Your medical records were breached. What to do.

A health breach is the one kind where the damage can land in your medical chart as well as your credit file — and where the warning signs arrive in insurance paperwork most people never open.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

Read the notice for whether the Social Security number and insurance ID leaked as well as the clinical data. If they did, freeze your credit at all three bureaus, then start reading every explanation of benefits and the claims list in your insurer portal — treatment billed in your name is the harm unique to a medical breach, and no credit monitoring watches for it. Request a copy of your records from each provider, ask for an accounting of disclosures, and get anything false amended. Then take the household off people-search sites, because that is what turns leaked health data into a convincing phone call.

1. Work out which kind of data leaked

Health breaches are two breaches in one envelope, and the response differs. The identity half — name, date of birth, address, Social Security number, insurance member ID — is what funds fraud. The clinical half — diagnoses, prescriptions, test results, treatment notes — cannot be used to open accounts, but it cannot be reissued either, and it is what makes a later approach convincing. The notice has to list the categories, so read that list before doing anything. Under the HIPAA breach rule the letter is due without unreasonable delay and no later than 60 days after the organisation discovers the breach, and where 500 or more people in a state are affected it also has to tell the media and the federal regulator in that window.

2. If the Social Security number was in it, freeze your credit

Medical files carry Social Security numbers more often than people expect, because that is how billing and insurance eligibility have historically been keyed. If the number is on the list, freeze your file at Equifax, Experian and TransUnion. It is free, it does not touch your score, and it stops new accounts being opened in your name — which a monitoring service can only tell you about after the fact. You have to do all three separately. Do the same for children on the plan: a child on a family policy has records in the same system and a clean credit file worth more to a thief than yours.

3. Watch your insurance, not just your bank

This is the step specific to medical breaches and the one people skip. Someone using your identity to get treatment leaves a paper trail through your health plan, not your current account. Log in to the insurer portal and read the claims list; go through every explanation of benefits instead of filing it unread; and query anything you do not recognise, including small amounts. Bills or collection letters from clinics you have never visited, prescriptions you did not fill and a benefit limit reached early are the everyday signals. Report a suspect claim to the insurer’s fraud line, and start the recovery paperwork at IdentityTheft.gov if something has already gone through.

4. Ask for your records — and for who else has seen them

You have the right to a copy of your own medical record, and providers generally have 30 days to hand it over. Request one from each provider involved and read it for entries that are not yours. Separately, ask for an accounting of disclosures: HIPAA lets you be told who your information was shared with over the past six years, excluding routine treatment and billing traffic. Both requests are free at least once a year, and after a breach they are the only way to see what actually happened to your file rather than what the notice summarised.

5. Correct the record if someone was treated as you

This is what makes medical identity theft different from the financial kind. A stranger’s treatment, allergies and blood type get written into your chart, and that file is what a doctor reads when you turn up unconscious. You cannot delete another person’s entries, but HIPAA gives you the right to request an amendment; the provider has to respond within 60 days, and if they refuse you can file a statement of disagreement that has to travel with the record from then on. Do it with every provider, insurer and pharmacy that received the false information, because correcting one does nothing to the copies held elsewhere.

6. Expect the calls and letters that follow the notice

A health breach is a gift to fraudsters because it hands them a real, checkable event to reference. The recurring ones: a caller “verifying your details for the settlement”, a fake claim site standing up days after any lawsuit is filed, an enrolment page for identity protection that collects exactly the data that leaked, and a request to confirm your insurance member number so benefits can be “reinstated”. If the clinical half of your file leaked, the approaches get specific — a caller who knows your condition and your medication sounds like they belong. Hang up and dial the number printed on your insurance card or on the provider’s own site, never one supplied in the message.

7. Remember the health data that HIPAA never covered

Plenty of your health information sits outside the system this guide has been describing: symptom and period trackers, fitness and sleep apps, connected scales and cuffs, direct-to-consumer genetic tests, wellness programmes bolted onto an employer benefit. HIPAA does not reach them. Since 2024 the FTC’s Health Breach Notification Rule does, and it treats an unauthorised disclosure — data handed to advertisers or partners without your say-so — as a breach in its own right. Practically: delete the accounts you no longer use, turn off data sharing in the ones you keep, and check whether a password from any of them is already circulating with our password check.

8. Shrink the public half of your profile

The stolen records are out of reach; nobody can pull them back. What is still in your control is the public layer that makes fraud built on them workable — the data brokers and people-search sites publishing your address, phone number, age and relatives, which is how a caller with your diagnosis also knows where you live and who your family is. Removing that does not undo the breach, and it does make the follow-up harder. Our data-broker opt-out guide has the free, site-by-site route, and what to do after a data breach covers the general steps in order.

See what a caller could already look up about you

PersProtect finds where your name, address, phone number and relatives are published across 499 broker and people-search sites and files the removals for you. Start with a free scan.

Check my exposure — free →

Where this stands, August 2026

Three health-sector cases moved in the same few weeks. Read together they show where medical records actually leak from now, and it is rarely the clinic whose name is on the door.

Abbott confirmed health data is in the stolen files

On August 5 the company updated its own statement on the intrusion into its Exact Sciences cancer-screening business: some of the affected files do contain personal information and health information, the review is still running, and the required notifications to individuals have not gone out yet. It also describes the break-in as a vishing attack, meaning staff were talked out of their credentials by phone rather than hit with encryption malware. Two days later the records themselves were published. What was exposed, and why an email check will not confirm it →

A billing vendor nobody has heard of reported 3.8 million patients

Unlimited Technology Systems, an Ohio company that runs billing and revenue-cycle software for oncology and specialty practices, posted a breach covering 3,803,750 people to the federal HHS breach portal on August 6. The intrusion itself ran over five days in October 2025 — nine months before the number became public. Nobody in that count chose the vendor or knew it held their file; they picked a clinic, and the clinic picked the software. What was in the file, and what the notice does not cover →

One vendor breach, letters arriving from clinics you did use

Aesto Health, an Alabama healthcare technology company, has reported that patient information stored in its systems was accessed in December 2025, worked out in late May 2026 what had been taken, and began telling its client organisations in June. Those clients are now writing to their own patients, which is why a letter can arrive from a practice you recognise about a breach at a company you have never heard of. The reported categories are the heavy ones: dates of birth, medical information, insurance and financial account details, government ID and Social Security numbers.

Two threads run through all three. The first is the subcontractor: the organisation that lost the data is usually not the one you dealt with, so the name on the envelope may be new to you and there is no account anywhere to secure. The second is the delay — months between the intrusion and the letter, and that gap is exactly when the file is worth the most to whoever bought it. If you are waiting to be told before you act, the steps below are the ones worth starting anyway.

Sources: the companies’ own breach notices, the federal HHS Office for Civil Rights breach portal, and healthcare and security press reporting through mid-August 2026.

Common questions

Medical breaches, answered

Can I freeze my medical records the way I freeze my credit?

No. There is no central medical file to lock and no bureau to call, because your records sit separately with every provider, insurer, lab and pharmacy that has ever treated or billed you. A credit freeze still matters, because a health file almost always carries the Social Security number that opens new accounts — but it does nothing about treatment billed in your name. For that side, the working equivalent is attention: read the claims your insurer processes, ask each provider for a copy of your record, and query anything you did not receive.

How would I even know someone used my insurance?

It shows up in paperwork most people bin. An explanation of benefits for a visit you never made, a bill or a collection notice from a clinic you have never heard of, a prescription refill you did not request, or a letter saying your benefit limit for the year has been reached. Later signals are worse: a denial because your plan already paid for the procedure you are asking for, or a detail in your chart — a blood type, an allergy, a diagnosis — that is not yours. Log in to the insurer portal and read the claims list rather than waiting for the post.

What is an accounting of disclosures, and why would I ask for one?

It is a right under HIPAA to be told who a provider or insurer shared your health information with, going back six years. Routine disclosures for treatment, payment and running the practice are excluded, so it will not list every fax to a specialist — but it does surface the ones outside that, and it is free at least once a year. After a breach it is a reasonable way to find out where your records travelled beyond the organisation that wrote to you.

The notice says the breach was at a billing company, not at my doctor. Does that change anything?

Not for you. Healthcare runs on subcontractors — billing services, claims clearinghouses, transcription vendors, imaging archives, patient-communication platforms — and under HIPAA these business associates hold the same duty to protect the data. One intrusion at a vendor reaches every practice that uses it, which is why a notice can arrive from a name you have never dealt with. The exposed data and the steps are identical either way.

Can I sue, or get money, over a HIPAA breach?

Not under HIPAA itself — it gives no private right of action, so you cannot sue for a HIPAA violation. What you can do is file a complaint with the HHS Office for Civil Rights, generally within 180 days of finding out, which is what drives investigation and penalties against the organisation. Money, when it appears, comes through class actions brought under state negligence and consumer-protection law, and those take years. Breaches of 500 or more people are listed publicly on the OCR breach portal, so you can check what the organisation reported.

Is my health app covered by HIPAA?

Usually not. HIPAA covers providers, health plans, clearinghouses and their contractors. A fitness tracker, a period or diet app, a connected blood-pressure cuff or a direct-to-consumer genetic test is generally outside it, even though the data is as sensitive. Those fall under the FTC Health Breach Notification Rule, amended in 2024 to say so plainly: they have to notify you, and the FTC, when identifiable health data is exposed — including when it was disclosed without your authorisation rather than stolen.

They offered free credit monitoring. Is it worth taking?

Take it, enrol before the deadline, and be clear about what it does. It watches the credit system: new accounts, inquiries, addresses attached to your file. It does not watch claims made against your health plan or records held by a clinic, which is the part specific to a medical breach. So enrol, and keep reading your explanations of benefits yourself — nothing on offer does that for you.

The records are gone. The rest of your profile does not have to be.

See which sites are publishing your address, phone and relatives right now — free, in about a minute.

Run a free exposure scan →