CipherWatch All articles
Account Security

Your Medical Records Are in the Wrong Hands: What to Do After a Healthcare Data Breach

CipherWatch
Your Medical Records Are in the Wrong Hands: What to Do After a Healthcare Data Breach

Photo: hospital data breach medical records cybersecurity doctor office computer, via media.consumeraffairs.com

In February 2024, a cyberattack on Change Healthcare — a subsidiary of UnitedHealth Group that processes roughly one-third of all US medical claims — disrupted billing and prescription services at hospitals and pharmacies across the country. Months later, the company confirmed that the personal and health information of potentially 100 million Americans had been compromised, making it one of the largest healthcare data breaches in US history.

For most of those individuals, the first indication that something had gone wrong was a letter in the mail. For many, that letter arrived long after their data had already circulated on criminal forums.

Healthcare breaches are not isolated events. According to the Department of Health and Human Services breach portal — informally known as the "Wall of Shame" — hundreds of covered entities report breaches affecting 500 or more individuals every year. The data exposed in these incidents is not limited to names and email addresses. It typically includes Social Security numbers, insurance policy identifiers, diagnosis codes, prescription histories, and billing records. In the wrong hands, that combination enables medical identity theft, insurance fraud, and financial crimes that can take years to unwind.

If you have received a breach notification from a healthcare provider or insurer, here is what you should actually do.

Understand What Was Exposed Before You Act

Not all healthcare breaches are equivalent. A notification letter is required by HIPAA to specify the categories of information involved, the approximate date of the breach, and the steps the covered entity is taking in response. Read this section carefully before doing anything else.

The risk profile differs significantly depending on what was compromised:

If the notification letter is vague about what was exposed, you have the right under HIPAA to request a more detailed accounting from the covered entity directly.

Your Rights Under HIPAA

The Health Insurance Portability and Accountability Act establishes baseline protections for patients whose health information is held by covered entities — hospitals, clinics, insurers, and their business associates. When a breach occurs, HIPAA requires covered entities to notify affected individuals within 60 days of discovering the incident, though in practice many notifications arrive considerably later.

Beyond breach notification, HIPAA grants you several rights that are particularly relevant after a compromise:

Complaints about HIPAA violations, including inadequate breach notification, can be filed with the HHS Office for Civil Rights at hhs.gov/ocr.

Immediate Steps: The First 72 Hours

Place a fraud alert or credit freeze. Contact any one of the three major credit reporting agencies — Equifax, Experian, or TransUnion — to place an initial fraud alert. This prompts lenders to take additional verification steps before opening new accounts in your name, and the alert is automatically shared with the other two bureaus. A credit freeze is more restrictive and more protective: it prevents new credit from being opened in your name entirely until you lift it. Freezes are free and can be managed online at each bureau's website.

File an identity theft report with the FTC. IdentityTheft.gov is the federal government's centralized resource for identity theft victims. Filing a report there generates a personalized recovery plan, pre-filled dispute letters, and documentation that is recognized by creditors and law enforcement.

Contact your health insurer directly. Request a copy of your Explanation of Benefits (EOB) statements for the past 12 months and review them for services you did not receive. If your insurer has issued you a new member ID following the breach, activate it immediately and destroy the old card.

Alert your financial institutions. If your Social Security number or payment information was included in the breach, notify your bank and credit card issuers. Many institutions will proactively monitor for suspicious activity or reissue account numbers upon request.

Long-Term Monitoring: The Threats That Emerge Over Months

Healthcare data breaches are unusual in that their consequences frequently surface long after the initial incident. Medical identity theft in particular can lie dormant for months before a fraudulent claim triggers a collections notice or a benefits denial.

Monitor your credit reports regularly. Under federal law, you are entitled to a free credit report from each bureau annually at AnnualCreditReport.com. Following a significant breach, reviewing all three reports on a rotating quarterly basis is prudent. Look for accounts you did not open, inquiries from lenders you did not approach, and addresses you have never lived at.

Request your medical records annually. Reviewing your records at your primary care provider and any specialists you see regularly allows you to identify fraudulent entries before they affect your care. Incorrect diagnoses introduced by medical identity thieves have, in documented cases, led to patients being denied insurance coverage or receiving inappropriate treatments.

Watch for targeted phishing using your health data. Criminals who obtain detailed health records sometimes use that information to craft highly convincing phishing messages — for example, emails purporting to be from your actual insurance company referencing your specific plan or a recent procedure. Treat any unsolicited communication that references your health information with heightened skepticism, and verify by calling the organization directly using a number from their official website.

Check the IRS for tax identity theft. If your Social Security number was exposed, a fraudulent tax return filed in your name could delay your legitimate refund. Creating an account at IRS.gov and enrolling in the Identity Protection PIN program — which assigns a unique six-digit PIN required to file your federal return — is one of the most effective preventive measures available.

Free Credit Monitoring Offered by Breached Entities: Should You Accept It?

Most breach notification letters include an offer of free credit monitoring, typically for one or two years, through a third-party service. These offers are worth accepting, but with clear-eyed awareness of their limitations.

Credit monitoring detects new-account fraud relatively well. It does not detect medical identity theft, insurance fraud, or the misuse of your health records in ways that do not appear on a credit report. Accepting the offer does not require you to waive any legal rights — read the enrollment terms carefully to confirm this before signing up, and note the expiration date so you can arrange independent monitoring before coverage lapses.

The Broader Context

The healthcare sector has become one of the most targeted industries for ransomware and data theft, in part because patient data commands a premium on criminal markets — a complete medical record can sell for significantly more than a credit card number, which can be cancelled and reissued. The combination of sensitive personal identifiers, insurance credentials, and health history creates a profile that is difficult for victims to fully remediate.

The steps outlined here will not undo a breach that has already occurred. What they can do is substantially narrow the window in which criminals can act on the information they obtained — and ensure that when fraudulent activity does surface, you are positioned to dispute it with documentation, legal standing, and a clear record of the actions you took.

All Articles

Related Articles

Every Lightbulb Is a Door: The Hidden Cyber Risks Living Inside Your Smart Home

Every Lightbulb Is a Door: The Hidden Cyber Risks Living Inside Your Smart Home

Beyond the Password: What Passkeys, Biometrics, and Hardware Keys Actually Mean for Your Security

One Vault to Rule Them All: The Hidden Risks Inside Your Password Manager

One Vault to Rule Them All: The Hidden Risks Inside Your Password Manager