All prompts

Draft/Featured

Draft a HIPAA breach notification letter and the record behind it

Produces the documented four-factor risk assessment, the patient letter with all five required elements, the HHS and media posture, and the state deadlines that run shorter than HIPAA's sixty days.

About 20 minintermediateHealthcare, Privacy, Regulatory

Your prompt4,997 characters

Still to fill in: Incident, dates, and forensics, Affected individuals, Containment and mitigation, State regimes to layer on HIPAA

RoleYou are a healthcare privacy lawyer who has run a dozen breach notifications and sat through two OCR compliance reviews. You write the risk assessment before the letter, because the letter is only the conclusion and the assessment is the reasoning someone audits two years later. You write to patients at an eighth-grade reading level, and you never let "out of an abundance of caution" stand in for a determination.What I needWork the incident below. Notifying party: Covered entity notifying individuals. Layer the state regimes in State regimes to layer on HIPAA on top of HIPAA.InputsIncident, dates, and forensics: Incident, dates, and forensics Affected individuals: Affected individuals Containment and mitigation: Containment and mitigationHow to work this1. Run the four factors under 45 C.F.R. § 164.402 before drafting a word of the letter and state the determination in one line. If the facts genuinely rebut the presumption, say so and stop. Do not notify to be safe without telling me that is the call and what it costs. 2. Fix the clock. Name the discovery date, the sixty-day limit under § 164.404(b), and every shorter deadline State regimes to layer on HIPAA imposes. Put the earliest at the top. 3. Draft the letter to hit the five elements of § 164.404(c)(1) in order, each a labeled paragraph, at an eighth-grade reading level, none longer than five lines. 4. Count by state. Media notice triggers at 500 residents of one State, not 500 nationwide; portal timing turns on the aggregate. Show the counts you used. 5. Say what is unknown. If forensics cannot exclude acquisition, the letter says so plainly. "No evidence of misuse" is not "we can rule it out." 6. Build the state overlay as a table: state, trigger, deadline, regulator notice, consumer reporting agency notice, content beyond HIPAA. 7. On the business associate path, write the report to the covered entity instead of the patient letter, and name which obligations stay with the covered entity regardless of the BAA.Close with these four sections, every time, without being askedAssumptions I made. The discovery date, whether the forensic findings are final, which data elements were actually in the exposed set, and whether any law in State regimes to layer on HIPAA has been amended. Mark each [verify] or [safe]. Where this is weakest. The two or three statements in the letter or assessment most likely to draw an OCR follow-up or a plaintiff's demand. Name the sentence, not "the notice generally." What only you can decide. Present each as options with tradeoffs. At minimum: notifying on a record that would support a low-probability-of-compromise determination. Notifying is the conservative call but creates a permanent portal entry, plaintiff-bar attention, and an admission you cannot walk back, while documenting no breach keeps it off the portal and rests entirely on how strong that memo looks in two years. And the monitoring offer: twelve months costs less, twenty-four is what several state AGs treat as the floor for health data. Naming the vendor publicly, and when to brief the board and the cyber carrier, are yours. What would make this materially better. Rank by impact: the final forensic report, confirmed per-state counts, the BAA's notice clause, and the address-quality report that decides whether substitute notice triggers.Output formatA privileged four-factor assessment memo with a determination; the individual letter formatted to mail, with the five elements labeled; the HHS posture with the portal timing; the media plan naming each State over 500; the substitute-notice analysis; the state overlay table; and the four closing sections.Never do this- If the letter would fit any breach at any provider, it is too generic. Name this data, these dates, this remedy. - No hedging filler. Cut "arguably," "we take your privacy seriously," and "out of an abundance of caution" used in place of a determination. Do not tell me to consult privacy counsel. I am privacy counsel. - Never invent a regulatory citation, an OCR guidance document, a state statute number, a forensic finding, or a count of affected individuals. Anything not in my inputs is marked [UNVERIFIED - confirm before mailing]. - Where the forensics do not establish whether data was acquired, say you do not know, in the memo and in the letter. Do not smooth the gap over with reassuring prose. - Do not pad the letter. Patients read the first two paragraphs and the phone number. Length is not value.Before you answer- Did I run the four factors and reach a determination before drafting? - Are all five required elements present, in order, each labeled? - Did I show the aggregate count and the per-state counts I relied on? - Does any sentence claim more certainty than the forensics support? - Would this letter fit a different incident? It should not.

Adds driver's-seat tunes: options instead of answers, questions before work, every citation flagged. Your values come with it.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

An OCR compliance review is already open off the portal entry. Read the assessment and letter as the investigator working that file. Name the two sentences in the letter that generate a follow-up request, the factor in the four-factor analysis that is thinnest and what document would fix it, and the one operational gap that turns this from a routine notice into a resolution agreement with a corrective action plan. Then rewrite those two sentences and tell me exactly what to add to the assessment.
3

Go deeper

Pushes the work further once the basics are right.

The phones start ringing the day the letters land. Write the call-center script for inbound calls from notified individuals: the opening, the eight questions people actually ask (was my prescription information seen, who saw it, will my insurance change, do I have to do anything), the answers, the three things representatives must never say, the escalation path to the privacy office, and the fields each call must log for the incident record.

Before you run it

What to gather first

  • The date of the incident and the date of discovery, and who discovered it
  • What the forensics can and cannot establish about access or acquisition
  • The exact data elements involved, and whether any are Social Security or financial
  • Counts of affected individuals by state of residence, and whether any are minors
  • Whether a business associate caused it and what the BAA says about notice

Watch for

  • The four-factor analysis is the document OCR asks for first. Write it before the letter and keep it privileged and dated. A determination reconstructed after the fact does not hold up.
  • State deadlines frequently run shorter than HIPAA's sixty days, and several require separate AG or consumer reporting agency notice on their own clocks. Track each state independently.
  • Media notice triggers at 500 residents of a single State or jurisdiction, not 500 in total. The model will conflate the two if the per-state counts are not in your inputs.
  • Do not put PHI or the word "breach" on the envelope or in any window field, and check the return address. A privacy-office return line can itself identify the recipient.
  • Ransomware and encryption events carry their own OCR interpretive posture. If that is the incident, confirm the current guidance before relying on any rebuttal analysis here.

What comes back

A privileged four-factor risk assessment memo ending in a stated determination; the individual notification letter formatted to mail with the five § 164.404(c)(1) elements labeled; the HHS notification posture and portal timing; the media notification plan naming each State with 500 or more affected residents; the substitute-notice analysis; a state overlay table with deadlines, AG and consumer reporting agency notice, and content deltas; and the four collaboration sections.

See an example of what you’ll get
Earliest deadline: Wednesday, April 29, 2026: the California fifteen-business-day clock from discovery, not HIPAA's sixty days. THE ARITHMETIC, because you are going to check it. Discovery was Wednesday, April 8, 2026. Counting business days from the next day, with no state holiday in the window: Apr 9–10 is two, Apr 13–17 is seven, Apr 20–24 is twelve, Apr 27–29 is fifteen. Fifteenth business day = Wednesday, April 29, 2026. HIPAA's sixty calendar days from April 8 run to Sunday, June 7, 2026, thirty-nine days later, and irrelevant to your real deadline. [UNVERIFIED - confirm that the fifteen-business-day period reaches this entity type, and that it is business days and not calendar days. On a calendar-day reading the date is April 23 and the letters have to be in the mail six days sooner.] PART 1: FOUR-FACTOR ASSESSMENT (PRIVILEGED). Discovery date April 8, 2026. - *Factor 1, nature and extent.* Name, date of birth, prescription history, prescriber name. No SSN or financial data. Prescription history is sensitive and re-identifiable; moderate-to-high. - *Factor 2, unauthorized person.* The public internet: an unbounded class. One researcher identified; the other 22 access events are unattributed. - *Factor 3, actual acquisition or viewing.* 23 access events logged. No bulk-download signature. Acquisition by others over 45 days cannot be excluded. - *Factor 4, mitigation.* Closed within four hours, logs preserved, no observed downstream use, 24 months of monitoring offered. - Determination: breach. Forty-five days of open public exposure defeats a low-probability-of-compromise rebuttal on this record. Notification proceeds. PART 2: INDIVIDUAL LETTER (excerpt). Subject: Important information about your records at Northshore Pharmacy *What happened.* On April 8, 2026, our service provider found that a storage setting had been left open, which allowed some patient records to be reached from the internet between February 22 and April 8, 2026. The setting was corrected within four hours. Your records were among those that could be reached. *What information was involved.* Your name, date of birth, prescription history, and the name of the doctor who prescribed your medication. Your Social Security number and payment information were not in these records. *What we know and what we do not.* Our investigation found 23 times when someone opened the records. We did not find evidence that records were copied in bulk. We cannot be certain that no one else saw your information. PART 3: HHS. Aggregate 4,300: contemporaneous submission on the OCR portal with the individual mailing. [UNVERIFIED - confirm the current portal field set before filing.] PART 4: MEDIA. California (1,150) and New York (612) each exceed 500 residents and require notice to prominent outlets serving those states. No other state reaches the threshold. PART 6: STATE OVERLAY (excerpt). | State | Trigger | Deadline | Regulator notice | CRA notice | |---|---|---|---|---| | California | 1,150 residents | 15 business days from discovery → Apr 29, 2026 [UNVERIFIED - confirm the period and that it applies here]; § 1798.82: without unreasonable delay | AG submission required, 500+ residents | Not triggered | | New York | 612 residents | Without unreasonable delay | AG, DOS, and State Police | Only above 5,000 | --- Assumptions I made. The April 8 discovery date is the date the entity first knew or should have known [verify - if the researcher emailed earlier and it sat in an inbox, every date above moves back with it and April 29 may already be gone]. The forensic count of 23 is final [verify]. No SSNs were in the exposed set [verify against the actual field schema, not the data dictionary]. Where this is weakest. The sentence "we did not find evidence that records were copied in bulk." It is true and it is the sentence a plaintiff will quote next to the 45-day exposure window. It stays, but expect it back. What only you can decide. Whether to notify the roughly 80 minors' guardians separately with tailored language. Separate letters are the better patient experience and generate a second wave of calls and a second chance to say something wrong. And the monitoring term: 12 months costs about half, but the California AG has treated 24 as the floor for health data, and you have already told the researcher what you are offering. Naming BlueRiver in the press statement, and when to notify the cyber carrier, are yours. What would make this materially better. (1) The email header showing when the researcher first made contact: it sets the discovery date, and therefore every deadline above. (2) Confirmed per-state counts from the mailing file. (3) The BAA's notice clause. (4) The address-quality report, which decides whether substitute notice is triggered.
Why this prompt is built the way it is
## Framework 1. **Assessment before letter.** The four factors under 45 C.F.R. § 164.402 decide whether there is a breach at all. Write that analysis down and reach a determination. 2. **The clock starts at discovery.** Sixty calendar days is the outer limit under § 164.404(b), not the plan. Several state laws run shorter. 3. **Five elements, every time.** What happened, what information was involved, what individuals should do, what the entity is doing, and how to reach a human. § 164.404(c)(1). 4. **Count by state, not in total.** Media notice triggers at 500 residents of one State or jurisdiction. The HHS portal timing turns on the aggregate. 5. **State what is unknown.** "No evidence of misuse" is not the same as "we can rule it out," and OCR reads the difference. 6. **State overlays are cumulative.** AG notice, consumer reporting agency notice, and content requirements that exceed HIPAA, each on its own deadline. 7. **Business associate reports up, covered entity notifies out.** The covered entity's obligation to individuals does not transfer.