Skip to main content
Category: Breach Notification

Notification Content Requirements

Also known as: Breach Notification Content, Individual Notice Content Requirements
Simply put

Notification Content Requirements are the specific pieces of information that must be included when a covered entity tells individuals about a breach of their unsecured protected health information. At a minimum, the notice must explain what happened, what information was involved, and what people should do to protect themselves. These requirements aim to give affected individuals enough detail to understand the incident and respond to it.

Formal definition

Under the HIPAA Breach Notification Rule, the content elements a covered entity must include in notifications to affected individuals following a breach of unsecured protected health information are specified at 45 CFR § 164.404. To the extent possible, the notification must include a brief description of what happened, including the date of the breach and the date of its discovery (where known); notification of the events and types of information involved must be provided along with recommended steps individuals can take to protect themselves, information about what the covered entity is doing to investigate and mitigate, and contact procedures for individuals to obtain further information. Practitioners should note that this entry addresses the content of individual notice specifically and does not cover timing, method of delivery, media notice, or notification to HHS OCR, which are addressed by related provisions of the Rule. State breach notification laws (as surveyed across all 50 states and the District of Columbia) may impose additional or different content requirements, so applicable state law should be reviewed alongside the federal requirements. Verify the specific enumerated elements against the current regulatory text of 45 CFR § 164.404.

Why it matters

When a breach of unsecured protected health information occurs, the notice sent to affected individuals is often their only window into what happened to their data and what they can do about it. Notification Content Requirements exist to ensure that this communication is substantive rather than a vague acknowledgment: individuals need to understand what information was involved and what protective steps they can take, such as monitoring accounts or requesting a credit freeze. A notice that omits required elements can leave individuals unable to respond effectively and can expose the covered entity to enforcement scrutiny from HHS OCR.

Content requirements also matter because they interact with a broader web of obligations. Getting the substance of the notice right is a distinct question from getting the timing, delivery method, media notice, or HHS notification right, and a covered entity can satisfy one while falling short on another. Because content is one of the more visible and reviewable aspects of a breach response, it is frequently examined after the fact when regulators or affected individuals evaluate whether an organization handled an incident responsibly.

Finally, the federal content elements are a floor, not a ceiling. All 50 states and the District of Columbia have enacted breach notification laws, and these may impose additional or different content requirements. A notice drafted to satisfy only 45 CFR § 164.404 may still be deficient under an applicable state law, so organizations generally need to reconcile federal and state requirements when preparing a notice.

Who it's relevant to

Privacy and Compliance Officers
Those responsible for breach response typically own the drafting and review of individual notices. They need to ensure each required content element under 45 CFR § 164.404 is addressed and reconciled with any additional state-law content requirements before a notice goes out.
Legal Counsel
In-house and external counsel generally review notice content to confirm it meets both the federal content elements and applicable state breach notification laws across the states where affected individuals reside, since state requirements may add to or differ from the HIPAA baseline.
Covered Entities
Covered entities bear the direct obligation to notify affected individuals following a breach of unsecured PHI. Where a business associate experiences the breach, the covered entity generally remains responsible for individual notice unless otherwise delegated, so it must ensure the content requirements are met regardless of where the incident originated.
Business Associates
While individual notice content is a covered entity obligation, business associates often supply the underlying breach details, what happened, dates, and information types, that populate the required content elements. The allocation of notification responsibilities is typically governed by the business associate agreement.
Incident Response and Communications Teams
Staff coordinating breach communications need to understand that a compliant notice must convey specific substance, not just reassurance, and that content requirements are separate from timing, delivery, and HHS reporting obligations addressed elsewhere in the Rule.

Inside Notification Content Requirements

Description of the Breach
A brief account of what happened, generally including the date of the breach and the date of its discovery, if those dates are known.
Types of Information Involved
A description of the categories of unsecured protected health information involved in the breach (for example, whether names, Social Security numbers, dates of birth, addresses, account numbers, diagnoses, or other data elements were affected), without necessarily disclosing the specific information itself.
Steps Individuals Should Take
Guidance on measures affected individuals can take to protect themselves from potential harm resulting from the breach.
Covered Entity's Response
A brief description of what the covered entity is doing to investigate the breach, mitigate harm to individuals, and protect against further breaches.
Contact Information
Contact procedures for individuals to ask questions or learn additional information, which generally includes a toll-free telephone number, an email address, website, or postal address.

Common questions

Answers to the questions practitioners most commonly ask about Notification Content Requirements.

Does providing individuals with prompt notice of a breach satisfy all of an organization's notification obligations?
No. Notifying affected individuals is only one component. The Breach Notification Rule generally also requires, depending on the circumstances, notification to HHS OCR and, for breaches affecting a threshold number of residents of a state or jurisdiction, notification to prominent media outlets. Individual notice with all required content elements does not by itself discharge these separate obligations. Timing, recipients, and content each carry their own requirements, and readers should verify current specifics against the applicable regulatory text.
If a vendor experiences a breach, is that vendor solely responsible for sending the required notifications?
Not necessarily. A business associate that discovers a breach is generally obligated to notify the covered entity, but the responsibility for notifying affected individuals typically rests with the covered entity unless the parties have agreed otherwise. The specific allocation of notification duties is often addressed in the business associate agreement. Because obligations attach through these defined relationships, organizations should confirm who bears which duty before an incident occurs rather than assuming the party that experienced the breach handles all notifications.
What core content elements should generally be included in a notification to affected individuals?
Notifications generally should describe, to the extent known, what happened, including the date of the breach and the date of discovery; the types of information involved (such as names, Social Security numbers, or health information); steps individuals can take to protect themselves; what the organization is doing to investigate, mitigate harm, and prevent recurrence; and contact procedures for individuals to ask questions, typically including a toll-free number, email, website, or postal address. Confirm the precise required elements and any updates against the current regulation.
How should notifications be written so recipients can actually understand them?
Notifications are generally expected to be written in plain language so that affected individuals can understand the nature of the incident and what actions they should take. In practice this means avoiding technical or legal jargon, organizing content around the required elements, and considering accessibility and, where relevant, language needs of the affected population. State law or other frameworks may impose additional readability or translation expectations beyond HIPAA.
What content considerations apply when using substitute notice because contact information is insufficient?
When an organization lacks sufficient or up-to-date contact information for some or all affected individuals, substitute notice methods may be permitted. Even when the delivery method changes, the substantive content should still convey the required information about the breach and the steps individuals can take. Substitute notice methods generally have their own conditions, such as posting on a website or media notice and providing a toll-free number, so verify the current requirements and thresholds against the applicable regulatory text.
How can an organization prepare notification content before an incident to enable a timely response?
Many organizations maintain notification templates that pre-structure the required content elements, leaving placeholders for incident-specific facts such as dates, the information involved, and mitigation steps. Preparing draft language, contact channels, and internal review and approval workflows in advance can help meet applicable timing expectations. Because facts should be accurate and complete to the extent known at the time of notice, any template should be reviewed against the specific incident and against current regulatory requirements before it is sent.

Common misconceptions

Notification content requirements apply only to covered entities, so business associates have no content obligations.
While the individual notification is generally the responsibility of the covered entity under the Breach Notification Rule, business associates must notify the covered entity of a breach and provide the information the covered entity needs to satisfy its notification content obligations. The precise flow of these duties is typically defined in the business associate agreement, and readers should verify current regulatory text.
Meeting HIPAA's notification content elements is enough because those elements are the same everywhere.
The Breach Notification Rule sets a federal baseline for content, but state breach notification laws or the HITECH Act may impose additional content elements, different timelines, or other requirements. Practitioners should confirm applicable state law and current federal guidance rather than assuming the HIPAA content list is exhaustive.
Achieving HITRUST CSF certification satisfies the notification content requirements.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. Notification content obligations arise under the HIPAA Breach Notification Rule as enforced by HHS OCR and must be met independently of any HITRUST certification.

Best practices

Maintain a breach notification template that maps each required content element (description of the breach, types of information involved, protective steps for individuals, the entity's response, and contact information) so that no component is inadvertently omitted.
Include clear contact procedures such as a toll-free number, email address, website, or postal address so affected individuals can readily obtain additional information.
Coordinate with business associates through the business associate agreement to ensure they promptly supply the information needed to populate the notification content, since duties flow through defined relationships.
Cross-check notifications against applicable state breach notification laws and the HITECH Act, as these may require additional content or shorter timelines beyond the HIPAA baseline.
Verify content requirements, timelines, and thresholds against the current Breach Notification Rule text and HHS OCR guidance, since specifics are subject to change over time.
Document the drafting and review of each notification to demonstrate that all required elements were addressed, treating thorough content as a component of overall compliance rather than a guarantee against enforcement action.