HIPAA Breach Notification Response Template
Four documents and three sheets that track two different 500-person thresholds separately, because clearing one almost never means the other was cleared too.
Free download · No account needed
Notification Deadline Tracker
Two thresholds, evaluated independently
Illustrative preview. Every deadline runs from the discovery date, never the incident date.
| Incident | Discovery Date | Aggregate | Highest Single State | Media Notice | Secretary Notice |
|---|---|---|---|---|---|
One number, two different tests
Media notice fires only where a single state's own count passes 500 residents. Secretary notice fires once the total across every state passes 500, no matter how thin the split. A breach can clear one and clear the other in zero states.
Remaining columns: Incident Start Date, Days Undetected, Reportable Breach, Individual Notice Deadline, Media Notice Deadline, Status.
45 CFR 164.402 presumes every unauthorized use or disclosure of unsecured PHI is a breach unless a four-factor risk assessment demonstrates a low probability the information was compromised. Most incidents a practice logs never clear that bar: a misdirected export retrieved and deleted the same night. The mistake runs both directions. Treating everything as reportable burns weeks on letters nobody owed; treating nothing as reportable until it obviously is misses the window, because the clock in 164.404(a)(2) starts at discovery, not when the investigation ends.
Discovery, and then two separate counts. 164.406(a) requires media notice only in a state where more than 500 of its own residents were affected. 164.408(b) requires Secretary notice, on the same 60-day clock as individual notice, once the total across every state reaches 500, no matter how thin the split. A breach can clear the second test while clearing the first in no state at all, and a checklist that only asks 'over 500?' as one question, not two, is the one gap in every generic breach-response template we read.
Wexford Family Medicine, a fictional three-state practice, logged three incidents this year. One, fourteen records retrieved within hours, never cleared the four-factor test and needed no notice at all. One, a phished scheduling mailbox, affected 512 patients across Ohio, Kentucky and Indiana, 261/178/73, none of which tops 500. Secretary notice was owed by April 3; no state got a media notice. One, a stolen laptop, put 540 Ohio patients over that state's own threshold, triggering both. Same aggregate math, two different outcomes.
What's in the pack
Risk Assessment of the Incident
The four-factor test from 164.402 run on the specific facts, with a written conclusion rather than a checkbox, since a tie is not a low probability and the burden sits with the practice to demonstrate one affirmatively.
Notification Deadline Tracker
One row per incident with the discovery date, the per-state counts, the aggregate, and all three deadlines computed independently, so a breach that clears one threshold and not the other shows exactly which notices are actually owed.
Affected Individual Register
One row per affected person, identified by record number rather than name, carrying state of residence, notice method, and send date, reconciled against the tracker's aggregate figure so the two numbers cannot silently drift apart.
Notification Letters
Drafted to the five elements 164.404(c) requires, in plain language, plus the substitute-notice path for ten or more individuals whose contact information will not reach a mailed letter.
Regulator Report
The Secretary submission content, built before the HHS portal rather than inside it, with a cross-check against the register and the tracker so the figures submitted match the figures already on file.
Remediation Log
Root cause, the specific control that changed, an owner and a verification date per incident, so an internal report can point at a closed row instead of restating a promise.
Internal Report
The record for the practice's own file: which obligations triggered and which did not, the reasoning behind the four-factor conclusion, and what specifically changed afterward.
Where this fits with the rest of a compliance programme
This pack starts after an incident happens. The safeguards that reduce how often one does is the HIPAA security risk assessment template, and the policies naming who is authorized to touch PHI in the first place are the HIPAA policies and procedures template.
How to use it
- 1
Open in River, or download it
Open the pack in River and let the agent run the four-factor assessment on a real incident, or download the blank Word and CSV files instantly and start with whatever just happened.
- 2
Run the four-factor test before anything else
Nature of the data, the recipient, whether it was actually viewed, and how far the risk was mitigated. Most incidents are resolved right here, logged and done, with no clock started.
- 3
Set both thresholds from the discovery date
Per-state counts for media notice, the aggregate for Secretary notice, evaluated independently. Never assume clearing one means the other cleared too.
- 4
Build the register and send the notices owed
Populate the affected individual register, draft the letters, and file the regulator report for whichever obligations the tracker actually shows are due.
Frequently asked questions
Is this template free?
Yes. Download the four documents and three sheets as Word and CSV files with no signup and no card. "Edit with AI" is a separate, optional path for practices that want the agent to run the assessment on a real incident. The rest of the library is at the template library.
How is a breach different from a security incident?
Every unauthorized use or disclosure of unsecured PHI is presumed a breach unless a four-factor risk assessment shows a low probability the information was compromised. A security incident that clears that bar, such as a file retrieved and confirmed deleted within hours, is logged but is not a reportable breach and starts no notification clock at all.
Why track a per-state count separately from the total?
Because they trigger different notices on different tests. Media notice under 164.406(a) requires more than 500 residents of one specific state. Secretary notice under 164.408(b) requires 500 total individuals anywhere. A breach spread across three states can clear the second test in every state and the first test in none of them.
What if we are not sure when the breach was actually discovered?
164.404(a)(2) sets discovery as the first day the breach was known, or by reasonable diligence would have been known, to any workforce member other than whoever caused it. That is usually a forensic vendor's finding date or an IT alert date, not the login-log timestamp buried inside what they examined.
What happens if the aggregate is under 500 individuals?
Secretary notice moves off the 60-day clock and onto an annual log instead, due 60 days after the calendar year in which the breach was discovered ends, per 164.408(c). Media notice never applies below 500 aggregate, since no single state's count can exceed a total that is itself under 500.
Does this pack decide whether a use or disclosure was permitted in the first place?
No. It starts from the assumption that it was not, and runs the four-factor test on that assumption. Where the underlying permission question is genuinely close, that determination belongs with counsel, not with a template.
What format are the downloaded files?
Word documents for the risk assessment, the letters, the regulator report and the internal report, plus CSV for the three sheets, zipped into one download. They open in Word, Pages, Google Docs, Excel, Numbers, and Sheets without a conversion step.
Find out which notices a real incident actually owes
Send what happened, who was affected, and where they live. The four-factor assessment comes back first, and if it is a breach, both thresholds get checked before any letter goes out.
Edit with AI