← Blog

Your Data Was in a Breach. Do These Things First.

Share on X

Finding out your data was in a breach is unnerving. It is also routine. Breach letters, state AG filings, and even those "Were you affected?" lawyer ads all mean the same thing: someone else lost control of information that describes you. What you do in the first 48 hours matters more than panic scrolling.

This guide is for people—not CISOs. Whether you got a formal notice from your bank, a hospital, or you saw headlines about an incident like the unverified Decatur Diagnostic Laboratory LockBit claim in Alabama, the playbook is similar. Move fast, document everything, and do not let criminals turn the breach into a second attack.

Start with the notice (or the headline)

If a letter or email arrived, read it twice. Legitimate breach notifications name the company, describe what happened in plain language, and list the categories of data involved—names, emails, Social Security numbers, health records, payment cards, and so on. They should give you a way to contact the organization directly, not just a random link.

No letter yet? You are still allowed to act. Many victims learn about exposure from news, leak-site trackers, or class-action solicitations before the company mails anything. HIPAA-covered entities, for example, have up to 60 days after discovery to notify patients. Waiting for paper is how people get hit by fraud first.

Write down: who lost the data, when they say it happened, and which fields they admit were exposed. That list drives every step below.

Freeze credit—or at least fraud-alert it

If Social Security numbers, dates of birth, or full addresses were involved, treat financial identity theft as likely—not theoretical.

You have two main tools in the United States:

  • Credit freeze — Blocks new lenders from pulling your file, which stops most new-account fraud cold. You must freeze (and later thaw) separately at Equifax, Experian, and TransUnion. It is free. This is the stronger option.
  • Fraud alert — Tells creditors to verify identity before opening accounts. One bureau notifies the others. Easier, but weaker than a freeze.

A freeze does not hurt your existing cards or score. It stops strangers from opening a car loan in your name while you sleep.

Change passwords that matter—and turn on MFA

Breaches often dump emails and passwords, sometimes from an entirely different site. Attackers run those pairs against banks, email, and shopping accounts.

Priority order:

  1. Email — Your inbox is the recovery key for everything else. Unique password + authenticator-app MFA.
  2. Financial accounts — Banks, brokerages, PayPal, anything that moves money.
  3. Medical portals — MyChart-style logins if health data was exposed.
  4. Any account that reused the breached password — Assume the old password is burned.

Use a password manager if you can. SMS two-factor is better than nothing, but app-based MFA beats text codes when SIM-swap risk is in play.

Healthcare breaches need a different checklist

Lab and hospital incidents—like the April 2026 unverified ransomware listing against Decatur Diagnostic Laboratory—are not just about credit cards. You cannot cancel your medical history.

Medical identity theft shows up in boring places:

  • Explanation of Benefits (EOB) statements from your insurer listing doctor visits you never had
  • Collection calls for hospital bills that are not yours
  • Errors in your chart—wrong allergies, wrong medications—because someone else was treated under your ID

Pull a free annual copy of your medical records from major providers and check your insurer's online claims history. Dispute bogus entries in writing, keep copies, and ask how the provider will flag your file against future fraudulent use.

Watch for the second wave: phishing

The cruelest part of modern breaches is that attackers know why you are anxious. A scam email that says "Your lab results are ready" or "Confirm your breach credit monitoring" lands right after a real incident.

Treat every unexpected message as hostile until verified:

  • Do not click links in breach-themed texts or DMs
  • Do not call phone numbers printed in suspicious emails—look up the company site yourself
  • Never give MFA codes, payment card numbers, or SSN digits to someone who contacted you first

Real breach-response vendors hired by companies will tell you in the official notice letter. Random "free monitoring" portals with typos are not that.

Document time and money

Keep a folder—email label, notes app, whatever you use:

  • The original breach notice (PDF or screenshot)
  • Dates you froze credit, changed passwords, or called insurers
  • Hours spent fixing fraud (some state laws and class settlements compensate lost time)
  • Receipts for credit monitoring you paid out of pocket

If fraudulent charges appear, dispute them with the bank immediately. If medical fraud appears, loop in your insurer and the provider's privacy office. In the U.S., you can report identity theft at IdentityTheft.gov, which generates a recovery plan and FTC report.

What not to do

Do not pay criminals who email claiming they will "delete" your leaked record. That is a secondary scam.

Do not ignore small breaches. A clinic with 150 patients and a hotel chain with reservation metadata can both enable targeted fraud—the hotel knows your stay dates; the clinic knows your diagnosis codes.

Do not assume "no financial data" means safe. Names + phone + booking details = convincing voice phishing. Names + DOB + NHS or insurance numbers = medical fraud.

When to escalate

Call a lawyer if you already suffered measurable harm—tax refund theft, denied medical coverage because your record was poisoned, or six-figure wire fraud. Many breach cases also run as class actions; that is optional, not mandatory, for protecting yourself.

Contact your state attorney general's consumer line if the company never notifies you despite a credible public breach claim. Regulators use those complaints to prioritize investigations.

The short version

  1. Read the notice and list what was exposed
  2. Freeze credit if SSN/DOB-class data was involved
  3. Fix email + bank passwords; enable MFA
  4. For health data: monitor EOBs and medical records
  5. Ignore breach-themed phishing; verify out-of-band
  6. Document everything

BreachHistory tracks verified disclosures and labeled unverified leak-site claims so you can see what is confirmed versus what is still actor marketing. Current example: Decatur Diagnostic Laboratory (unverified LockBit 5.0 listing, April 2026).

Sources: U.S. FTC IdentityTheft.gov guidance; HIPAA Breach Notification Rule overview (HHS); breach-notification practice summaries from state AG offices. Incident context: Ransomware.live LockBit listing, DeXpose monitoring report.