Applied Behavioral Analysis Services (ABAS)

ABAS Compliance Program

Policies, standards, and program documents
CFM-014

Breach Notification Templates Pack

Version 1.0Approved by Compliance Officer · 2026-08-19Review cycle: Annual

Instructions for Use

These templates support POL-014 (Breach Notification and Response) and the Breach Response Operation SOP (SOP-002). Form 1 documents the risk assessment that determines whether notice is required. Forms 2 through 6 are the notices, each carrying the content its statute or agreement requires.

Access and handling. Completed forms are part of the incident's compliance ticket and are handled under the access controls in POL-003 and POL-003-SOP. Form 1 is restricted to the Privacy & Security Officer and the Executive Director.

Approval. No notice in this pack is sent without the approvals in SOP-002. The Privacy & Security Officer prepares each notice and the Executive Director approves it before it is sent.

Realization. These templates may be completed on paper or as electronic documents. Any realization must carry every required element defined here and reference each form by its number. Bracketed fields are completed in every use. A bracketed element that does not apply is removed before sending.

Breach Notification Forms

Form 1: Breach Risk Assessment (Restricted)

Access level: Privacy & Security Officer and Executive Director

Use: Completed for every reported incident before any notification determination. The completed form is the record that rebuts or confirms the breach presumption. File in the ticket.

Ticket ID:

Date of report:

Date of discovery (per POL-014 Definitions):

Assessor:

Incident description (what happened, when, where, who was involved):


Information involved:

Was the PHI unsecured? ☐ Yes ☐ No (encrypted per HHS guidance; not a breach)

Encryption status / safeguards in place:

HIPAA analysis:

Was the Privacy Rule violated? ☐ Yes ☐ No (incidental disclosure against reasonable safeguards)

Does a POL-014 exception apply?

Four-factor assessment (45 CFR § 164.402):

  1. Nature and extent of the PHI involved, including identifiers and the likelihood of re-identification:
  2. The unauthorized person who used the PHI or to whom it was disclosed:
  3. Whether the PHI was actually acquired or viewed:
  4. The extent to which the risk has been mitigated:

Probability of compromise: ☐ Low (documented above; no HIPAA notice) ☐ Not low (HIPAA breach)

Massachusetts analysis (M.G.L. c. 93H):

Does the information meet the personal-information definition? ☐ Yes ☐ No

Unauthorized acquisition or use creating substantial risk of identity theft or fraud, or encrypted data acquired with its key? ☐ Yes ☐ No

Determination:

Individuals affected (count or estimate, and states of residence):

Massachusetts residents affected:

Social Security numbers involved? ☐ Yes (credit monitoring required, SOP-002 Step 6) ☐ No

Notice lanes triggered (from the SOP-002 Notice Lanes table):

Assessor signature / date:


Form 2: Individual Breach Notification Letter (HIPAA) (Template)

Use: Sent to each affected individual without unreasonable delay and no later than 60 days after discovery, by first-class mail to the last known address, or by email where the individual agreed to electronic notice. For a deceased client, the letter goes to the next of kin or personal representative if their address is known. If contact information is insufficient, the substitute-notice rules in POL-014 Section 4 apply and the substitution is documented in the ticket. If PHI may be subject to imminent misuse, telephone notice may precede this letter. The letter is still sent.

Sharing rules: State facts known at send time and supplement later as facts develop. The letter does not include: other individuals' information; investigation working-file detail; speculation, blame, or admissions of legal responsibility; internal system names.

Tone: Plain, factual, and respectful. Every required element below stays in the letter; write each in plain language.

Ticket ID (internal; does not print in the letter):

> Dear [name of the individual or their representative], > > We are writing to tell you about a privacy incident at Applied Behavioral Analysis Services that involved some of [your / your child's] health information. > > What happened: [a brief description of the incident, the date it occurred, and the date we discovered it] > > What information was involved: [the types of information, such as name, date of birth, address, diagnosis, treatment information, insurance information, or Social Security number] > > What we are doing: [the investigation, the steps taken to mitigate harm, and the changes made to prevent recurrence] > > What you can do: [protective steps matched to the information involved, such as reviewing statements from your health plan, monitoring accounts, or placing a fraud alert] > > For more information: Contact the Privacy & Security Officer at 413-461-7120 or privacy@abaswma.org, or write to Applied Behavioral Analysis Services, 432 State Street, Belchertown, MA 01007. > > We regret that this happened. > > [Name, role]


Form 3: HHS Breach Portal Checklist

Use: Both HHS lanes file through the HHS breach reporting portal (ocrportal.hhs.gov). For a breach affecting fewer than 500 individuals, complete this checklist when the breach is confirmed and hold it in the breach log. The calendar year's log entries file within 60 days after the year ends. For a breach affecting 500 or more individuals, file when the individual notices are sent and no later than 60 days after discovery.

Media lane: If the breach involves more than 500 residents of one state, the Executive Director directs notice to prominent media outlets serving that state on the same clock, carrying the same content elements as Form 2.

Ticket ID:

Filing lane: ☐ Under 500 (annual log) ☐ 500 or more (concurrent filing)

Portal fields, prepared before filing:

Filed by / date:


Form 4: Massachusetts Regulator Report, Attorney General and OCABR (Template)

Use: Filed with both the Attorney General and the Office of Consumer Affairs and Business Regulation as soon as practicable after a Massachusetts security breach is confirmed, and never delayed to determine the total resident count. Both offices provide online data breach reporting forms on mass.gov; the Attorney General's form asks for a copy of the resident notice (Form 5). Supplement the report as facts develop.

Ticket ID:

Required content, prepared before filing:

Filed by / date:


Form 5: Massachusetts Resident Notice (Template)

Use: Sent to each affected Massachusetts resident as soon as practicable, and never delayed to determine the total resident count. This notice and Form 2 are separate instruments. Where both apply, the resident receives both. The bracketed credit monitoring paragraph is included when Social Security numbers are involved and removed otherwise.

Sharing rules: The notice never states the nature of the breach or the number of residents affected (M.G.L. c. 93H). Do not reuse Form 2 content in this notice.

Tone: Plain, factual, and respectful.

Ticket ID (internal; does not print in the letter):

> Dear [name], > > We are writing to tell you about a security incident that may affect your personal information. > > Your right to a police report: You have the right to obtain a copy of any police report filed about this incident. > > Security freeze: You have the right to place a security freeze on your credit report with each consumer reporting agency (Equifax, Experian, and TransUnion). A security freeze prevents new credit from being opened in your name without your consent. There is no fee to place, lift, or remove a security freeze. To request one, contact each agency at [current contact information for each agency]. > > [Credit monitoring: We are offering you credit monitoring services at no cost to you for [18 or more] months, provided by [provider]. To enroll: [all information needed to enroll]. Accepting these services never requires you to give up any legal right.] > > For more information: Contact the Privacy & Security Officer at 413-461-7120 or privacy@abaswma.org, or write to Applied Behavioral Analysis Services, 432 State Street, Belchertown, MA 01007. > > [Name, role]


Form 6: Payer or Business Associate Notice (Template)

Use: Sent where a payer contract or business associate agreement requires notice of a privacy or security incident, on the agreement's clock and to the agreement's named contact. The Vendor and Contract Register (REG-002) identifies the agreements carrying notice duties. Confirm the agreement's required content before sending; add any element the agreement names.

Sharing rules: State findings at conclusion level. The notice does not include: other clients' or families' information; investigation working-file detail; speculation, blame, or admissions of legal responsibility. Content stays consistent with any parallel regulator filing.

Ticket ID (internal; does not print in the letter):

> Dear [contact name], > > Under [agreement name and notice provision], Applied Behavioral Analysis Services, LLC is notifying you of a privacy incident. > > What occurred: [category-level description and the dates of the incident and its discovery] > > Information involved: [the categories of information] > > Members or individuals affected under your agreement: [count or estimate] > > What we are doing: [containment, investigation, notifications underway, and prevention steps] > > Contact: Privacy & Security Officer, 413-461-7120, privacy@abaswma.org. > > [Name, role]

Retention

Completed forms are part of the incident's compliance ticket and are retained for six years per POL-014, stored securely with role-based access controls under POL-003-SOP.

The Privacy & Security Officer is custodian of the Breach Risk Assessment (Form 1) and of the breach log. Copies of every notice sent, with dates and delivery methods, are retained in the ticket for the same period.