Establishing secure connection…Loading editor…Preparing document…

Health Information Privacy and Security Breach Template

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Easement Letter




Re: Easement

Dear :

Enclosed herewith please find the original Easement proposed by the City of for the property located at . The easement appears to be in proper legal form and specifically provides that the City will install and back fill around and over the culverts which you provide and waives the collection of all fees for a single connection to the sewer system. My only recommended revision is that the next to the last paragraph be modified to clearly provide that you are only releasing claims relating to the easement and not any other claims which you may have against the City of .

Please review the easement and call me with any comments you might have. Once I have heard from you, I will contact and have the easement put in final form.

I look forward to hearing from you soon.

Sincerely,

BY:

/ Enclosure

Enter text

What the Health Information Privacy and Security Breach Template Is

The Health Information Privacy and Security Breach Template is a standardized document for recording, assessing, and notifying stakeholders after an unauthorized access, use, or disclosure of protected health information (PHI). It captures incident details, affected individuals, PHI categories, mitigation actions, and recommended notifications to individuals, regulators, and partners. The template is designed to support HIPAA breach-response obligations and to produce a clear, auditable record suitable for internal review, regulatory reporting, and potential legal follow-up under federal and state rules.

Why a Structured Breach Template Matters

A consistent template ensures timely, complete documentation of PHI incidents, reduces confusion across teams, and supports compliance with HIPAA notification expectations and state breach laws. It also centralizes evidence for audits and reduces legal and regulatory risk by recording decisions and actions.

Why a Structured Breach Template Matters

Who Typically Completes This Template

Use the template when security, privacy, or compliance teams investigate suspected PHI exposure and prepare notifications.

  • Privacy/compliance teams in covered entities responsible for HIPAA breach assessments and reporting.
  • Security incident response teams documenting technical details and mitigation steps for audits.
  • Business associates, vendors, or third-party processors when their systems involve PHI and a breach occurs.

The completed template supports legal review, regulatory notices, and record retention for potential investigations.

Typical Signers and Responsible Parties

Privacy Officer

The Privacy Officer reviews incident summaries, confirms breach determinations, coordinates notifications, and documents legal bases for disclosures; they ensure the template aligns with HIPAA and organizational policy.

Security Lead

The Security Lead provides technical findings, containment and mitigation steps, and timeline of events; their signature attests to the accuracy of the forensic and corrective-action entries.

Essential Data Elements to Capture

Incident ID: Unique identifier
Date/Time: MM/DD/YYYY and time
Affected Count: Number of individuals
PHI Types: Examples: medical, billing
Breach Vector: E.g., email compromise
Mitigation: Containment steps taken

Step-by-Step: Complete the Template

Follow these ordered steps to ensure the incident record is complete, accurate, and supports required notifications.

  • 01
    Identify incident: Record when and how the event was detected.
  • 02
    Scope PHI: List PHI types and estimated affected individuals.
  • 03
    Containment: Document immediate technical and administrative actions.
  • 04
    Notify: Prepare regulator and individual notification drafts.

How to Set Up an Online Breach Workflow

Configure the digital workflow to collect signatures, enforce routing, and preserve an auditable trail for each incident record.

Field Configuration
Authentication Level Email + SMS code
Retention Policy Retain 6 years
BAA Required Yes for third-party hosts
Routing Order Privacy → Security → Legal

Technical and Platform Considerations

Use a platform that supports audit trails, strong encryption, and appropriate integrations for secure handling.

  • File Formats: PDF, DOCX supported
  • Integrations: Salesforce, NetSuite, Google Workspace
  • Security: TLS and AES-256

Verify HIPAA support and a signed BAA when PHI is stored, processed, or transmitted by third-party platforms.

Where to Send the Completed Template

Route the finalized record to internal and external recipients according to the incident severity and applicable law.

  • Internal Security: Send secured copy to the incident response team and SOC.
  • Privacy Office: Provide full template for breach determination and legal review.
  • Affected Individuals: Notify per template method and retention requirements.
  • HHS OCR / State AG: Submit required regulator notices when thresholds are met.

Key Notification Deadlines to Track

Track statutory and internal deadlines to meet HIPAA and state breach-notification requirements and to control legal exposure.

Immediate Actions:

Containment and internal notification as soon as incident is discovered.

HHS OCR Deadline:

Notify without unreasonable delay and no later than 60 days for breaches affecting 500+ individuals.

Individual Notices:

Send notices promptly; many state laws require within 30–60 days.

State AG Notices:

Some states require Attorney General notice when thresholds are exceeded.

Annual Reporting:

For breaches under federal thresholds, include in annual OCR reporting when applicable.

Common Preparation Mistakes to Avoid

  • Failing to record precise timestamps and discovery logs, which undermines incident timelines and forensic analysis.
  • Underestimating affected individual counts and later needing to amend notifications or submit supplementary reports.
  • Omitting the specific PHI types exposed, causing incomplete or misleading notification content and compliance gaps.
  • Skipping a signed BAA or failing to document third-party involvement, which increases regulatory and contractual risk.

Consequences of Incomplete or Late Reporting

Regulatory Enforcement: OCR investigations and potential civil money penalties
State Actions: State AG enforcement and fines
Civil Liability: Class actions or individual lawsuits
Contract Breach: Breach of business associate agreements
Reputational Harm: Loss of patient trust and public notice
Operational Costs: Remediation, credit monitoring expenses

eSignature Pricing Comparison for Breach Workflows

Compare common pricing and feature dimensions when choosing an eSignature provider for breach notification templates and secure workflows.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently Asked Questions About the Breach Template

Answers to common questions about usage, legal validity, notifications, and secure electronic handling of breach records.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users