If you received a notice that your medical information may have been exposed, contact the provider or insurer using a phone number or website you already know is genuine. Find out what data was involved, whether your account is secure, and what protections the organization offers. Then watch for signs that someone has used your medical identity. The steps that make sense depend on whether the exposed information was medical details, insurance or identity numbers, or account credentials—and whether there is evidence of misuse.
This guidance is based on U.S. federal resources. Privacy rules and reporting options differ in other countries.
First, verify the notice and contact the organization safely
Do not use a link or phone number in an unexpected email, text, or call to investigate a breach. The Federal Trade Commission (FTC) advises people not to give medical information to unexpected callers, emailers, or texters. Instead, type in the organization’s official website yourself or call a number from a bill, insurance card, or other trusted source.
Ask the provider, insurer, or company:
- What information about you was involved, and when did the exposure occur?
- Was a password, insurance identifier, Social Security number, payment information, or medical detail exposed?
- Has the organization secured the account or corrected the problem?
- What steps does it recommend, and does it offer free identity-theft insurance or credit monitoring?
Use the contact information in the notice only after independently confirming it. The FTC’s guidance on responding to a data breach is at IdentityTheft.gov/databreach.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Know what the notice should explain
For a breach of unsecured protected health information at a HIPAA-covered entity, the organization must notify affected individuals without unreasonable delay and no later than 60 days after discovering the breach. That is the organization’s deadline—not a deadline for you to report the incident or finish recovery steps. HHS says the notice should, to the extent possible, describe the breach and information involved, actions individuals should take, the organization’s investigation and mitigation, and how to contact it. See the HHS HIPAA Breach Notification Rule guidance.
HHS’s Office of the National Coordinator for Health Information Technology (ONC) explains that the requirement applies to most doctors, hospitals, other health care providers, and insurers when unsecured information is involved. Information encrypted so unauthorized people cannot read it is considered secure for this purpose. A notice may therefore concern information that was encrypted, or it may involve a service whose legal obligations differ; ask the organization what happened rather than assuming the notice means your records were read.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Watch for medical identity theft
Medical identity theft happens when someone uses your personal or insurance information to obtain care or prescriptions. Check mail, insurer portals, and billing records for signs such as:
- A bill or Explanation of Benefits (EOB) for treatment, equipment, or prescriptions you did not receive.
- Collections activity for medical debt you do not owe.
- Medical debt on a credit report that you do not recognize.
- A notice that you have reached a limit on your health benefits when you have not.
An EOB is an insurer’s summary of a claim; it is not necessarily a bill. Still, an unfamiliar claim deserves prompt follow-up with the insurer and the provider shown on the statement. The FTC’s medical identity theft guidance explains warning signs and recovery steps.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
If you find misuse, review records and correct errors
- Contact the organizations shown in the suspicious activity. Call the insurer and the doctor, clinic, hospital, pharmacy, laboratory, or other organization where the information appears to have been used. Use verified contact details.
- Request the relevant records. Explain that you believe your identity or insurance information was used without your permission, and ask how to obtain the records and dispute the claim, bill, or entry.
- Report inaccuracies to the organizations that hold them. Ask the provider and insurer to investigate and correct inaccurate billing or medical records. Keep copies of statements, correspondence, and case or reference numbers.
- Get a recovery plan. IdentityTheft.gov’s medical identity theft resource can guide you through steps when someone uses your information or health insurance to obtain care or prescriptions.
Focus first on correcting the medical and insurance records involved. A credit freeze or credit monitoring does not remove a false medical claim or fix a provider’s chart.
Match financial identity steps to what was exposed
Financial identity protections are not a universal remedy for a medical-record exposure. Consider them when the exposed information could be used to open accounts or impersonate you—for example, if the breach involved a Social Security number or other identity data. If the notice offers free credit monitoring or identity-theft insurance, the FTC says to take advantage of the offered services; review the terms so you understand what they cover and for how long.
Rank #4
- Check credit reports for unfamiliar accounts or inquiries if financial identity information may have been exposed.
- Consider a fraud alert or credit freeze if the exposed identifiers could be used to apply for credit. These are credit-file protections, not safeguards for medical records or health portals.
- Follow the organization’s account-security advice if login credentials were exposed. Contact it through a verified channel to learn how to secure the affected account.
The FTC’s step-by-step resource for a general breach is IdentityTheft.gov/databreach. Which steps are appropriate depends on the information involved and whether there are signs of misuse.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Know which rules and complaint route may apply
Providers and insurers covered by HIPAA
HIPAA applies to covered entities and their business associates; it does not automatically cover every company that handles health-related information. Some personal health records offered through a provider or health plan may be covered, while a stand-alone consumer health-record service may fall outside HIPAA. ONC’s health information privacy guidance explains these distinctions and points people with concerns about a non-HIPAA-covered online company to the FTC.
Recommended Free Tools
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Potential HIPAA or Part 2 violations
If you believe a covered organization violated your privacy rights, you can file a complaint with the HHS Office for Civil Rights (OCR). OCR says complaints generally must be filed within 180 days of when you knew about the alleged violation; it may extend that period for good cause. This is a complaint-filing period, not the HIPAA breach-notice deadline. See OCR’s complaint process.
Paper records
For paper insurance forms, prescriptions, or physician statements, ONC recommends safeguarding the information and shredding documents you no longer need. A cross-cut shredder can help with that narrow paper-disposal task; it cannot secure an online account or undo a digital exposure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




