HIPAA breach letter to riders, and the notice to your broker: a fill-in template for ride companies

Updated 12 min read

Overview

A HIPAA breach notification letter tells each affected rider, in plain language, what happened and when, which kinds of information were involved, how the rider can protect themselves, what you are doing to fix the problem, and where to reach you. Mail it first class as soon as the facts are in, and always within 60 calendar days of discovering the breach.

On this page

When does a ride company have to send a breach letter?

You send a rider letter after you discover a breach of unsecured protected health information and you are the covered entity that owes riders notice. HIPAA treats every use or disclosure the Privacy Rule does not allow as a breach unless an exception applies or you show, in writing, a low probability that the information was compromised (45 CFR 164.402). The breach log template walks each incident through that decision. This page starts once the answer is yes.

Three things can lift the duty or move it:

  • Encryption. Information encrypted as HHS’s guidance describes, with the key not compromised, is not “unsecured,” so notice is not required (74 FR 42740).
  • Your role. A company that runs trips only for a broker or health plan is usually a business associate. It notifies the covered entity, and the rider letters follow the contract. Our guide to HIPAA for NEMT providers explains which role you hold and lists the deadline for each recipient.
  • Law enforcement. If an official states in writing that notice would impede a criminal investigation, you wait for the period the statement gives. An oral request holds notice for no more than 30 days unless a written statement follows, and you write down who made it (164.412).

What must the rider letter say?

The letter must cover five points, each “to the extent possible,” in plain language (164.404(c)):

  1. What happened, with the date of the breach and the date you discovered it, if known.
  2. The types of information involved, such as full name, Social Security number, date of birth, home address, account number, diagnosis, or disability code.
  3. Any steps the rider should take to protect themselves from harm.
  4. What you are doing to investigate, reduce harm, and prevent a repeat.
  5. How to reach you: a toll-free telephone number, an email address, a website, or a postal address.

HHS’s explanation of the rule adds three points that matter to a ride company (74 FR 42750):

  • Describe types, not contents. Do not print the rider’s actual Social Security number or card number, and generally leave out sensitive details. For a rider on dialysis, write “the name and address of the place you were going,” not the clinic or the treatment.
  • Write for the reader. HHS asks for an appropriate reading level, clear language, no extra material, and sets no page limit.
  • Reach every rider. Where Title VI, Section 504, or the ADA applies to your company, HHS says the notice may need translating into the languages your riders use, or making it available in Braille, large print, or audio. Your language access plan lists those languages.

The rule lists the toll-free number first and spells it out as required in one case: substitute notice for 10 or more riders, covered below. Riders are more likely to phone than write, so give a toll-free number that someone answers during stated hours.

Letter 1: to the rider

Print on letterhead and fill the brackets. Keep each part short. Delete the bracketed choices that do not fit what happened.

[Date]

[Rider name, or “The family of [rider name]”] [Mailing address on file]

A notice about your personal information

Dear [Mr. or Ms. last name],

We are writing to tell you that some of your personal information was [lost / taken / sent to the wrong person]. We are sorry this happened.

What happened

On [date], [one plain sentence: “a phone one of our drivers used was taken from a parked van” / “a trip list was sent by mistake to an office that does not serve you”]. We learned about it on [date]. [We reported it to the police on [date].]

What information was involved

It included your [name, home address, phone number, and the date, time, and place of your ride]. [It did not include your Social Security number, your Medicaid or insurance number, or any bank or card information.] List only types you have confirmed.

What you can do

  • Look at statements from your health plan for rides or care you did not get. If you see any, call [health plan member services number].
  • Do not give personal or health information to anyone who calls, emails, or texts you about this unless you called them at a number you know is real.
  • [If a Social Security number or card number was involved: You can place a free fraud alert or credit freeze with the credit bureaus. Go to IdentityTheft.gov/databreach for the steps.]
  • [If you are offering it: We are paying for [number] months of [credit monitoring]. To sign up, [steps and deadline].]

What we are doing

[We locked the account the same day, filed a police report, and are [adding screen locks and encryption to every work phone / retraining our staff on sending trip details]. We are reviewing how this happened so it does not happen again.]

How we will contact you

[We will write to you by mail. We will not ask you for personal details by phone, text, or email about this notice.]

Who to call

Call [name or office] at [toll-free number], [days and hours], or write to [address]. [Email address.] [Language line: “Free interpreter help and large-print copies are available. Call [number] (TTY [number or 711]).”]

Sincerely,

[Name and title] [Company name]

The “How we will contact you” paragraph comes from the FTC’s advice to tell people how you will reach them later, which helps them spot a scam that rides on the news (FTC data breach guide, August 2023). The first bullet under “What you can do” follows the FTC’s list of warning signs of medical identity theft, such as a bill or benefits statement for services the person did not get (FTC, September 2024). The FTC also suggests offering at least a year of free credit monitoring when Social Security numbers or financial information were exposed.

A worked example: a driver’s phone is taken from a van

This is an invented example, to show how the dates and decisions fit together. Assume the company is a covered entity because it sends its own Medicaid claims electronically. On March 2, a driver’s phone is taken from a parked van. It held the day’s trip list for 38 riders: names, pickup addresses, phone numbers, appointment times, and the places they were going. It had no screen lock.

  • March 2, within the hour. The driver tells dispatch, dispatch tells the privacy official, and the official logs the incident, has the work accounts locked, and files a police report. March 2 is the discovery date, because the company knew that day.
  • March 3. The official records the decision. The phone was not encrypted and nobody can show the data was never opened, so the presumption of a breach stands and no exception fits. The company must notify. With 38 riders, there is no media notice, and the report to HHS can wait for the yearly deadline, 60 days after the year ends.
  • March 12. The 38 names are confirmed from trip records, along with mailing addresses for 36 of them. HHS has said 60 days is an outer limit: having the information ready on day 10 and waiting until day 60 would still be an unreasonable delay (74 FR 42749). The letters go out that week. Day 60 would be May 1.
  • Two riders have no mailing address. Fewer than 10 riders cannot be reached by mail, so the company phones each one, covers the same five points, and notes each call.

What the letter’s first two parts would say in this example:

What happened. On March 2, a phone one of our drivers used was taken from a parked van. We learned about it the same day and reported it to the police.

What information was involved. It included your name, home address, phone number, and the date, time, and place of your ride. It did not include your Social Security number, your Medicaid or insurance number, or any bank or card information.

Had the same phone been encrypted and locked, with its key not compromised, the privacy official would record why no notice was needed and file that note with the log. The record is the proof: HIPAA puts the burden on the company to show that it made every required notice or that the incident was not a breach (164.414).

Letter 2: notice to your broker or health plan

A business associate sends its notice to the covered entity, to the person and address its agreement names. Under the rule the notice has to identify each person affected, to the extent possible, and pass along whatever else the covered entity must put in the rider letter, either at once or promptly after (164.410(c)). HHS adds that a business associate should not hold its first notice while it gathers details, and should keep sending facts even after the 60 days have passed (74 FR 42754 to 42755).

[Date and time sent] [Method: email and phone, or the method your agreement names]

To: [Broker or plan privacy officer, from your agreement] From: [Company name, privacy official, phone, email] Re: Notice of a breach of unsecured protected health information under [agreement name and date]

  1. What happened. [Plain facts.] The breach occurred on [date or range] and we discovered it on [date].
  2. Types of information. [Names, addresses, phone numbers, ride dates and times, destinations. State what was not involved.]
  3. People affected. [Number] riders. The list is [attached / will follow by [date]], sent by [the secure method your agreement names].
  4. What we have done. [Locked accounts, police report, recovered or destroyed copies, other steps.]
  5. Steps for riders. A draft rider letter is attached [yes / no].
  6. Who writes to riders. [We propose to send the letters on [date] / Please tell us whether you will send them.]
  7. Contact. [Name, title, phone, email.]
  8. More to come. We will send further facts as we learn them and will tell you if a number changes.

The list of affected riders is itself protected health information, so send it by the secure method your agreement names, and if it names none, ask the broker’s privacy officer before you send. The business associate agreement template has the vendor-side version of this clause, for the companies that handle rider data for you.

The covered entity remains responsible for notifying riders and may delegate the job to a business associate. HHS asks the two to consider who is best placed to write, such as the party that holds the relationship with the rider, and to make sure a rider does not get a letter from each of them about the same breach (74 FR 42754 to 42755). Settle who sends the letters in your first message.

The reason brokers want a fast report is in the same HHS explanation. If a business associate acts as the covered entity’s agent, the business associate’s discovery is treated as the covered entity’s own, so the broker’s 60 days start the day you found the breach, not the day you called. If you are an independent contractor rather than an agent, the broker’s clock starts when you notify it (74 FR 42754). HHS suggests brokers address timing in their contracts, and they do, with clocks shorter than the federal 60 days. Three contracts show how:

  • WellTrans. Its provider package (revised October 16, 2025) sets two clocks. The account setup agreement requires a known breach to be reported to its HIPAA privacy and security officer within 48 hours. The business associate exhibit allows one business day from discovery for written notice to its HIPAA compliance officer, and asks for the five rider-letter points and the identity of each person affected, plus an immediate call or email when misuse looks imminent.
  • Modivcare. Its 2025 annual training for transportation providers says to report a security breach involving protected health information, “big or small,” immediately to the provider relations contact or to its privacy officer.
  • MTM. Its standard provider agreement (January 1, 2023, Pennsylvania copy) requires the provider to report any breach of member health or personal information to MTM and to sign the business associate agreement attached to it, so check that attachment for the clock.

Write the clock from your own contract next to Letter 2 and on your compliance calendar.

What if some riders have no usable address?

Give substitute notice, as soon as you learn the contact information is wrong or a letter comes back undeliverable, and include all five points (164.404(d)(2)). The method depends on how many riders you cannot reach:

  • Fewer than 10. Use another form of written notice, a phone call, or other means. HHS’s example: if the mailing address is out of date but you have an email address or a phone number, you may use it, even if the rider never agreed to email notice. HHS adds one caution for phone calls: an answering machine message can be heard by other people in the household, so leave only your company name and number and say you have an important message (74 FR 42751).
  • 10 or more. Publish a conspicuous public notice, either on your website’s home page for 90 days or in major print or broadcast media where the affected riders likely live. Either way, add a toll-free number that stays active at least 90 days so riders can learn whether their information was involved.

Two limits matter for ride companies. When you know a rider has died and have an address for the next of kin or personal representative, mail the letter there, and if that contact information is missing or out of date you owe no substitute notice (164.404(d)). For a minor or a rider who lacks legal capacity, notice to the parent or personal representative satisfies the rule (74 FR 42750).

A rider letter may go out in more than one mailing as facts come in, and the rule says so. When you see a risk of imminent misuse, such as stolen card numbers, you may also phone the rider in addition to the mailed notice.

Where state law changes the letter

State breach laws sit on top of HIPAA and often set a 30-day clock instead of 60. The guide to state privacy laws beyond HIPAA lists the deadlines and agency copies for six states, and shows how each treats a notice sent under HIPAA. Check your own state before the letter goes out.

Florida shows the kind of detail to look for. Its statute asks every notice to give the date or range of the breach, a description of the personal information involved, and contact details, a shorter list than HIPAA’s. It also lets a business decide that a breach will not likely cause identity theft or financial harm, but only after consulting law enforcement, in writing, kept at least 5 years, and sent to the Department of Legal Affairs within 30 days (501.171(4)). That is separate from HIPAA’s own assessment, and it applies to data in electronic form only.

Keeping a copy and paying for the mailing

Keep a copy of every letter, notice, and posting. When a rule requires a writing, a covered entity must keep it, and must keep each required record for six years from when it was created or last in effect, whichever is later (164.530(j)). File the letters with the log entry, the saved police report, and the mailing proof. The breach log template shows where each one is recorded.

Check your insurance before you hire a mailing service or call center. One broker’s contract already requires the cover: Paratransit Services’ Washington subcontract asks for breach response insurance that pays for forensics, notification and call center services, and credit monitoring. Our guide to cyber insurance for NEMT companies explains what those policies usually pay.

Keeping rider details off a lost phone

In HealthRide, rider details stay off the lock screen of the driver app, and each person on your team sees only what their role allows. HealthRide is HIPAA compliant, and every change in it is recorded, which helps when you are working out what happened and when. Team chat runs under the company’s name, so dispatchers and drivers do not trade personal phone numbers, and the conversations stay with the business.

Frequently asked questions

Does every lost phone or wrong text need a letter to the rider?
No. A letter is required only for a breach of unsecured protected health information. HIPAA presumes an impermissible use or disclosure is a breach, but three exceptions apply, and you can also show in writing, from a four-factor risk assessment, a low probability that the information was compromised. Information encrypted as HHS guidance describes, with the key not compromised, is not unsecured at all. Write down whichever reason you rely on.
Can I send the breach notice by text message?
Not as the only notice for a rider you can reach by mail. The rule names written notice by first-class mail to the last known address, or by email if the rider agreed to electronic notice and has not withdrawn that agreement. Telephone or other means is allowed in addition when misuse looks imminent, and as substitute notice when fewer than 10 riders have no usable contact information. A text message is not one of the named methods.
What if I only run trips for a broker and the broker holds the rider relationship?
Then you are usually a business associate. You notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, and the covered entity stays responsible for telling riders, though it may delegate that to you. Brokers set shorter clocks in their contracts. Send your notice first, and send details as you learn them, because HHS says not to hold the first notice while you collect facts.
Do I put the rider's diagnosis or home address in the letter?
No. HHS says to describe the types of information involved and not to print the actual information, such as a Social Security number or card number, and generally to avoid sensitive details. For a ride company, write that the information included the name and address of the place the rider was going, not the clinic or the treatment. The rider already knows their own details.
What do I do for riders I cannot reach?
Give substitute notice, as soon as you learn the contact information is wrong. With fewer than 10 such riders you can use another form of written notice, a phone call, or other means. With 10 or more, you need a toll-free number that stays active for at least 90 days, plus a public notice: either on your website's home page for 90 days or in major print or broadcast media where the riders likely live.
Who gets the letter if the rider has died or is a child?
If you know the rider has died and have an address for the next of kin or a personal representative, mail the letter to either one. If you have no address for them, you owe no substitute notice. For a minor, or a rider who cannot act for themselves, notice to the parent or personal representative meets the rule. Each letter still covers the same five points.

Official resources

HealthRide plans the whole day in one click and bills every ride.