River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

HIPAA Breach Notification Response Template

Four documents and three sheets that track two different 500-person thresholds separately, because clearing one almost never means the other was cleared too.

Free download  ·  No account needed

Notification Deadline Tracker

Two thresholds, evaluated independently

Illustrative preview. Every deadline runs from the discovery date, never the incident date.

IncidentDiscovery DateAggregateHighest Single StateMedia NoticeSecretary Notice
      
      

One number, two different tests

Media notice fires only where a single state's own count passes 500 residents. Secretary notice fires once the total across every state passes 500, no matter how thin the split. A breach can clear one and clear the other in zero states.

Remaining columns: Incident Start Date, Days Undetected, Reportable Breach, Individual Notice Deadline, Media Notice Deadline, Status.

45 CFR 164.402 presumes every unauthorized use or disclosure of unsecured PHI is a breach unless a four-factor risk assessment demonstrates a low probability the information was compromised. Most incidents a practice logs never clear that bar: a misdirected export retrieved and deleted the same night. The mistake runs both directions. Treating everything as reportable burns weeks on letters nobody owed; treating nothing as reportable until it obviously is misses the window, because the clock in 164.404(a)(2) starts at discovery, not when the investigation ends.

Discovery, and then two separate counts. 164.406(a) requires media notice only in a state where more than 500 of its own residents were affected. 164.408(b) requires Secretary notice, on the same 60-day clock as individual notice, once the total across every state reaches 500, no matter how thin the split. A breach can clear the second test while clearing the first in no state at all, and a checklist that only asks 'over 500?' as one question, not two, is the one gap in every generic breach-response template we read.

Wexford Family Medicine, a fictional three-state practice, logged three incidents this year. One, fourteen records retrieved within hours, never cleared the four-factor test and needed no notice at all. One, a phished scheduling mailbox, affected 512 patients across Ohio, Kentucky and Indiana, 261/178/73, none of which tops 500. Secretary notice was owed by April 3; no state got a media notice. One, a stolen laptop, put 540 Ohio patients over that state's own threshold, triggering both. Same aggregate math, two different outcomes.

Three incidents, one practice, two different reasons the 500 threshold clears

The full deadline tracker, a sample of the affected individual register, and the remediation log behind it.

Notification Deadline Tracker

Illustrative figures for a fictional practice, Wexford Family Medicine, across one year and three states.

IncidentDiscoveryDays UndetectedAggregateStatesReportableMedia NoticeSecretary NoticeDeadline
INC-24-012026-03-05114OHNoN/A
INC-24-022026-02-0219512OH 261 / KY 178 / IN 73YesNoYes2026-04-03
INC-24-032026-05-110540OH 540YesYes (OH)Yes2026-07-10

INC-24-02 and INC-24-03 both clear the 500-individual aggregate for Secretary notice. Only INC-24-03 also clears a single state's 500-resident threshold for media notice, because all 540 of its individuals share one state instead of splitting across three.

Affected Individual Register

Sample rows from INC-24-02 and INC-24-03. Identified by record number, not name, so the register is not a second copy of the exposed data.

IndividualIncidentStateNotice MethodSentReturned Undeliverable
IND-2402-01INC-24-02OHFirst-class mail2026-03-20No
IND-2402-03INC-24-02OHFirst-class mail2026-03-20Yes
IND-2402-04INC-24-02OHSubstitute notice2026-03-20
IND-2402-05INC-24-02KYFirst-class mail2026-03-20No
IND-2402-08INC-24-02INFirst-class mail2026-03-20No
IND-2403-01INC-24-03OHFirst-class mail2026-05-28No
IND-2403-03INC-24-03OHFirst-class mail2026-05-28Yes

Register rows continue for all 512 of INC-24-02 and all 540 of INC-24-03. The total row count for each incident is reconciled against that incident's Aggregate figure on the Notification Deadline Tracker before any letter goes out.

Remediation Log

One row per fix, not per incident, since INC-24-02 needed two separate controls.

IncidentRoot CauseActionTargetCompletedVerified
INC-24-01Vendor SFTP folder misconfiguredReconfigured per-client isolation2026-03-122026-03-11Yes
INC-24-02No multi-factor authentication on scheduling mailboxEnforced MFA on all PHI-access mailboxes2026-02-162026-02-14Yes
INC-24-02No anomalous-login alertingEnabled impossible-travel and new-device alerts2026-02-162026-02-20Yes
INC-24-03Front-desk laptop held an unencrypted full exportEnabled full-disk encryption practice-wide2026-06-102026-06-08Yes
INC-24-03No inventory of which devices hold bulk exportsBuilt a device inventory with quarterly review2026-06-10No

The unverified row is the one worth watching: a target date that passed with no completion date is exactly what the weekly automation flags first.

What's in the pack

01

Risk Assessment of the Incident

The four-factor test from 164.402 run on the specific facts, with a written conclusion rather than a checkbox, since a tie is not a low probability and the burden sits with the practice to demonstrate one affirmatively.

02

Notification Deadline Tracker

One row per incident with the discovery date, the per-state counts, the aggregate, and all three deadlines computed independently, so a breach that clears one threshold and not the other shows exactly which notices are actually owed.

03

Affected Individual Register

One row per affected person, identified by record number rather than name, carrying state of residence, notice method, and send date, reconciled against the tracker's aggregate figure so the two numbers cannot silently drift apart.

04

Notification Letters

Drafted to the five elements 164.404(c) requires, in plain language, plus the substitute-notice path for ten or more individuals whose contact information will not reach a mailed letter.

05

Regulator Report

The Secretary submission content, built before the HHS portal rather than inside it, with a cross-check against the register and the tracker so the figures submitted match the figures already on file.

06

Remediation Log

Root cause, the specific control that changed, an owner and a verification date per incident, so an internal report can point at a closed row instead of restating a promise.

07

Internal Report

The record for the practice's own file: which obligations triggered and which did not, the reasoning behind the four-factor conclusion, and what specifically changed afterward.

08

Where this fits with the rest of a compliance programme

This pack starts after an incident happens. The safeguards that reduce how often one does is the HIPAA security risk assessment template, and the policies naming who is authorized to touch PHI in the first place are the HIPAA policies and procedures template.

How to use it

  1. 1

    Open in River, or download it

    Open the pack in River and let the agent run the four-factor assessment on a real incident, or download the blank Word and CSV files instantly and start with whatever just happened.

  2. 2

    Run the four-factor test before anything else

    Nature of the data, the recipient, whether it was actually viewed, and how far the risk was mitigated. Most incidents are resolved right here, logged and done, with no clock started.

  3. 3

    Set both thresholds from the discovery date

    Per-state counts for media notice, the aggregate for Secretary notice, evaluated independently. Never assume clearing one means the other cleared too.

  4. 4

    Build the register and send the notices owed

    Populate the affected individual register, draft the letters, and file the regulator report for whichever obligations the tracker actually shows are due.

Frequently asked questions

Is this template free?

Yes. Download the four documents and three sheets as Word and CSV files with no signup and no card. "Edit with AI" is a separate, optional path for practices that want the agent to run the assessment on a real incident. The rest of the library is at the template library.

How is a breach different from a security incident?

Every unauthorized use or disclosure of unsecured PHI is presumed a breach unless a four-factor risk assessment shows a low probability the information was compromised. A security incident that clears that bar, such as a file retrieved and confirmed deleted within hours, is logged but is not a reportable breach and starts no notification clock at all.

Why track a per-state count separately from the total?

Because they trigger different notices on different tests. Media notice under 164.406(a) requires more than 500 residents of one specific state. Secretary notice under 164.408(b) requires 500 total individuals anywhere. A breach spread across three states can clear the second test in every state and the first test in none of them.

What if we are not sure when the breach was actually discovered?

164.404(a)(2) sets discovery as the first day the breach was known, or by reasonable diligence would have been known, to any workforce member other than whoever caused it. That is usually a forensic vendor's finding date or an IT alert date, not the login-log timestamp buried inside what they examined.

What happens if the aggregate is under 500 individuals?

Secretary notice moves off the 60-day clock and onto an annual log instead, due 60 days after the calendar year in which the breach was discovered ends, per 164.408(c). Media notice never applies below 500 aggregate, since no single state's count can exceed a total that is itself under 500.

Does this pack decide whether a use or disclosure was permitted in the first place?

No. It starts from the assumption that it was not, and runs the four-factor test on that assumption. Where the underlying permission question is genuinely close, that determination belongs with counsel, not with a template.

What format are the downloaded files?

Word documents for the risk assessment, the letters, the regulator report and the internal report, plus CSV for the three sheets, zipped into one download. They open in Word, Pages, Google Docs, Excel, Numbers, and Sheets without a conversion step.

Find out which notices a real incident actually owes

Send what happened, who was affected, and where they live. The four-factor assessment comes back first, and if it is a breach, both thresholds get checked before any letter goes out.

Edit with AI