Help Center / Notification letters

Notification letters

Generate jurisdiction-correct breach-notification letters that prefill from your incident, flag any missing required statutory fields, and export as text or PDF.

On this page

The nine letter templates

TemplateFor
Notice to Affected IndividualsThe consumer / patient notice letter.
Notice to State Attorney GeneralState AG / agency notice.
HHS OCR Breach Report SummaryHIPAA report summary to HHS Office for Civil Rights.
DFARS / DIBNet Cyber Incident Report SummaryThe DoD rapid-report package summary.
GDPR Art. 33 — Supervisory Authority NotificationThe EU DPA notification.
Media Notice (HIPAA 500+ in a jurisdiction)Prominent-media notice when 500+ residents of one state are affected.
PIPEDA — OPC Breach Report (Canada)Report to the Office of the Privacy Commissioner of Canada.
Québec Law 25 — CAI Confidentiality-Incident Notice (Canada)Notice to the Commission d'accès à l'information.
Substitute Notice — Website PostingUsed when direct notice is infeasible / a substitute-notice threshold is met.

Generating a letter

  1. Open the Letters tab.
  2. Pick a Template from the dropdown. If you have an incident open, a note shows it is prefilling from that incident.
  3. The left panel lists every merge field in the template. Required fields are marked with a red asterisk (*).
  4. Fill in the fields. The Preview on the right updates live as you type.
  5. When the required fields are filled, export the letter (below).

Prefill from the incident

If an incident is open, the letter auto-fills what it can from the incident facts so you're not retyping:

FieldPrefilled from
Incident date / Discovery dateThe incident's Discovered at (date portion).
Total affectedThe summed per-state affected count.
Data typesThe data-type checkboxes you set on the incident.
DateToday's date.

You always edit anything before exporting — prefill is a starting point, not a lock.

The missing-required-field guard

Each template declares which fields are statutorily required. If any are still blank, a red banner at the top of the preview lists them: "Missing required: ORG_NAME, …". Unfilled merge tokens also remain visible in the preview as [[FIELD]] so you can spot them. Fill the listed fields and the banner clears.

The guard checks that required fields are present — it does not and cannot judge whether your wording satisfies a regulator. That's a job for counsel.

Substitute-notice & credit-monitoring clauses

Exporting (.txt / print-to-PDF)

ButtonResult
Download .txtSaves the rendered letter as a plain-text file you can drop into your own letterhead / mail-merge.
Print / PDFOpens a clean print view; use your browser's "Save as PDF" to produce a PDF.

Filing-quality DOCX rendering is not currently produced — Klaxon generates the .txt / print-PDF package and a submission worksheet. See the FAQ on DOCX.

Optional AI narrative drafter

If — and only if — you have enabled the bring-your-own-key AI copilot (off by default), the Letters view offers to AI-draft the narrative field of a letter (the SUMMARY / ACTIONS / DESCRIPTION-type prose). Crucial guarantees:

If you have not enabled AI, a small tip points you to the AI Copilot tab; nothing AI-related runs otherwise.

Filing the letter (DIBNet / HHS)

The federal portals (DoD DIBNet, HHS OCR) have no submission API by design. Klaxon generates the letter and a submission worksheet; you file through the official portal yourself, then record the confirmation. After filing, return to the incident and Mark filed on that obligation, and log it in the communications log.

← Obligation clocks  ·  Next: Timeline integrity →