What happens if your information is exposed

No security posture is a guarantee. What separates a well-run service from a poorly run one is not the claim that nothing will ever go wrong, but a defined, honest and time-bound response for the day something does.

Definition

Not every mistake is a breach

A breach is an impermissible use or disclosure of protected health information that compromises its security or privacy. The test is whether the information was actually put at risk, assessed against factors including its nature, who received it, whether it was actually viewed and whether the exposure has been mitigated.

An email sent to the wrong internal colleague who deletes it unread is handled differently from a database exposed to the open internet. Both are recorded and investigated; only one is likely to require notification.

RecordedEvery incident is logged and investigated, however minor
AssessedRisk evaluated against the statutory factors
NotifiedWhere risk is more than low, affected people are told
EscalatedRegulators, and at scale the media, are informed

The clock

Notification deadlines

Immediately

Containment. Stopping continued exposure takes priority over everything else, including notification.

Without undue delay

Investigation and risk assessment, documented as it proceeds rather than reconstructed afterwards.

Within 60 days

Written notice to each affected individual, describing what happened and what to do.

Within 60 days

Notice to the Secretary of Health and Human Services where 500 or more people are affected.

Annually

Smaller incidents reported to HHS in an annual log rather than individually.

What a notice must actually tell you

A notice that says only “we experienced a security incident” is not a compliant notice. It must be specific enough for you to judge your own exposure and act on it.

  • A brief description of what happened and when
  • The types of information involved
  • Steps you should take to protect yourself
  • What the organisation is doing to investigate and mitigate
  • Contact details for asking questions

If you receive one

Read what was involved. An exposed email address is a different problem from an exposed clinical record.

Change the password if account credentials are named, and anywhere you reused it.

Keep the notice. It is dated evidence if anything follows from the exposure.

Ask directly whether your specific record was among those affected.

Frequently asked

How quickly must I be told about a breach?

Without unreasonable delay and no later than 60 days from discovery. Containment comes first, but the 60-day outer limit is fixed.

What if fewer than 500 people are affected?

You must still be notified individually within the same 60-day window. The difference is that HHS is informed through an annual log rather than immediately.

Does a breach mean my landlord saw my diagnosis?

Not necessarily, and usually not. The notice must state which types of information were involved, which is exactly why that detail is required.

Is an email sent to the wrong person always a breach?

No. It is always recorded and assessed, but where the risk is demonstrably low — for instance an internal recipient who deleted it unread — notification may not be triggered.

What can I do if I think a breach was concealed?

File a complaint with the Office for Civil Rights. Failing to notify is itself a violation, and complaints of this kind are investigated.

Should I be worried about identity theft after a health data breach?

It depends entirely on what was exposed. The notice must tell you the categories involved so you can judge; credentials and identifiers warrant more action than an exposed appointment time.

Your privacy is not an afterthought here

Start a free evaluation and see exactly what your landlord will — and will not — receive.

Start free evaluation All privacy topics