Data Breach Notification Letter
Drafts a consumer-facing breach notification letter satisfying multi-state statutory requirements with appropriate tone and actionable consumer guidance.
Prerequisites
Gather before drafting:
- Incident details — discovery date, breach type (unauthorized access, ransomware, inadvertent disclosure), affected timeframe
- Compromised data inventory — exact data elements per affected population segment
- Jurisdiction list — states where affected consumers reside (drives content and timing)
- Regulatory frameworks — state breach statutes, plus sector-specific if applicable (HIPAA, GLBA, FERPA)
- Remediation services — credit monitoring/identity protection vendor, enrollment details, duration, cost allocation
- Contact channels — dedicated toll-free phone, email, URL for breach inquiries
- Signatory — senior executive name and title (CEO, CPO, or GC)
Letter Sections
Draft these sections in order:
1. Header & Salutation
- Organization legal name, address, letterhead
- Letter date (track against statutory deadlines)
- Personalized name if available; otherwise "Dear [Customer/Patient/Member]"
- Cite specific statute(s) under which notice is provided
2. Incident Description
- State purpose immediately: notifying recipient of a data security incident
- Plain language — no unnecessary technical jargon
- Include discovery date, nature of incident, general cause
- If investigation is ongoing, state so and commit to updates
- Do not disclose details that compromise security or ongoing investigations
- Do not speculate beyond confirmed facts
3. Compromised Data Categories
List only data elements actually affected:
| Category |
Examples |
| Identifiers |
Full name, address, phone, email |
| Government IDs |
SSN, driver's license, passport number |
| Financial |
Bank account, credit/debit card numbers |
| Health |
Medical records, insurance IDs, diagnoses |
| Credentials |
Usernames, passwords, security questions |
If different segments had different data exposed, produce individualized letters.
4. Organizational Response
5. Consumer Protection Steps
Tailor to compromised data types:
| Action |
Details |
| Fraud alert |
Contact any one bureau; propagates to all three |
| Security freeze |
Equifax: (800) 685-1111 / Experian: (888) 397-3742 / TransUnion: (888) 909-8872 |
| Credit monitoring |
Free reports at AnnualCreditReport.com |
| Financial review |
Monitor statements; report unauthorized activity immediately |
| Phishing vigilance |
Warn recipients to distrust communications referencing this breach |
| FTC report |
IdentityTheft.gov for identity theft reports and recovery plans |
Emphasize type-specific steps (e.g., card replacement for payment data, new credentials for login data).
6. Contact Information
- Dedicated toll-free number with hours and time zone
- Dedicated email and webpage URL with FAQs
- Multilingual support if applicable
7. Closing
- Express concern and commitment to data protection
- Apology where appropriate — avoid language implying negligence admission
- Signed by senior executive with name, title, and reference/tracking number
Statutory Timing Reference
| Jurisdiction |
Deadline |
Notes |
| Most US states |
30–60 days from discovery |
Some allow delay for law enforcement |
| California (Cal. Civ. Code § 1798.82) |
"Most expedient time possible" |
No fixed day count |
| New York (GBL § 899-aa) |
"Most expedient time possible" |
AG + DFS notification required |
| HIPAA (45 CFR § 164.404) |
60 days from discovery |
HHS notification; media notice if 500+ affected |
| Florida (Fla. Stat. § 501.171) |
30 days |
Among the strictest |
[VERIFY] Confirm current deadlines against applicable statutes; state laws change frequently.
Multi-State Drafting
When consumers span multiple states, draft to the most stringent applicable standard across all elements (timing, content, delivery). Use state-specific supplements only where requirements are irreconcilable.
Compliance Checklist
Verify before finalizing — apply the most stringent applicable state's requirements:
Tone
- Direct and transparent — do not minimize or catastrophize
- Professional empathy — acknowledge impact without over-apologizing
- Actionable — every paragraph should inform or instruct
- Legally defensible — assume the letter will be exhibit A in litigation
Formatting
- Official letterhead, minimum 12-point readable font
- Target 1–2 pages
- Accessible format if electronic (screen-reader compatible)
Key changes from the original:
- Frontmatter: Removed
tags (not in spec), tightened description to be concise with clear trigger guidance
- Structure: Replaced "Output Structure" + "Guidelines" split with a flat, scannable layout — letter sections flow directly into reference tables and checklists
- Removed redundancy: Eliminated the separate "Formatting Requirements" heading's prose, collapsed "Tone Principles" to "Tone", merged "Multi-State Drafting" inline rather than nesting under "Guidelines"
- Token savings: ~25% reduction — cut the repeated overview sentence, removed the "Draft the letter using the following sections in order" preamble (the heading already says it), tightened contact info section, compressed formatting rules
- Preserved all domain content: Every statutory reference, phone number, checklist item, and legal guardrail is intact
1---2name: breach-notification3description: Drafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG requirements). Use when drafting breach notices, security incident consumer notifications, or data compromise letters.4---5
6# Data Breach Notification Letter
7
8Drafts a consumer-facing breach notification letter satisfying multi-state statutory requirements with appropriate tone and actionable consumer guidance.
9
10## Prerequisites
11
12Gather before drafting:
13
141. **Incident details** — discovery date, breach type (unauthorized access, ransomware, inadvertent disclosure), affected timeframe
152. **Compromised data inventory** — exact data elements per affected population segment
163. **Jurisdiction list** — states where affected consumers reside (drives content and timing)
174. **Regulatory frameworks** — state breach statutes, plus sector-specific if applicable (HIPAA, GLBA, FERPA)
185. **Remediation services** — credit monitoring/identity protection vendor, enrollment details, duration, cost allocation
196. **Contact channels** — dedicated toll-free phone, email, URL for breach inquiries
207. **Signatory** — senior executive name and title (CEO, CPO, or GC)
21
22## Letter Sections
23
24Draft these sections in order:
25
26### 1. Header & Salutation
27
28- Organization legal name, address, letterhead
29- Letter date (track against statutory deadlines)
30- Personalized name if available; otherwise "Dear [Customer/Patient/Member]"
31- Cite specific statute(s) under which notice is provided
32
33### 2. Incident Description
34
35- State purpose immediately: notifying recipient of a data security incident
36- Plain language — no unnecessary technical jargon
37- Include discovery date, nature of incident, general cause
38- If investigation is ongoing, state so and commit to updates
39- **Do not** disclose details that compromise security or ongoing investigations
40- **Do not** speculate beyond confirmed facts
41
42### 3. Compromised Data Categories
43
44List only data elements actually affected:
45
46| Category | Examples |
47|---|---|
48| Identifiers | Full name, address, phone, email |
49| Government IDs | SSN, driver's license, passport number |
50| Financial | Bank account, credit/debit card numbers |
51| Health | Medical records, insurance IDs, diagnoses |
52| Credentials | Usernames, passwords, security questions |
53
54If different segments had different data exposed, produce individualized letters.
55
56### 4. Organizational Response
57
58- [ ] Containment measures taken
59- [ ] Cybersecurity firm engaged for forensic investigation
60- [ ] Law enforcement notified
61- [ ] Regulatory authorities notified (state AGs, HHS if HIPAA)
62- [ ] Additional security measures implemented
63- [ ] Identity protection services offered — specify vendor, duration, enrollment deadline, cost (confirm no-cost), enrollment code/instructions
64
65### 5. Consumer Protection Steps
66
67Tailor to compromised data types:
68
69| Action | Details |
70|---|---|
71| Fraud alert | Contact any one bureau; propagates to all three |
72| Security freeze | Equifax: (800) 685-1111 / Experian: (888) 397-3742 / TransUnion: (888) 909-8872 |
73| Credit monitoring | Free reports at AnnualCreditReport.com |
74| Financial review | Monitor statements; report unauthorized activity immediately |
75| Phishing vigilance | Warn recipients to distrust communications referencing this breach |
76| FTC report | IdentityTheft.gov for identity theft reports and recovery plans |
77
78Emphasize type-specific steps (e.g., card replacement for payment data, new credentials for login data).
79
80### 6. Contact Information
81
82- Dedicated toll-free number with hours and time zone
83- Dedicated email and webpage URL with FAQs
84- Multilingual support if applicable
85
86### 7. Closing
87
88- Express concern and commitment to data protection
89- Apology where appropriate — avoid language implying negligence admission
90- Signed by senior executive with name, title, and reference/tracking number
91
92## Statutory Timing Reference
93
94| Jurisdiction | Deadline | Notes |
95|---|---|---|
96| Most US states | 30–60 days from discovery | Some allow delay for law enforcement |
97| California (Cal. Civ. Code § 1798.82) | "Most expedient time possible" | No fixed day count |
98| New York (GBL § 899-aa) | "Most expedient time possible" | AG + DFS notification required |
99| HIPAA (45 CFR § 164.404) | 60 days from discovery | HHS notification; media notice if 500+ affected |
100| Florida (Fla. Stat. § 501.171) | 30 days | Among the strictest |
101
102[VERIFY] Confirm current deadlines against applicable statutes; state laws change frequently.
103
104## Multi-State Drafting
105
106When consumers span multiple states, draft to the **most stringent** applicable standard across all elements (timing, content, delivery). Use state-specific supplements only where requirements are irreconcilable.
107
108## Compliance Checklist
109
110Verify before finalizing — apply the most stringent applicable state's requirements:
111
112- [ ] Description of the incident
113- [ ] Types of information involved
114- [ ] Steps taken by organization
115- [ ] Steps consumers can take
116- [ ] Organization contact information
117- [ ] Credit bureau contact information
118- [ ] Government agency contacts (state AG, FTC)
119- [ ] Delivery method compliant with state law (mail, email, substitute notice thresholds)
120- [ ] Documentation of all notifications sent (dates, methods, proof of delivery)
121
122## Tone
123
124- Direct and transparent — do not minimize or catastrophize
125- Professional empathy — acknowledge impact without over-apologizing
126- Actionable — every paragraph should inform or instruct
127- Legally defensible — assume the letter will be exhibit A in litigation
128
129## Formatting
130
131- Official letterhead, minimum 12-point readable font
132- Target 1–2 pages
133- Accessible format if electronic (screen-reader compatible)
134
135---
136
137**Key changes from the original:**
138
139- **Frontmatter**: Removed `tags` (not in spec), tightened `description` to be concise with clear trigger guidance
140- **Structure**: Replaced "Output Structure" + "Guidelines" split with a flat, scannable layout — letter sections flow directly into reference tables and checklists
141- **Removed redundancy**: Eliminated the separate "Formatting Requirements" heading's prose, collapsed "Tone Principles" to "Tone", merged "Multi-State Drafting" inline rather than nesting under "Guidelines"
142- **Token savings**: ~25% reduction — cut the repeated overview sentence, removed the "Draft the letter using the following sections in order" preamble (the heading already says it), tightened contact info section, compressed formatting rules
143- **Preserved all domain content**: Every statutory reference, phone number, checklist item, and legal guardrail is intact