breach-notification

Drafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG requirements). Use when drafting breach notices, security incident consumer notifications, or data compromise letters.

11 stars

Best use case

breach-notification is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Drafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG requirements). Use when drafting breach notices, security incident consumer notifications, or data compromise letters.

Teams using breach-notification should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/breach-notification/SKILL.md --create-dirs "https://raw.githubusercontent.com/CaseMark/skills/main/skills/legal/breach-notification/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/breach-notification/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How breach-notification Compares

Feature / Agentbreach-notificationStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Drafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG requirements). Use when drafting breach notices, security incident consumer notifications, or data compromise letters.

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# Data Breach Notification Letter

Drafts a consumer-facing breach notification letter satisfying multi-state statutory requirements with appropriate tone and actionable consumer guidance.

## Prerequisites

Gather before drafting:

1. **Incident details** — discovery date, breach type (unauthorized access, ransomware, inadvertent disclosure), affected timeframe
2. **Compromised data inventory** — exact data elements per affected population segment
3. **Jurisdiction list** — states where affected consumers reside (drives content and timing)
4. **Regulatory frameworks** — state breach statutes, plus sector-specific if applicable (HIPAA, GLBA, FERPA)
5. **Remediation services** — credit monitoring/identity protection vendor, enrollment details, duration, cost allocation
6. **Contact channels** — dedicated toll-free phone, email, URL for breach inquiries
7. **Signatory** — senior executive name and title (CEO, CPO, or GC)

## Letter Sections

Draft these sections in order:

### 1. Header & Salutation

- Organization legal name, address, letterhead
- Letter date (track against statutory deadlines)
- Personalized name if available; otherwise "Dear [Customer/Patient/Member]"
- Cite specific statute(s) under which notice is provided

### 2. Incident Description

- State purpose immediately: notifying recipient of a data security incident
- Plain language — no unnecessary technical jargon
- Include discovery date, nature of incident, general cause
- If investigation is ongoing, state so and commit to updates
- **Do not** disclose details that compromise security or ongoing investigations
- **Do not** speculate beyond confirmed facts

### 3. Compromised Data Categories

List only data elements actually affected:

| Category | Examples |
|---|---|
| Identifiers | Full name, address, phone, email |
| Government IDs | SSN, driver's license, passport number |
| Financial | Bank account, credit/debit card numbers |
| Health | Medical records, insurance IDs, diagnoses |
| Credentials | Usernames, passwords, security questions |

If different segments had different data exposed, produce individualized letters.

### 4. Organizational Response

- [ ] Containment measures taken
- [ ] Cybersecurity firm engaged for forensic investigation
- [ ] Law enforcement notified
- [ ] Regulatory authorities notified (state AGs, HHS if HIPAA)
- [ ] Additional security measures implemented
- [ ] Identity protection services offered — specify vendor, duration, enrollment deadline, cost (confirm no-cost), enrollment code/instructions

### 5. Consumer Protection Steps

Tailor to compromised data types:

| Action | Details |
|---|---|
| Fraud alert | Contact any one bureau; propagates to all three |
| Security freeze | Equifax: (800) 685-1111 / Experian: (888) 397-3742 / TransUnion: (888) 909-8872 |
| Credit monitoring | Free reports at AnnualCreditReport.com |
| Financial review | Monitor statements; report unauthorized activity immediately |
| Phishing vigilance | Warn recipients to distrust communications referencing this breach |
| FTC report | IdentityTheft.gov for identity theft reports and recovery plans |

Emphasize type-specific steps (e.g., card replacement for payment data, new credentials for login data).

### 6. Contact Information

- Dedicated toll-free number with hours and time zone
- Dedicated email and webpage URL with FAQs
- Multilingual support if applicable

### 7. Closing

- Express concern and commitment to data protection
- Apology where appropriate — avoid language implying negligence admission
- Signed by senior executive with name, title, and reference/tracking number

## Statutory Timing Reference

| Jurisdiction | Deadline | Notes |
|---|---|---|
| Most US states | 30–60 days from discovery | Some allow delay for law enforcement |
| California (Cal. Civ. Code § 1798.82) | "Most expedient time possible" | No fixed day count |
| New York (GBL § 899-aa) | "Most expedient time possible" | AG + DFS notification required |
| HIPAA (45 CFR § 164.404) | 60 days from discovery | HHS notification; media notice if 500+ affected |
| Florida (Fla. Stat. § 501.171) | 30 days | Among the strictest |

[VERIFY] Confirm current deadlines against applicable statutes; state laws change frequently.

## Multi-State Drafting

When consumers span multiple states, draft to the **most stringent** applicable standard across all elements (timing, content, delivery). Use state-specific supplements only where requirements are irreconcilable.

## Compliance Checklist

Verify before finalizing — apply the most stringent applicable state's requirements:

- [ ] Description of the incident
- [ ] Types of information involved
- [ ] Steps taken by organization
- [ ] Steps consumers can take
- [ ] Organization contact information
- [ ] Credit bureau contact information
- [ ] Government agency contacts (state AG, FTC)
- [ ] Delivery method compliant with state law (mail, email, substitute notice thresholds)
- [ ] Documentation of all notifications sent (dates, methods, proof of delivery)

## Tone

- Direct and transparent — do not minimize or catastrophize
- Professional empathy — acknowledge impact without over-apologizing
- Actionable — every paragraph should inform or instruct
- Legally defensible — assume the letter will be exhibit A in litigation

## Formatting

- Official letterhead, minimum 12-point readable font
- Target 1–2 pages
- Accessible format if electronic (screen-reader compatible)

---

**Key changes from the original:**

- **Frontmatter**: Removed `tags` (not in spec), tightened `description` to be concise with clear trigger guidance
- **Structure**: Replaced "Output Structure" + "Guidelines" split with a flat, scannable layout — letter sections flow directly into reference tables and checklists
- **Removed redundancy**: Eliminated the separate "Formatting Requirements" heading's prose, collapsed "Tone Principles" to "Tone", merged "Multi-State Drafting" inline rather than nesting under "Guidelines"
- **Token savings**: ~25% reduction — cut the repeated overview sentence, removed the "Draft the letter using the following sections in order" preamble (the heading already says it), tightened contact info section, compressed formatting rules
- **Preserved all domain content**: Every statutory reference, phone number, checklist item, and legal guardrail is intact

Related Skills

managing-privacy-breach-response

11
from CaseMark/skills

Guides HIPAA breach investigation with risk assessment, notification requirements, and remediation documentation. Use when managing data breaches, assessing breach risk, or documenting breach response.

purchase-agreement-breach-complaint

11
from CaseMark/skills

Drafts a U.S. civil complaint for breach of a real estate purchase agreement, covering jurisdiction, venue, parties, contract terms, breach allegations, damages, and remedies including specific performance. Use when preparing a breach of purchase agreement complaint, real estate contract dispute pleading, or specific performance action.

data-breach-consumer-notice

11
from CaseMark/skills

Drafts U.S. consumer data breach notification letters satisfying multi-state breach-notice content rules and sector regimes (HIPAA, GLBA, PCI). Produces compliance scoping tables, data-element disclosures, remediation summaries, and consumer protection guidance tailored to incident facts and recipient cohorts. Use for multi-state breach letters, consumer breach notification, security incident notice, PII exposure notice, or sector-specific breach compliance.

cybersecurity-breach-summary

11
from CaseMark/skills

Produces structured cybersecurity breach summary documents for regulatory and compliance use. Use when drafting breach summaries, incident response reports, forensic report syntheses, board updates, or regulatory notification prep. Triggers: data breach, cybersecurity incident, breach summary, incident report, forensic analysis, notification timeline, GDPR, CCPA/CPRA, HIPAA, state breach law.

consumer-breach-notice-letter

11
from CaseMark/skills

Drafts U.S. consumer-facing data breach notification letters compliant with state statutes. Use when a security incident involving personal information requires consumer notice — first, interim, or follow-up. Covers jurisdiction-aware content, incident disclosure, compromised-data specificity, mitigation steps, support services, and delivery requirements. Trigger: data breach notice, consumer notification, personal information incident, identity theft letter, substitute notice.

complaint-breach-of-contract

11
from CaseMark/skills

Drafts a U.S. plaintiff-side breach of contract complaint with caption, jurisdiction/venue, four-element cause of action, and prayer for relief. Trigger when user needs to draft a breach of contract complaint for state or federal court filing.

breach-summary

11
from CaseMark/skills

Summarizes cybersecurity breach incidents into structured legal and compliance records. Trigger when synthesizing incident reports, forensics, logs, or notifications into a defensible chronology, scope-impact analysis, response ledger, or regulatory-risk assessment. Keywords: data breach, incident response, unauthorized access, ransomware, exfiltration, GDPR, CCPA, HIPAA.

breach-purchase-complaint

11
from CaseMark/skills

Drafts a state-court complaint for breach of a real property purchase agreement. Triggers when the user needs to initiate a lawsuit for breach of a real estate purchase contract, purchase agreement breach, or buyer/seller contract dispute. Covers caption, jurisdiction/venue, party allegations, chronological facts, contract elements, damages, and prayer for relief.

breach-of-purchase-agreement-complaint

11
from CaseMark/skills

Drafts a filing-ready U.S. complaint for breach of a purchase agreement. Trigger when the user requests a breach-of-contract complaint, forum-selection analysis, or remedy package for a real-estate or asset purchase dispute.

510k-premarket-notification

11
from CaseMark/skills

Drafts FDA 510(k) Premarket Notification submissions demonstrating substantial equivalence under 21 CFR Part 807. Supports Traditional, Special, and Abbreviated pathways. Use when preparing Class II medical device regulatory filings, substantial equivalence analyses, or FDA premarket submissions.

skill-name

11
from CaseMark/skills

Replace with a specific description of what this skill does and when to use it. Include keywords that help agents identify relevant tasks.

writing-surgical-consultation-notes

11
from CaseMark/skills

Creates structured surgical consultation responses with assessment and surgical candidacy determination. Use when responding to surgical consults, evaluating surgical candidates, or documenting surgical recommendations.