Compliance

HIPAA Breach Notification Letter Template for NEMT Companies: Rider Letter, Broker Notice, and Website Notice

Overview

A HIPAA breach notification letter tells each rider whose unsecured health information was exposed what happened, what information was involved, what to do, what you are doing about it, and how to reach you. Mail it first-class within 60 days of discovery, sooner when you can. On broker trips you usually notify the broker, and the state or health plan above it decides who writes to riders.

  • If you run broker trips, your notice usually goes to the broker, not to riders, unless your agreement hands you the rider letters.
  • Every rider letter covers five things in plain language: what happened, what information, what to do, what you are doing, and how to reach you.
  • Sixty days is the outer limit. HHS says waiting until day 60 when the facts were ready on day 10 is an unreasonable delay.
  • Name the types of information, never the numbers. A breach letter should not print a Social Security number or a Medicaid ID.
  • California wants the title "Notice of Data Breach" and five set headings, New York wants agency phone numbers and websites, and both want it within 30 days.

Only the title and the template print.

A breach notice is short, and each line answers a rule. This template holds the three notices a NEMT company may have to send after rider information leaks: the notice to your broker or health plan, the letter to each rider, and the website or media notice for riders you cannot reach. For the first hours after an incident, from stopping the loss to calling the police, start with what to do after a NEMT data breach.

How to use this template

  1. Log the incident and decide whether it is a breach. Open a line in your HIPAA breach log the day it is found, and write the four-factor risk assessment. HIPAA presumes a breach unless that assessment shows a low probability the information was compromised (45 CFR 164.402). If it is not a breach, you send no letter, but you keep the assessment.
  2. Find out who sends what. Read your business associate agreement. If you run trips for a broker, you usually owe the broker the notice in Part 2, and the state or health plan above it decides on rider letters. If you are the covered entity, or the agreement hands you the rider letters, use Part 3 too. HIPAA for NEMT providers explains how to tell which one you are.
  3. Write both deadlines in Part 1. HIPAA’s outer limit is 60 calendar days from the day anyone on your staff, other than the person at fault, knew or should have known. Your broker’s clock is usually far shorter.
  4. Fill in Part 1 once. Every notice draws on the same facts, so the broker, the riders, and any website notice tell the same story.
  5. Send the broker notice first and add facts as you learn them. HIPAA lets a business associate send missing details promptly after the first notice (164.410(c)(2)), so do not hold it while you investigate.
  6. Add the state lines in Part 4 to rider letters for people who live in California, New York, or Florida, and check the law of any other state where your riders live.
  7. Mail each rider letter first-class to the last known address. Email it only to riders who agreed to get notices by email.
  8. Use Part 5 for riders you cannot reach, and for the media when more than 500 residents of one state are affected.
  9. Record every notice in Part 6 and keep a copy of each one. You must be able to prove each notice went out on time (45 CFR 164.414).

The template

Part 1: Breach facts

Field Write it here
Incident number from your breach log
Date of the breach, or the estimated date or date range
Date discovered, and who discovered it
Last day to notify under HIPAA (60 calendar days after discovery)
Broker’s or plan’s deadline under your agreement
Earliest state deadline for these riders
What happened, in two or three plain sentences
Types of information involved: name, address, phone, date of birth, Medicaid or member ID, Social Security number, driver’s license number, pickup and drop-off addresses, clinic or appointment destination, diagnosis or condition, mobility needs, card or bank details, other
Types of information not involved
Number of riders affected, and how many live in each state
Riders with no good mailing address (count)
Was electronic information encrypted, with the key kept apart?
Police or other law enforcement report (agency and report number)
Law enforcement delay asked for (official’s name, agency, written or spoken, end date)
Steps riders should take
What you are doing to investigate, limit harm, and prevent a repeat
Toll-free number, email, website, and postal address for questions
How you will contact riders about this later (mail only, phone, website updates)
Languages and formats riders need (large print, braille, audio)
Who signs the notices (name and title)

Part 2: Notice to your broker or health plan

[Your letterhead]

Date: ______________

To: ______________________________ (the privacy or HIPAA officer your agreement names, with address, fax, or email)

Re: Notice of a breach of unsecured protected health information under our business associate agreement dated ______________

What happened. On ______________, ______________________________. We discovered it on ______________. [It began on ______________ and ended on ______________.]

Riders affected. The breach involves ______ riders. Attachment A lists each rider we have identified so far, with the trips and information involved. [We are still reviewing ______________ and will send an updated list by ______________.]

Information involved. ______________________________. It did not include ______________________________.

What riders should do. ______________________________.

What we are doing. ______________________________. [We reported the theft to the ______________ police, report number ______________.] [On ______________, ______________ of ______________ asked us to delay notice until ______________.]

Contact. ______________ can answer questions from you and from riders at ______________ (phone) and ______________ (email).

Rider letters. Please tell us in writing whether you will notify the riders or want us to, and whether you want to review our draft letter first.

We will send any new information as soon as we have it.

Signature: ______________________________ Printed name and title: ______________________________

Attachment A: Riders affected (send it the way your agreement says)

No. Rider name Member or Medicaid ID Trip dates Information involved State of residence
1
2
3
4
5
6

Part 3: Letter to riders

[Your letterhead]

Date of this notice: ______________

[Rider’s name] [Mailing address]

Notice of Data Breach

Dear ______________,

We are writing to tell you about a problem that involved some of your information. [Company name] gives you rides to medical appointments [for ______________ (program or health plan)].

What happened? On ______________, ______________________________. We learned about it on ______________. [We waited to send this letter because ______________ (law enforcement agency) asked us to, so its investigation would not be harmed.]

What information was involved? The information included your ______________________________. It did not include your ______________________________.

What we are doing. We ______________________________ (for example: got the papers back, erased the phone from a distance, reported the theft to the police, changed passwords, retrained our staff). To keep this from happening again, we ______________________________.

What you can do.

  • If you get statements from Medicaid or your health plan, read them. If you see a ride, visit, or medicine you did not get, call the plan.
  • Do not give your Medicaid number or health details to anyone who calls, texts, or emails you about this letter. We will contact you about it only by ______________.
  • [If a Social Security, driver’s license, or bank or card number was involved: You can ask the credit bureaus for a free fraud alert or credit freeze. Equifax: 1-800-685-1111. Experian: 1-888-397-3742. TransUnion: 1-888-909-8872.]
  • [We are offering ______ months of free ______________ (credit monitoring or identity protection). To sign up, ______________ by ______________.]
  • For steps that fit the kind of information involved, visit IdentityTheft.gov/databreach.

Other important information. [Add the lines from Part 4 for the rider’s state.]

For more information. Call us toll-free at ______________, ______________ (days and hours). You can also email ______________, visit ______________, or write to ______________. If you need this letter in another language, in large print, or in another format, call the same number.

Sincerely,


Name and title

Part 4: State additions for rider letters

Rider’s state Add to the letter Other notices the state requires
California Keep the title and the five headings, set them so they stand out, and use 10-point type or larger. Give the date of the notice and whether law enforcement delayed it. If a Social Security, driver’s license, or California ID number was involved, list the credit bureaus’ toll-free numbers and addresses. A sample copy to the Attorney General within 15 days of notifying riders, when more than 500 Californians are notified
New York The phone numbers and websites of state and federal agencies that give breach response and identity theft help, and each specific kind of information involved The Attorney General, Department of State, and State Police, with a copy of the letter. A covered entity also tells the Attorney General within 5 business days of reporting to HHS.
Florida The date or estimated date range, what personal information was involved, and how to ask what information you keep about the rider The Department of Legal Affairs within 30 days, when 500 or more Floridians are affected

Sample line for New York riders: “To learn how to protect yourself from identity theft, visit the Federal Trade Commission at IdentityTheft.gov, or contact ______________ (state agency) at ______________ (phone) or ______________ (website).”

Part 5: Riders you cannot reach, the media, and urgent calls

Situation What to send When
Bad or old address for fewer than 10 riders Another written notice, a phone call, or another way to reach them As soon as you learn the address is bad
Bad or old address for 10 or more riders The notice below on your website home page, or in major print or broadcast media where they likely live, with a toll-free number As soon as you learn the addresses are bad; keep the posting and phone line up 90 days
More than 500 residents of one state affected The same notice to prominent media serving that state, usually as a press release Within 60 days of discovery
Misuse looks imminent A phone call to riders, on top of the letter Right away
Rider has died, and you know it and have the address The letter to the next of kin or the personal representative Same deadline as the letter

Notice of Data Breach (posted ______________, kept up through ______________)

On ______________, [company name], which gives rides to medical appointments in ______________, learned that ______________________________. The information involved was ______________________________. We are ______________________________. If you rode with us between ______________ and ______________, you can ______________________________. Call us toll-free at ______________ (open through ______________) to find out whether your information was involved, or write to ______________.

Part 6: Notice record

Rider or group How sent (mail, email with consent, phone, website, media) Date sent Returned or bounced? Follow-up and date

What HIPAA requires the letter to say

The rider letter must include, to the extent possible, five things (45 CFR 164.404(c)):

  1. A short description of what happened, with the date of the breach and the date you discovered it, if known.
  2. The types of information involved, such as full name, Social Security number, date of birth, home address, account number, diagnosis, or disability code.
  3. Steps riders should take to protect themselves from harm.
  4. What you are doing to investigate, limit harm to riders, and protect against further breaches.
  5. How to reach you, which must include a toll-free number, an email address, a website, or a postal address.

It must be written in plain language. HHS explained in its August 24, 2009 rule (74 FR 42750) that this means an appropriate reading level, clear sentences, and nothing extra that could bury the message. HHS set no page limit.

That same discussion settles three questions a NEMT company often asks:

  • Types, not numbers. Describe the kinds of information involved. Do not print the actual Social Security number, card number, or other breached data in the letter, and keep sensitive details out of it. For a NEMT rider, “your name, home address, and the clinic you ride to” says enough.
  • What “what we are doing” can cover. HHS gave examples: steps to get the information back, such as a police report after a theft; steps to improve security; and sanctions applied to staff involved.
  • Language and format. Where Title VI of the Civil Rights Act applies to you, meaningful access can mean translating the notice into languages your riders often speak. Where Section 504 or the Americans with Disabilities Act applies, it can mean large print, braille, or audio. The “For more information” line in Part 3 invites those requests.

The FTC’s August 2023 breach guide adds a step worth copying: tell people how you will and will not contact them later, so a scam call about the breach is easier to spot. The FTC’s medical identity theft advice (September 2024) lists the warning signs to give riders, such as a bill or benefit statement for care they never got.

The media notice and any website or substitute notice carry the same five elements (164.406(c); 74 FR 42751).

Who sends it: you, the broker, or the plan

HIPAA splits the job. The covered entity notifies riders (164.404). A business associate notifies the covered entity, naming each affected person as far as it can and passing along everything the covered entity needs for its letters, at the time or promptly after (45 CFR 164.410). A broker’s subcontractor is a business associate too, so the notice moves up the chain: you notify the broker, the broker notifies the state or health plan, and that covered entity notifies riders, HHS, and any media unless it hands the job to a business associate (78 FR 5590). HHS said in 2009 that a business associate should not hold its first notice to gather details, and should keep sending new facts even after the letters go out or the 60 days pass (74 FR 42754).

HHS’s Breach Notification Rule page (last reviewed July 26, 2013) says the covered entity stays ultimately responsible for notifying riders but may hand that job to the business associate. HHS suggests the two decide who is better placed, such as whoever has the relationship with the rider, and avoid sending riders two letters about the same breach (74 FR 42755). HHS’s sample agreement language (last reviewed June 16, 2017) invites the parties to write down a shorter reporting deadline and whether the business associate will notify individuals, HHS, and the media. Part 2 ends by asking that question in writing.

Broker agreements set the details. As of October 2026:

  • WellTrans. Its agreement (revised October 16, 2025) requires written notice to its HIPAA Compliance Officer within one business day of discovery. The notice must be in plain language, cover the same five elements as a rider letter, and identify each affected rider if known. Send it to WellTrans, Inc., Attn: HIPAA Compliance Officer, 7340 Shadeland Station, Indianapolis, IN 46256, or fax 1-888-238-9816, and call 1-317-785-5500 at once if misuse seems imminent. Article V of the same agreement also asks for a report to its privacy and security officer at (800) 486-7647 within 48 hours, so meet the earlier clock.
  • Modivcare. Its 2025 annual compliance training tells providers to report any breach of rider health information, big or small, immediately to their provider relations partner or to its privacy officer at hipaaofficer@modivcare.com.

If you bill Medicaid or a health plan yourself, you may be the covered entity, and Part 3 is yours to send. State breach laws also reach records you own, such as private-pay riders’ files, whether or not HIPAA applies, so check them even when the broker sends the HIPAA letters.

Deadlines and how to deliver it

  • Sixty days is a ceiling, not a target. Notice goes out without unreasonable delay and no later than 60 calendar days after discovery (164.404(b)). HHS’s example: a covered entity with everything it needs on day 10 that waits until day 60 has delayed unreasonably, and unreasonably letting an investigation lag for 30 days is a delay too (74 FR 42749).
  • First-class mail is the default. Email works only for riders who agreed to electronic notice and have not withdrawn it. You may send the notice in more than one mailing as facts come in (164.404(d)(1)).
  • Write to the right person. For a rider who has died, write to the next of kin or personal representative if you know of the death and have the address. For a minor or a rider who cannot make their own decisions, notice to the parent or personal representative counts (74 FR 42750).
  • Unreachable riders get substitute notice, and an urgent case can add a phone call (164.404(d)(2) and (3)). Part 5 lays out each case.
  • Media notice applies above 500 residents of one state, within the same 60 days and with the same content (164.406). HHS says covered entities will likely send it as a press release.
  • Law enforcement can pause the clock. A written request delays notice for the time it states. A spoken one delays it no more than 30 days unless a written request follows, and you must write down who made it (45 CFR 164.412).
  • HHS gets its own report from the covered entity. Breaches of 500 or more people are reported at the same time as the rider letters, and smaller ones within 60 days after the year ends, so breaches found in 2026 are due by March 1, 2027 (164.408). HHS’s reporting page (last reviewed February 13, 2026) asks for a separate report for each breach. The breach log template holds that worksheet.

State laws that change the letter

The FTC notes that every state, the District of Columbia, Puerto Rico, and the Virgin Islands have breach notice laws. Three that reach many NEMT riders change the letter itself, and each sets a 30-day deadline for its residents. All three cover computerized or electronic records only, so a lost paper manifest falls under HIPAA but not under these laws:

  • California (Civil Code 1798.82). Since January 1, 2026, notice is due within 30 calendar days of discovery. The notice must be titled “Notice of Data Breach” and use the headings “What Happened?”, “What Information Was Involved?”, “What We Are Doing,” “What You Can Do,” and “For More Information,” in type no smaller than 10 point. It must give the date of the notice and say whether law enforcement delayed it. When a Social Security, driver’s license, or California ID number was exposed, it lists the credit bureaus’ toll-free numbers and addresses. A company that caused a breach exposing a Social Security number or a government ID number, such as a driver’s license or passport number, offers at least 12 months of free identity theft prevention and mitigation services. A HIPAA covered entity that fully meets HIPAA’s content rule is treated as meeting these content rules, but the deadline and the Attorney General copy still apply. Part 3 already uses the California headings, so one letter can serve every state.
  • New York (General Business Law 899-aa, as revised March 28, 2025). Notice is due within 30 days of discovery, and every notice names the specific data elements involved and gives the phone numbers and websites of state and federal agencies that help with breaches and identity theft. If riders were notified under HIPAA, New York requires no second letter, but the state agency notices still go out.
  • Florida (Statutes 501.171). Notice is due within 30 days and states the date or estimated date range, what personal information was involved, and how to ask about the breach and the information you keep about the rider. Florida’s definition includes medical, health insurance, and geolocation information. Notice that follows the rules of your primary or functional federal regulator counts as Florida’s rider notice, and sending the Department of Legal Affairs a copy on time counts as its department notice.

Keep the letter, the mailing list, proof of each mailing date, and returned mail for at least 6 years (45 CFR 164.530(j)), longer if a broker contract asks for it. Then update your HIPAA policy and risk assessment so the same gap does not open again.

Frequently asked questions

Does my NEMT company have to send breach letters to riders?

Only if you are the covered entity or your agreement gives you the job. HIPAA puts rider letters on the covered entity, such as the state Medicaid program or a health plan. A broker's subcontractor is a business associate too: it notifies the broker, which notifies the covered entity. HHS lets a covered entity hand the rider letters to a business associate, so read your business associate agreement.

How soon must a HIPAA breach letter go out?

Without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.404(b)). The clock starts when anyone on your staff other than the person at fault knew, not when the investigation ends. HHS says that holding letters until day 60 when you had the facts on day 10 is an unreasonable delay. California, New York, and Florida set 30 days for their residents.

Can I email the breach notice instead of mailing it?

Only to riders who agreed to get notices by email and have not withdrawn that agreement (45 CFR 164.404(d)(1)). Everyone else gets first-class mail at the last known address. If misuse looks imminent, you may also call riders, but the call is in addition to the written notice, not instead of it.

What if I do not have a current address for some riders?

Give substitute notice. For fewer than 10 riders, another written notice, a phone call, or other means works. For 10 or more, post the notice on your website home page for 90 days or run it in major print or broadcast media where they likely live, with a toll-free number that stays active for 90 days (45 CFR 164.404(d)(2)).

Should the letter list the rider's Medicaid ID or trip details?

No. HIPAA asks for the types of information involved, such as "your name, home address, and Medicaid ID number," not the numbers themselves. HHS said in its August 24, 2009 rule that a notice should not list the actual information breached and should avoid sensitive information in the letter itself.

Do I have to offer free credit monitoring?

HIPAA does not require it. California requires at least 12 months of free identity theft prevention and mitigation services when your company caused a breach that exposed a Social Security number or a government ID number, such as a driver's license or passport number, though a HIPAA covered entity that follows HIPAA's content rules is treated as meeting California's notice content rules. The FTC's August 2023 guide suggests considering at least a year of free monitoring, especially when Social Security numbers or financial information were exposed.

Official resources

One email a month

Broker changes, new state rules, and new guides. No spam.