What the Notice to an Individual Must Say
Most statutes agree on a short list of elements and then diverge. One state prescribes the title, the headings, the minimum type size and a model form; another asks only for three items; the federal health rule sets a fifth element none of them require.

The rule in short
A breach notice is built from a common core: who is writing, what categories of information were involved, when the incident happened, and how to get more information. States then add in different directions. California prescribes a title, five headings, a ten-point minimum type size and a model form. Washington requires the credit bureau contacts. The federal health rule requires a description of the entity's own remediation.
A breach notice is a regulated document. The statutes do not merely require that people be told; they specify what the telling must contain, and in one state they specify how it must look. The elements are additive across jurisdictions, so an organization writing to residents of several states is drafting to the union of the applicable lists rather than to any one of them.
The elements almost every statute requires
Four items appear in nearly every list. The first is the identity of the entity writing, with contact information sufficient for the recipient to ask questions. The second is a description of the categories of personal information that were, or are reasonably believed to have been, involved. The third is timing, expressed as the date of the breach, an estimated date or a date range where the exact figure cannot be fixed. The fourth is a route to more information, usually a telephone number and an address or website.
Washington's list is a clean statement of the core with one addition: plain language, the name and contact information of the reporting entity, the types of personal information involved, a time frame of exposure including the dates of the breach and of its discovery, and the toll-free telephone numbers and addresses of the major credit reporting agencies where the breach exposed personal information. Florida's list is the shortest of the group, requiring the date or estimated date range, a description of the information accessed, and information the recipient can use to contact the entity about the incident and about what records it holds.
Where the statute prescribes the document itself
California goes considerably further than a content list. The notice must be written in plain language, titled "Notice of Data Breach", and must present the required information under five headings in a fixed sequence: what happened, what information was involved, what is being done, what the recipient can do, and where to get more information. The format must be designed to call attention to the nature and significance of the information. The title and headings must be clearly and conspicuously displayed, and the text must be no smaller than ten-point type.
The statute then supplies a model form and provides that using it, or using the prescribed headings with the required information in plain language, is compliance with the formatting subdivision. That is a genuine safe harbor on presentation, and it is the reason most multi-state notices are built inside the California structure even where California residents are a small part of the population. The content minimum sits alongside the format: the reporting entity's name and contact details, the types of information involved, the date or estimated date or range together with the date of the notice, whether notification was delayed by a law enforcement investigation, a general description of the incident, and the credit reporting agency contacts where the exposure included the categories that make those contacts useful.
| Element | California | Washington | Florida | Federal health rule |
|---|---|---|---|---|
| Categories of information involved | Required | Required | Required | Required, with examples given |
| Date, estimated date or range | Required, plus the date of the notice | Required, with the discovery date | Required | Required if known, with the discovery date |
| Credit reporting agency contacts | Required for named categories | Required | Not specified | Not specified |
| What the entity is doing about it | Under a prescribed heading | Not specified | Not specified | Required as an element |
| Whether notice was delayed | Required where determinable | Not specified | Not specified | Not specified |
| Prescribed format | Title, headings, ten-point type | Plain language only | Not specified | Plain language only |
What the federal health rule adds
The health rule's list overlaps the state core and then adds an element the states largely omit: a brief description of what the covered entity is doing to investigate the breach, to mitigate harm to individuals and to protect against further breaches. It also asks for any steps individuals should take to protect themselves, and it specifies the contact procedures in the alternative, requiring a toll-free number, an email address, a website or a postal address. Like California, it requires plain language.
The remediation element changes the drafting problem. A sentence describing what the organization has done is a factual statement made under a rule that places the burden of demonstrating compliance on the entity, and it will be read later against the incident record. Vague assurance is worse than a short specific account, and an account that outruns what was actually done is worse still.
The rule also requires the notice to state any steps individuals should take to protect themselves. That element is where the credit bureau contacts, the credit freeze information and any offered services naturally sit, and it is the part of the letter most likely to be reused verbatim across incidents. Reuse is fine as far as it goes, but the steps have to match the exposure. Advice about monitoring bank statements attached to a notice about a breach of health diagnoses tells the recipient that the letter was assembled rather than written.
One further divergence is worth noting. Several state statutes deem notice given under the rules of a covered entity's primary or functional federal regulator to satisfy the state requirement, provided the individuals are notified in accordance with those rules. Florida includes such a provision. That is a substitution of one content standard for another rather than an exemption, and it works only where the federal notice actually went to the state's residents.
Several statutes require a sample copy of the individual notice to be filed with the state, so the same document serves as consumer communication and as a regulatory submission. California asks for the sample copy within fifteen calendar days of notifying consumers, and Washington requires one with the attorney general filing. A letter drafted only for the household audience will be assessed against the statutory element list by a reader holding it beside the statute. The filing side is set out in notice to a state regulator and its thresholds.
Delivery, and what happens when it fails
The default method is written notice to the last known address, with electronic mail available where the recipient has agreed to it or, in some states, where email is the ordinary channel between the parties. Where the breach involves credentials rather than identity data, several statutes prescribe a different route: notice delivered online when the consumer connects to the account from an address or location the entity knows the consumer customarily uses, and, where the compromised credentials belong to an email account the entity itself provides, a route other than that email address.
When contact information is missing or stale for enough people, the statutes switch to a published form of notice with its own thresholds and methods, described in substitute notice when people cannot be reached. The switch is conditional, not elective; an entity that has usable addresses cannot choose a website posting because it is cheaper. And whichever method is used, the timing obligations are unchanged, which is why drafting normally proceeds in parallel with the clock analysis set out in the state notification clocks and where they differ rather than after it.
Points to carry away
- Nearly every statute requires the categories of personal information involved and a way to contact the notifying entity.
- California prescribes the title, five fixed headings, a ten-point minimum type size and a model form.
- California also requires disclosure of whether notice was delayed by a law enforcement investigation.
- Washington requires the toll-free numbers and addresses of the major credit reporting agencies.
- Florida sets the shortest list: the date or date range, a description of the information, and contact information.
- The federal health rule adds a description of what the entity is doing to investigate and mitigate.
Questions readers ask
Can one letter satisfy every state at once?
Usually, because the elements are additive rather than contradictory. The standard approach builds a single notice containing the union of what the applicable statutes require, then checks that no state forbids an inclusion. The main constraint is California, which fixes the title, the order of headings and a minimum type size, so a combined letter is generally built inside that structure with other states' elements distributed under the prescribed headings. The alternative, a separate draft per jurisdiction, multiplies the chance that two versions describe the incident differently.
Must the letter say the notice was delayed?
In California, yes, where that fact can be determined when the notice is prepared. The statute lists whether notification was delayed as a result of a law enforcement investigation among the minimum contents. Most states do not require the disclosure, but none of them prohibits it, and including it is often the cleaner course where a delay was granted, because the alternative is a letter whose stated breach date sits months before its own date without explanation.
Are free credit monitoring or identity theft services required?
The offer itself is not universally required, but California conditions it: where services are offered, and the breach exposed a Social Security number or a driver's license or state identification number, they must be provided at no cost for not less than twelve months together with everything needed to take up the offer. A shorter or conditional offer to the same population does not satisfy that provision. Several other statutes require the notice to state what services are being made available without charge.
Sources
- California Civil Code section 1798.82Prescribes the title, the five headings, ten-point type, the model form and the minimum content list.
- RCW 19.255.010 — Washington notice of security breachesRequires plain language and lists four minimum items including the credit reporting agency contacts.
- Florida Statutes section 501.171Sets a three-item minimum for individual notice and permits written or email delivery.
- 45 CFR 164.404 — Notification to individualsLists five content elements including the entity's own investigation and mitigation steps, and requires plain language.
- New York General Business Law section 899-aaRequires contact information for the notifying entity and a description of the categories of information believed to have been acquired.
- 16 CFR 318.5 — Methods of notice under the health breach ruleSets delivery methods for personal health record vendors and the ten-individual threshold for substitute notice.
Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.
More in Breach Notification
The State Clocks and Where They Differ
State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.
Notifying a Regulator and the Threshold That Triggers It
Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.
The Sixty-Day Rule for Health Information
A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.


