it in plain language, and the tone choices that make the difference between reassurance and alarm. It is general information, not legal advice. Your counsel should review any letter before it goes out.
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach. The notice must be written in plain language and generally include:
A brief description of what happened, including the date of the breach and the date of discovery, if known
The types of information involved, such as names, Social Security numbers or diagnoses
Steps individuals should take to protect themselves
What your organization is doing to investigate, reduce harm and prevent recurrence
Contact information for questions
State laws may add requirements or shorter deadlines, so your attorney should confirm what applies to residents in each state you serve.
Aim for a reading level that most adults handle comfortably. Replace "unauthorized actor" with "someone who should not have had access." Replace "exfiltrated" with "copied." Avoid acronyms, or spell them out.
Open with the single most important fact: that information about the recipient was involved in a security incident. Do not bury it under apologies or background. People should understand within the first two sentences why they received the letter.
Vague statements like "some personal information" raise anxiety. Say exactly which categories were affected. If you are still investigating, say that, and promise a follow-up when you know more.
Tell readers what they can do, in a short numbered list. Typical steps include watching statements and explanation-of-benefits notices, placing a fraud alert or credit freeze, and reporting suspicious activity. If you are offering credit monitoring or identity protection services, explain how to sign up.
Take responsibility without drama. A sentence such as "We are sorry this happened, and we take our responsibility to protect your information seriously" is enough. Avoid blaming the attacker as an excuse or minimizing the event with phrases like "out of an abundance of caution," which can read as dismissive.
Never write "your information is completely safe now" unless you can prove it. It is better to describe what you have done: closed the access, brought in outside specialists, and strengthened controls.
Letters signed by the administrator or executive director, with a real phone number answered by a real person, feel different from anonymous legal notices. Consider that many recipients are elderly, so use a readable font size and avoid dense blocks of text.
Authorized representatives. Residents with cognitive impairment may have a family member or legal representative who should receive the letter.
Accessibility. Consider large print and translations for the languages your community speaks.
Call center readiness. Prepare staff and a script before letters arrive. Families will call, and they should receive consistent, kind answers.
Consistency. Make sure the letter, your website notice if one is required, and any media statement all say the same thing.
Record keeping. Keep copies of what was sent, when, and to whom.
What happened, in two or three sentences
What information was involved
What we are doing
What you can do
How to reach us
If your draft cannot be summarized on those five lines, it is probably too complicated.
The worst time to write a notification letter is during an incident. Draft a template now, have counsel review it, and decide who signs and who answers the phone. UnityCare IT helps healthcare organizations build incident response plans that include communication steps like these, so the technical response and the human one move together.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172