What happens if your information is exposed
No security posture is a guarantee. What separates a well-run service from a poorly run one is not the claim that nothing will ever go wrong, but a defined, honest and time-bound response for the day something does.
Definition
Not every mistake is a breach
A breach is an impermissible use or disclosure of protected health information that compromises its security or privacy. The test is whether the information was actually put at risk, assessed against factors including its nature, who received it, whether it was actually viewed and whether the exposure has been mitigated.
An email sent to the wrong internal colleague who deletes it unread is handled differently from a database exposed to the open internet. Both are recorded and investigated; only one is likely to require notification.
The clock
Notification deadlines
Containment. Stopping continued exposure takes priority over everything else, including notification.
Investigation and risk assessment, documented as it proceeds rather than reconstructed afterwards.
Written notice to each affected individual, describing what happened and what to do.
Notice to the Secretary of Health and Human Services where 500 or more people are affected.
Smaller incidents reported to HHS in an annual log rather than individually.
What a notice must actually tell you
A notice that says only “we experienced a security incident” is not a compliant notice. It must be specific enough for you to judge your own exposure and act on it.
- A brief description of what happened and when
- The types of information involved
- Steps you should take to protect yourself
- What the organisation is doing to investigate and mitigate
- Contact details for asking questions
If you receive one
Read what was involved. An exposed email address is a different problem from an exposed clinical record.
Change the password if account credentials are named, and anywhere you reused it.
Keep the notice. It is dated evidence if anything follows from the exposure.
Ask directly whether your specific record was among those affected.
Frequently asked
How quickly must I be told about a breach?
Without unreasonable delay and no later than 60 days from discovery. Containment comes first, but the 60-day outer limit is fixed.
What if fewer than 500 people are affected?
You must still be notified individually within the same 60-day window. The difference is that HHS is informed through an annual log rather than immediately.
Does a breach mean my landlord saw my diagnosis?
Not necessarily, and usually not. The notice must state which types of information were involved, which is exactly why that detail is required.
Is an email sent to the wrong person always a breach?
No. It is always recorded and assessed, but where the risk is demonstrably low — for instance an internal recipient who deleted it unread — notification may not be triggered.
What can I do if I think a breach was concealed?
File a complaint with the Office for Civil Rights. Failing to notify is itself a violation, and complaints of this kind are investigated.
Should I be worried about identity theft after a health data breach?
It depends entirely on what was exposed. The notice must tell you the categories involved so you can judge; credentials and identifiers warrant more action than an exposed appointment time.
Your privacy is not an afterthought here
Start a free evaluation and see exactly what your landlord will — and will not — receive.
Start free evaluation All privacy topics