Healthcare organizations hold a great deal of sensitive data, which makes them attractive targets for attackers. If your information is exposed in a breach, knowing your rights and the right steps to take can meaningfully limit the damage — and help you act quickly instead of feeling powerless. A breach is unsettling, but it doesn't have to leave you defenseless; most of the protective steps are straightforward and within your control.
Your right to be notified
Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals when their unsecured protected health information is breached — generally without unreasonable delay and no later than 60 days after the breach is discovered. Larger breaches also require notification to HHS and, in certain cases, to the media in the affected area.
Steps to take if you're affected
- Confirm the notice is legitimate. Scammers impersonate breached companies to phish for more information. Verify through official contact channels, not links in an unexpected email or text.
- Take any protections offered, such as free credit monitoring or identity-theft services.
- Monitor your accounts and your insurance explanation-of-benefits statements for unfamiliar charges or services.
- Consider a credit freeze or fraud alert with the major credit bureaus.
- Watch for medical identity theft, where someone uses your information to obtain care or bill your insurer.
Watch for medical identity theft
Medical identity theft is especially damaging because it can put false information into your records and lead to surprise bills. Warning signs include:
- Bills for care or equipment you never received
- A collection notice for an unfamiliar service
- Errors in your medical record or your explanation of benefits
- Being told you've reached a benefit limit you never actually used
| Action | Why it helps |
|---|---|
| Review records and EOBs | Catch fraudulent or incorrect entries early |
| Request corrections | Remove false information from your chart |
| Report identity theft | Create a recovery plan and an official record |
Where to get help
You can report identity theft and get a personalized recovery plan from the FTC at IdentityTheft.gov. If you believe a HIPAA-covered organization mishandled your information, you can also file a complaint with the HHS Office for Civil Rights.
Understanding what a breach notice can and can't tell you
A breach notification explains what the organization knows at the time it's sent, which isn't always the full story — investigations can take time, and what was exposed may be clarified later. Read the letter for the specifics that matter to you: was it your name and contact details, your Social Security number, your clinical information, or your insurance data? The more sensitive the exposed data, the more protective steps are worth taking. Keep the notice; it's useful documentation if fraud later appears. And be wary of anyone who contacts you "about the breach" asking you to confirm personal details — legitimate organizations won't cold-call you to collect the very information that was just exposed.
Prevention going forward
You can't control every organization that holds your data, but you can reduce your exposure: use strong, unique passwords, enable two-factor authentication, be cautious with health apps, and review your records and benefit statements regularly so you catch problems early.