| name | breach-notification |
| title | Data Breach Notification Letter |
| description | Drafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG requirements). Use when drafting breach notices, security incident consumer notifications, or data compromise letters. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/breach-notification |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | data-protection |
| language | en |
Data Breach Notification Letter
Drafts a consumer-facing breach notification letter satisfying multi-state statutory requirements with appropriate tone and actionable consumer guidance.
Prerequisites
Gather before drafting:
- Incident details — discovery date, breach type (unauthorized access, ransomware, inadvertent disclosure), affected timeframe
- Compromised data inventory — exact data elements per affected population segment
- Jurisdiction list — states where affected consumers reside (drives content and timing)
- Regulatory frameworks — state breach statutes, plus sector-specific if applicable (HIPAA, GLBA, FERPA)
- Remediation services — credit monitoring/identity protection vendor, enrollment details, duration, cost allocation
- Contact channels — dedicated toll-free phone, email, URL for breach inquiries
- Signatory — senior executive name and title (CEO, CPO, or GC)
Letter Sections
Draft these sections in order:
1. Header & Salutation
- Organization legal name, address, letterhead
- Letter date (track against statutory deadlines)
- Personalized name if available; otherwise "Dear [Customer/Patient/Member]"
- Cite specific statute(s) under which notice is provided
2. Incident Description
- State purpose immediately: notifying recipient of a data security incident
- Plain language — no unnecessary technical jargon
- Include discovery date, nature of incident, general cause
- If investigation is ongoing, state so and commit to updates
- Do not disclose details that compromise security or ongoing investigations
- Do not speculate beyond confirmed facts
3. Compromised Data Categories
List only data elements actually affected:
| Category | Examples |
|---|
| Identifiers | Full name, address, phone, email |
| Government IDs | SSN, driver's license, passport number |
| Financial | Bank account, credit/debit card numbers |
| Health | Medical records, insurance IDs, diagnoses |
| Credentials | Usernames, passwords, security questions |