Healthcare Data Breach Guide
Medical records and personal health information are extremely sensitive, and unauthorized exposure can have devastating consequences. Data breaches in the healthcare industry have steadily increased every year since 2009, with the highest number ever reported in 2025. That year, the federal government reported 772 healthcare data breaches that affected over 500 individuals across the U.S.
Home • What is a Data Breach? • Healthcare Data Breach Guide
- July 24, 2026
The U.S. Health Insurance Portability and Accountability Act (HIPAA) governs the privacy and security of digital health records for hospitals, doctors’ offices, and insurance companies. However, other companies that collect health information, such as fitness trackers and dieting apps, are not covered by HIPAA. Still, sensitive health information is protected by federal laws and regulations, giving affected individuals rights and options after their information is exposed in a breach.
- What Counts as a Medical Information Breach?
- What Should You Do Immediately After a Medical Records Data Breach?
- Can You Sue If Your Medical Records Were Exposed in a Data Breach?
- What Evidence Should You Keep After a Medical Records Breach?
- What Compensation May Be Available After a Medical Data Breach?
- How to Hold Companies Accountable for Medical Data Breaches
- Protect Your Health Information and Understand Your Legal Options
What Counts as a Medical Information Breach?
Under the Federal Trade Commission’s Health Breach Notification Rule, a medical information breach is any unauthorized acquisition of unsecured (i.e., non-encrypted or destroyed) identifiable health information.
The healthcare industry has become a main victim of external and internal cyberattacks, exposing patients’ personal health information. E-health data is most frequently targeted by hacking and IT incidents involving email and network services. Exposed information may include diagnoses, lab results, prescriptions, treatment history, insurance details, billing records, provider notes, and patient data collected by apps or trackers.
What Should You Do Immediately After a Medical Records Data Breach?
If you have received a data breach notice that your personal medical data has been compromised, take the following steps to protect your information, identity, and legal rights.
Read the Data Breach Notice Carefully
Under the Health Breach Notification Rule, certain organizations not covered by HIPAA must notify their customers, the FTC, and more if there is a breach of unsecured, individually identifiable health information. Health apps, connected devices, and similar products must comply. Consumers must be notified within 60 days and without unreasonable delay.
If your data was affected in a breach, you may receive a notification by mail or via email. The notice should identify the information exposed, when and how the breach occurred, which organization was involved, and any services being provided to affected consumers.
Save the Notice and Related Communications
Make sure to keep the breach notice, emails, letters, screenshots, patient portal messages, and any related documents.
Review Your Medical Bills and Explanation of Benefits Statements
Look for unfamiliar providers, services, prescriptions, medical devices, or claims on your medical bills and explanation of benefits statements.
Contact Your Healthcare Provider or Insurer About Suspicious Activity
Questionable charges to your provider or insurer should be raised with the provider or insurer first to determine whether they are errors or possible fraud. Then, you may report any unresolved issues through the appropriate fraud-reporting channels.
Change Passwords for Patient Portals and Insurance Accounts
If the data breach involved a specific account—for instance, a fitness tracker or app account, or your patient portal account for a provider or insurer—change your passwords and enable multi-factor authentication for the account.
Consider a Credit Freeze or Fraud Alert if Financial Data or SSNs Were Exposed
If you were affected by a data breach involving Social Security numbers, payment data, or other financial identifiers, you may want to freeze your credit, place fraud alerts, and review your credit reports. Visit IdentityTheft.gov for more recovery steps and information on credit freezes and identity theft monitoring.
New cases and investigations, settlement deadlines, and news straight to your inbox.
Can You Sue If Your Medical Records Were Exposed in a Data Breach?
If your medical records were exposed in a data breach, you may have grounds for a legal claim if the affected healthcare organization, insurer, employer health plan, vendor, or service provider failed to use reasonable safeguards or delayed notifying affected people. The statute of limitations for filing such a claim varies by state, so consult an experienced attorney to learn how long after a breach you have to take legal action.
What Evidence Should You Keep After a Medical Records Breach?
To support your personal recovery and maintain all possible legal options, keep the following evidence after a medical records breach.
- The Original Breach Notice: Save the original data breach notification letter or email, as it may identify the affected organization, the timeline, how data was compromised, and offer protections.
- Medical Bills and Insurance Statements: Save bills, Explanation of Benefits statements, claim denials, and notices involving unfamiliar services.
- Proof of Fraud or Identity Theft: Save fraud reports, account alerts, provider correspondence, insurance communications, police reports, and FTC identity theft reports.
- Records of Time and Expenses: Track the time you spend making calls, disputing bills, correcting records, freezing credit, replacing documents, or resolving identity theft. You may be able to recover compensation for the time and effort you invested.
- Screenshots and Patient Portal Message: Preserve digital evidence, including suspicious portal activity, login alerts, emails, text messages, and account notices.
What Compensation May Be Available After a Medical Data Breach?
After a medical data breach, victims may be able to receive various types of compensation through a class action, individual lawsuit, or mass arbitration action. You may be able to recover statutory penalties for violations of state and federal laws, as well as compensation for financial losses, loss of privacy, time and effort, and identity theft protection costs. However, no amount of compensation is guaranteed.
How to Hold Companies Accountable for Medical Data Breaches
Victims of privacy violations, such as healthcare data breaches, may have multiple legal options after a breach, including individual lawsuits, class actions, or mass arbitration. Individual lawsuits are filed by one person against the breaching entity, while class action lawsuits are filed by one person on behalf of an affected group. Mass arbitration occurs when companies include class-action waivers in their terms of service or contracts and face coordinated arbitration demands from large groups of individuals.
You may be able to join an existing class action or mass arbitration or start a new one for the data breach that affected you. An experienced data breach lawyer can advise you on the best option for your case and help you start or join an action.
Protect Your Health Information and Understand Your Legal Options
Medical record exposure is a serious violation of privacy that can have life-altering consequences on victims, from identity theft to financial losses. After a breach, it’s crucial to monitor your medical bills and insurance statements. If you received a healthcare data breach notice, contact Class Action U.
Class Action U’s goal is to simplify the process for individuals to join ongoing lawsuits by connecting them with our law firm partners who are ready to handle their cases. If you’ve been affected by a breach that could potentially lead to a class action lawsuit but hasn’t yet, we encourage you to share your information with us. For eligible participants in a class action, our site offers a straightforward way to sign up. View our list of current data breaches here.
New cases and investigations, settlement deadlines, and news straight to your inbox.