HIPAA breach notification mailing

HIPAA breach notification mailing, clause by clause.

The HIPAA Breach Notification Rule is specific about how individual notice goes out — the method, the timing, and what the letter has to contain. Here is each mailing-relevant requirement, what production has to do about it, and which parts remain counsel's call.

The question this page answers

Will the mailing satisfy what the Breach Notification Rule actually requires?

60 days

Outer limit for individual notice after discovery of a breach of unsecured PHI — and the rule also requires no unreasonable delay.

500 threshold

At 500 or more individuals, HHS notice is contemporaneous with individual notice, and media notice can be triggered per state.

The 60 days is not a production window. Forensics, review, and drafting normally consume 45 or more of it. What is left is the mailing — and that is the part we make short.

The requirements

What the rule says about getting the letter out.

Citations are to 45 CFR Part 164, Subpart D. They are here so your compliance reviewer can check our work — not as legal advice.

Timing

§ 164.404(b)

Individual notice must go out without unreasonable delay and no later than 60 calendar days after discovery of the breach. Because "without unreasonable delay" is independent of the 60-day cap, a mailing that sits in a production queue for three weeks is a problem even inside the window.

What we do: date-stamped intake, acknowledgment within two business hours, and a documented mail date on the affidavit — so the elapsed time between a final list and deposit with USPS is a matter of record rather than an argument.

Method

§ 164.404(d)(1)(i)

Written notification by first-class mail to the individual's last known address — or by email if the individual has agreed to electronic notice. Notice may be provided in one or more mailings as information becomes available.

What this means practically: the rule does not require Certified Mail. First-Class satisfies the method requirement. Certified is an evidentiary and business decision, not a HIPAA one — we cover that trade-off on the Certified Mail page. The "one or more mailings" language is also why a supplemental mailing for late-identified individuals is normal rather than a defect.

Content

§ 164.404(c)(1)

To the extent possible, the notice must include: a brief description of what happened, including the date of the breach and the date of discovery; the types of unsecured PHI involved; steps individuals should take to protect themselves; a brief description of what the covered entity is doing to investigate, mitigate harm, and protect against further breaches; and contact procedures, including a toll-free number, email address, website, or postal address.

What we do: we do not write these elements — counsel does. We do compose them into a letter where each element is visually findable rather than buried, and we can run a completeness check against the five elements as a courtesy before proofs go out. Confirmation that the content is legally sufficient stays with counsel.

Plain language

§ 164.404(c)(2)

The notification must be written in plain language.

What we do: compose to a 6th–8th grade reading level by default — short sentences, defined terms, no defensive legal register — and flag passages that read above it during proofing. Wording changes are counsel's to accept or decline.

Deceased individuals

§ 164.404(d)(1)(ii)

Where the covered entity knows an individual is deceased and has an address for the next of kin or personal representative, written notice goes by first-class mail to that person instead.

What we do: deceased suppression flags likely decedents in the exception report so they are not silently mailed as if living, and composition supports an estate or personal-representative addressee line. Whether the rule's knowledge condition is met for a given record is your determination, not a file-processing result.

Substitute notice

§ 164.404(d)(2)

Where contact information is insufficient or out of date and precludes written notice, substitute notice applies: for fewer than 10 individuals, an alternative written form, telephone, or other means; for 10 or more, either a conspicuous posting for 90 days on the home page of the covered entity's website or notice in major print or broadcast media where affected individuals likely reside, together with a toll-free number active for at least 90 days.

What we do: supply the numbers the decision rests on — how many addresses were undeliverable, why, and which ones survived re-lookup — through return-mail management. We do not place media notice or post to your website.

Urgent cases

§ 164.404(d)(3)

Where there is possible imminent misuse of unsecured PHI, the covered entity may notify by telephone or other means in addition to the written notice.

What we do: nothing — this is a client channel. It is here because it is a common source of confusion: telephone contact supplements the mailing, it does not replace it.

Media notice

§ 164.406

For a breach affecting more than 500 residents of a state or jurisdiction, notice to prominent media serving that area is required, without unreasonable delay and no later than 60 days after discovery.

What we do: report per-state counts off the processed file so counsel can see which jurisdictions cross the threshold. Placement is handled by the client or its communications counsel.

HHS notice

§ 164.408

Breaches involving 500 or more individuals are reported to the Secretary contemporaneously with individual notice. Breaches involving fewer than 500 are logged and submitted annually, within 60 days after the end of the calendar year.

What we do: provide the mailing date and final counts that the submission relies on. The submission itself is made by the covered entity.

Business associates

§ 164.410

A business associate that discovers a breach notifies the covered entity without unreasonable delay and no later than 60 days after discovery.

Where we sit: when we handle PHI for a mailing, we are a business associate — and our BAA carries these obligations. In practice that means our own incident reporting runs to you on a defined timeline, and it is one of the questions your vendor reviewer will ask. The answer is on the Security & Compliance page.

Division of labor

Who owns which requirement.

Vendor confusion on this table is how deadlines get missed. Print it and put it in the matter file.

ObligationOwnerOur contribution
Is it a breach?Covered entity & counselNone
Who is affectedForensics / data miningAccept the finalized list
Letter contentCounselCompose, proof, element check
Plain languageCounselDraft to 6th–8th grade, flag exceptions
First-class mailingNotifyCertainPrint, insert, deposit, document
Address currencySharedCASS, NCOA, exception report
Proof of mailingNotifyCertainAffidavit, manifest, USPS records
Substitute noticeCovered entity & counselUndeliverable counts and reasons
Media noticeCovered entityPer-state counts
HHS submissionCovered entityMail date and final counts

Where state law changes the mailing, not just the letter

Almost every HIPAA matter is also a state matter, and state breach statutes are not harmonized with the federal rule. Deadlines in several states run shorter than 60 days. Some states prescribe content elements HIPAA does not, or require specific disclosures when Social Security numbers are involved. A few require notice to a state regulator on a different clock than HHS.

Counsel resolves which requirements apply. What that resolution does to production is our problem, and it usually shows up in one of three ways:

  • The shortest clock governs the mail date. If one state runs 30 days, the whole mailing moves to that date unless counsel splits it by jurisdiction — which we can do, with separate manifests and affidavits per wave.
  • State content becomes a letter version. Extra disclosures for particular states are handled as versions or inserts driven off the state field, not by mailing one letter to everyone and hoping. See multi-population letters.
  • Per-state counts drive threshold decisions. Media notice and regulator notice thresholds are counted by state, so we report the file that way from the start.

We do not track or advise on state notification statutes. We build the production plan around the determinations counsel gives us.

The PHI handling question your privacy officer will ask

Recipient files in a HIPAA matter are PHI, and a mailing vendor is a real exposure surface. Ours is deliberately narrow: a BAA executed before intake, encrypted portal or SFTP transfer with no recipient data by email, role-based access scoped to the matter team, logging designed so recipient identifiers do not sit in plain text outside the production environment, no subcontractors touching recipient data, and a per-matter retention and destruction schedule that runs after the return-mail window closes. Full detail, in the form a risk reviewer wants it, is on the Security & Compliance page.

Common questions

HIPAA-specific questions

Does HIPAA require Certified Mail for breach notices?

No. § 164.404(d)(1)(i) specifies first-class mail to the last known address. Certified Mail exceeds the requirement and is chosen for evidentiary or relationship reasons, not compliance ones. On large populations the cost is significant, so it is worth a deliberate decision rather than a default.

The list is still growing. Do we wait or mail in waves?

The rule expressly contemplates notice "in one or more mailings as information is available." Waves are usually the better posture: they demonstrate you mailed as soon as each population was identified rather than holding everyone for the last record. Each wave gets its own manifest and affidavit.

Can you tell us whether our letter meets the content requirements?

We will point out if one of the five elements at § 164.404(c)(1) appears to be missing — as a production courtesy, in writing, before proofs. That is a formatting observation, not a legal opinion, and counsel decides what to do with it.

We are the business associate that caused the breach. Can we mail on the covered entity's behalf?

Commonly, yes — where the covered entity delegates it and the arrangement is documented. We will need to know whose letterhead the notice carries and who the affidavit names as the mailing party, because those follow the delegation rather than who is paying us.

How do you handle addresses we know are stale?

NCOALink updates records with a filed move; CASS validates deliverability. Records that survive neither surface in the exception report before printing, which is exactly the population that later drives the substitute-notice analysis. Nothing is dropped without your written instruction.

Do you keep PHI after the mailing?

Only what is necessary to evidence the mailing itself, per the retention schedule in the BAA and engagement. The recipient file is returned or destroyed after the return-mail window closes, and destruction is documented.

HIPAA matter on the clock?

BAA executed before intake. Acknowledged within 2 business hours.