If your doctor, hospital, insurer, or health app tells you your records were exposed, federal law is already working in your favor: after a medical data breach, the organization holding your protected health information must notify you within 60 calendar days of discovering the incident, explain what was taken, and tell you how to protect yourself. Beyond that letter, you can freeze your credit, file a federal complaint, and in many situations sue under state law for the damage the breach caused. What you cannot do is wait. The most useful steps have deadlines of their own.
What Counts as a Medical Data Breach
Under the HIPAA Breach Notification Rule, a breach happens when someone accesses, uses, or shares protected health information (PHI) in a way that violates federal privacy rules and compromises the security or privacy of that data. That covers the obvious cases, like a hacker stealing thousands of patient files, and the less obvious ones, like an employee snooping through a neighbor’s chart or a billing company mailing records to the wrong address.
PHI is any individually identifiable health data in any form, electronic, paper, or spoken. Your name paired with a diagnosis counts. So do Social Security numbers in a billing file, insurance ID numbers, treatment records, lab results, payment information, and identifiers as ordinary as an email address or IP address when they are linked to your health information.
Any unauthorized access to PHI is presumed to be a reportable breach. The organization can rebut that presumption only by documenting a formal risk assessment showing a low probability the information was actually compromised. In practice, if you receive a notice, that presumption has already worked in your favor.
One important limit: the notification rules only apply to “unsecured” PHI. If a stolen laptop was properly encrypted to federal standards, the thief cannot read the files and no notice is required. When you do get a letter, it means the data was readable.
The 60-Day Notice and What It Must Contain
A covered entity (a health plan, provider, or clearinghouse) that discovers a breach of your unsecured PHI has to send you written notice without unreasonable delay and no later than 60 calendar days after discovery. Discovery is the first day anyone at the organization knew, or through reasonable diligence should have known, about the breach, not necessarily the day the breach happened.
The notice must be in plain language and must tell you five things:
- What happened, including the dates of the breach and its discovery, if known.
- The specific types of information involved, such as name, Social Security number, diagnosis codes, or account numbers.
- Steps you can take to protect yourself.
- What the organization is doing to investigate, limit the harm, and prevent it from happening again.
- How to reach them with questions, including a toll-free number, email address, website, or mailing address.
Notice comes by first-class mail to your last known address, or by email if you previously agreed to electronic communications. When the organization cannot reach 10 or more affected people, it must either post a conspicuous notice on its website homepage for at least 90 days or run a notice in major print or broadcast media in the affected area. The substitute notice has to include a toll-free number that stays live for at least 90 days so you can call and ask whether your information was involved.
Breaches affecting 500 or more people also get reported to the Department of Health and Human Services within the same 60-day window and appear on a public federal breach portal. Smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year.
What to Do in the First 30 Days
A breach notification is a starting point, not a filing. Move on it while the offers and protections are fresh.
Read the notice carefully. The type of data exposed determines what you actually need to do. A breach involving your name and an appointment date is very different from one involving your Social Security number, insurance ID, and diagnosis codes.
Accept the free credit monitoring or identity protection. Most breached organizations offer one to two years of complimentary service. Enrollment windows are short, and there is no reason to leave the offer on the table even if you plan to take stronger steps too.
Freeze your credit. A credit freeze blocks anyone (including you) from opening new accounts in your name until you lift it. Freezes are free at all three credit bureaus: Equifax, Experian, and TransUnion. You have to contact each one separately. A freeze is stronger than a fraud alert because it blocks access outright rather than flagging your file for extra verification.
Or set up a fraud alert. An initial fraud alert requires lenders to verify your identity before granting credit. You only need to contact one bureau, and it notifies the other two. If you have already experienced identity theft, you can place an extended fraud alert after filing a report at IdentityTheft.gov or with local police.
Watch for Medical Identity Theft
Health data breaches carry a risk most people overlook: someone using your identity to get medical treatment, fill prescriptions, or file insurance claims in your name. That can corrupt your medical record with another person’s diagnoses, allergies, or blood type, which is genuinely dangerous the next time you need care.
Review the explanation-of-benefits statements from your insurer for services you did not receive. HIPAA gives you the right to request a copy of your medical records, and after a breach it is worth doing to check for entries that do not belong to you. If you find something, ask the provider in writing to correct the record.
Filing a Complaint with HHS
If you believe a healthcare organization or its vendor violated your privacy rights or failed to follow the breach notification rules, you can file a complaint with the HHS Office for Civil Rights (OCR). OCR investigates complaints and has real enforcement authority: it can impose civil penalties, require corrective action plans, and refer cases for criminal prosecution.
You have 180 days from when you knew or should have known about the violation to file, though the Secretary of HHS can waive that deadline for good cause. Complaints can be submitted through the OCR online portal, by mail, or by email. Describe what happened, name the organization, and explain how you think the rules were broken.
OCR does not award money to individual complainants. Its job is enforcement against the organization, not compensation for you. That said, an OCR investigation can produce findings that strengthen a separate lawsuit, and the prospect of federal scrutiny often nudges organizations toward settlements with affected individuals.
Suing After a Medical Data Breach
HIPAA itself does not let you sue. Federal courts have consistently held that HIPAA contains no private right of action, so a lawsuit based solely on a HIPAA violation will be dismissed. Enforcement belongs to the Secretary of HHS and, for criminal cases, the Department of Justice.
You still have options under state law. People affected by medical data breaches routinely file suits for negligence, breach of contract, and violations of state consumer protection or privacy statutes. A negligence claim requires showing the organization owed you a duty to protect your data, failed to meet the standard of care for data security, caused your harm, and left you with actual damages such as out-of-pocket costs from identity theft or the time and money spent responding.
When a breach affects thousands of people, these cases often proceed as class actions. The main hurdle is proving concrete injury. Courts have increasingly accepted that the risk of future identity theft and the cost of protective measures can qualify as harm, but outcomes vary by state and circuit. Many breached organizations settle before trial, offering cash payments and extended monitoring specifically to resolve these claims.
Health Apps, Wearables, and the FTC Rule
If your data was collected by a health-tracking app, a fitness wearable, or a direct-to-consumer health service that is not part of a traditional provider or insurer, HIPAA probably does not apply. Those companies are usually not covered entities or business associates.
They are still regulated. The FTC’s Health Breach Notification Rule, amended effective July 2024, explicitly covers makers of health apps, connected devices, and similar products. The timeline mirrors HIPAA: notice to individuals within 60 calendar days of discovering the breach. Breaches affecting 500 or more people also require notice to the FTC at the same time and to prominent media outlets. Smaller breaches can be reported to the FTC annually.
Penalties the Organization Faces
Civil monetary penalties under HIPAA follow a four-tier structure based on culpability. The 2026 inflation-adjusted amounts:
- Tier 1, didn’t know and couldn’t reasonably have known: $145 to $73,011 per violation, up to $2,190,294 per calendar year.
- Tier 2, reasonable cause but not willful neglect: $1,461 to $73,011 per violation, same annual cap.
- Tier 3, willful neglect corrected within 30 days: $14,602 to $73,011 per violation.
- Tier 4, willful neglect not corrected within 30 days: $73,011 to $2,190,294 per violation.
The gap between Tier 3 and Tier 4 is where enforcement bites. An organization that finds a problem and stalls on fixing it faces minimum penalties five times higher than one that moves quickly.
Individuals who knowingly obtain or disclose PHI in violation of HIPAA can also face criminal prosecution: up to $50,000 and one year in prison for a basic violation, up to $100,000 and five years for obtaining PHI under false pretenses, and up to $250,000 and ten years for stealing health data for sale, personal gain, or to cause harm. The Department of Justice brings these cases, and while they are less common than civil enforcement, they do happen, particularly against insiders who snoop or sell patient information.