Home/Healthcare Access/Healthcare Data Breach
Healthcare & Digital Privacy

Healthcare Data Breach: Your Rights, Who to Notify, and What You Can Actually Recover

A healthcare data breach notice often reads like it gives you a lawsuit against whoever lost your records. It usually doesn't — HIPAA itself has no private right of action. Here is what actually happened, which laws genuinely let you seek money, and the realistic path from here.

At a Glance

60 days
Deadline for a HIPAA-covered entity to notify you after discovering a breach
180 days
Window to file a HIPAA complaint with HHS OCR after you knew about it
$1,000+
California CMIA statutory damages per violation — no proof of harm required [verify current cap]
No cap
GDPR Article 82 compensation for EU/UK breaches — assessed on actual harm, not capped

HIPAA Requires Notification — But Gives You No Right to Sue

If you received a breach notice from a hospital, clinic, insurer, or other HIPAA-covered entity, the notification itself is required by federal law: the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414) requires covered entities and their business associates to notify affected individuals "without unreasonable delay" and no later than 60 days after discovering a breach of unsecured protected health information. For breaches affecting 500 or more people in a state or jurisdiction, the entity must also notify prominent media outlets and the HHS Secretary immediately; smaller breaches are reported to HHS annually.

What the notice does not give you is a lawsuit under HIPAA itself. Courts have consistently held — and HHS confirms — that HIPAA creates no private right of action; you cannot sue a hospital or insurer directly for "violating HIPAA." What you can do is file a complaint with the HHS Office for Civil Rights (OCR) within 180 days of when you knew about the act or omission (OCR can extend this for good cause). OCR investigates, and for serious or widespread violations can extract corrective action plans and civil monetary penalties — but those penalties go to the U.S. Treasury, not to you.

This gap between "notified" and "compensated" is the central thing to understand: your realistic path to money after a healthcare data breach almost never runs through HIPAA directly. It runs through state law, class action litigation, or — for EU/UK residents — data protection law that does create a direct right to compensation.

What You Can Realistically Recover

The mechanism depends entirely on which law actually applies to your situation

HHS OCR complaint (HIPAA)

No direct payment to you — OCR can impose penalties on the organization and order corrective action, but the money does not come to you.

State private right of action (e.g., CA CMIA)

Statutory damages per violation without proving harm, plus actual damages and possibly attorneys' fees, where your state provides this right. [verify state-specific availability and amounts]

GDPR Article 82 (EU/UK)

Compensation for material and non-material damage, including justified fear of future misuse — assessed on your actual circumstances, not a fixed schedule.

Where the Real Money Rights Live: State Law and GDPR

Several states fill the gap HIPAA leaves open with their own medical-privacy statutes that do create a private right of action. California's Confidentiality of Medical Information Act (CMIA), Civil Code § 56.36, is the best-known: it lets a patient sue a healthcare provider or plan directly, and allows nominal statutory damages (commonly cited around $1,000 per negligent violation, without needing to prove actual harm) plus actual damages, and up to a higher amount for willful violations, plus attorneys' fees. verify current dollar figures and the exact willful-violation cap against the current statute text before relying on a specific number. A May 2026 California Supreme Court decision clarified the standard for what counts as a compensable CMIA breach in the data-breach context — check current case law if you are relying on this route. Other states have their own, narrower medical-privacy statutes; whether your state gives you an equivalent private right of action is state-specific and needs individual confirmation. verify state-by-state

Separately, many health apps, wearables, and direct-to-consumer services (period trackers, fitness apps, at-home test kits) are not HIPAA-covered entities at all, because they don't sit inside the traditional provider/insurer/clearinghouse relationship HIPAA regulates. The FTC's Health Breach Notification Rule — substantially amended in 2024, with the amendments effective July 29, 2024 — fills part of that gap: it requires vendors of "personal health records" and connected health apps/devices that are not HIPAA-covered to notify affected consumers, the FTC, and (for large breaches) the media, on a similar "without unreasonable delay, no later than 60 days" timeline. Like HIPAA, this FTC rule is enforced by the government, not by an individual lawsuit — the FTC can pursue penalties and injunctive relief, but again does not put money directly in your pocket through the rule itself.

If you are in the EU or UK, GDPR gives you something HIPAA does not: Article 82 creates a direct right to compensation from the controller (the healthcare provider, insurer, or app) for material or non-material damage caused by a breach of the GDPR, including a data breach. The Court of Justice of the EU has clarified there is no minimum-severity threshold — well-founded fear of future misuse of your data can itself count as compensable non-material damage — but you still need to show an actual breach, actual damage, and a causal link; compensation is meant to make you whole, not to punish the controller. You can also complain to your national data protection authority (the ICO in the UK) at no cost, in parallel with or instead of a civil claim.

When the Usual Rules Don't Apply

Not every breach triggers a notification duty. If the exposed data was properly encrypted or otherwise rendered "unsecured" only in a way that meets the HHS/NIST safe-harbor standard, it may not count as a reportable breach under HIPAA at all — you may never receive a notice even though a security incident occurred, because the law treats properly-secured data differently from readable data.

Many entities that feel like "healthcare" companies are not HIPAA-covered entities or business associates — a wellness app that never bills insurance or works with a provider, for instance — so a breach there falls to the FTC rule (if it applies) or general state consumer-protection and data-breach-notification law instead, not HIPAA. Don't assume HIPAA applies just because health information was involved.

Class action settlements arising from a large breach are common but are a different track from an individual OCR complaint or state private-right-of-action claim — check any settlement notice carefully for claim deadlines and whether accepting a settlement payment requires you to release other claims.

What to Do After a Healthcare Data Breach Notice

Different tracks for different goals — regulatory pressure, individual compensation, or class settlement

1

Read the notice carefully and save it

Note exactly what categories of information were exposed (e.g., name and address only, versus diagnosis codes, Social Security numbers, or financial account details) — this materially affects both your practical risk and which legal routes are worth pursuing.

2

Enroll in any free credit monitoring offered

Breach notices for larger incidents often include free credit monitoring or identity-theft protection for a limited enrollment window — sign up promptly if offered, and keep the confirmation.

3

File a HIPAA complaint with HHS OCR if a covered entity is involved

Complaints must generally be filed within 180 days of when you knew about the issue (extendable for good cause). This won't pay you directly, but can trigger investigation, corrective action, and penalties against the organization.

4

Check whether your state gives you a direct claim

California residents should look at the CMIA; other states may have their own medical-privacy or data-breach statutes with a private right of action. This is genuinely state-specific — what works in one state may not exist in another. verify your state's specific statute before assuming a right exists

5

Watch for class action notices

Large breaches frequently trigger multidistrict litigation or class settlements; if you receive a claims-administrator notice, read the deadline and the proof-of-loss requirements (some settlements pay a flat sum, others require documented out-of-pocket losses for a higher payout).

6

EU/UK residents: contact the ICO or your national DPA, or pursue an Article 82 claim

A regulator complaint is free and doesn't require a lawyer; a direct Article 82 damages claim is a separate civil route if you have suffered — or reasonably fear — concrete harm from the breach.

Documents to gather

  • The original breach notification letter or email
  • Any free credit-monitoring or identity-protection enrollment confirmation
  • Evidence of actual harm — fraudulent charges, new accounts opened in your name, collection notices for debts you don't recognize
  • Correspondence with the healthcare provider, insurer, or app about the breach
  • Any class action settlement claim notice you receive

Timelines and Deadlines

The notification deadline the organization owes you is different from the deadline for your own complaint or claim

Track two separate clocks: how quickly the breached organization had to notify you, and how long you have to act once you know.

JurisdictionLimitation Period
US — HIPAA breach notification to youWithout unreasonable delay, no later than 60 days after the covered entity discovers the breach
US — HHS OCR complaint window180 days from when you knew of the act or omission (extendable for good cause)
US — FTC Health Breach Notification RuleWithout unreasonable delay, no later than 60 days after discovery (non-HIPAA health apps/devices)
California — CMIA civil claimSubject to California's general statute of limitations for statutory claims verify exact limitation period for your specific CMIA claim
EU/UK — GDPR Article 82 claimSet by each member state's national limitation rules, not by the GDPR itself verify the limitation period in your specific country

Realistic Outcomes and Caveats

An HHS OCR complaint can lead to a meaningful corrective-action plan or penalty against a healthcare organization with a documented pattern of failures, but it is not a mechanism for individual compensation — treat it as a regulatory-pressure tool, not a payout.

State private-right-of-action claims (where they exist, like California's CMIA) can produce real statutory damages without needing to prove financial loss, but availability, dollar amounts, and procedural requirements vary sharply by state and by the specific facts of the breach — this is not a one-size-fits-all right.

Class action settlements from large breaches often pay a modest flat amount (commonly well under a few hundred dollars) unless you can document actual, provable losses like fraud-related costs, in which case some settlements offer a higher documented-loss tier.

GDPR Article 82 claims are genuinely individualized: courts weigh the seriousness of the breach and the reality of your fear or harm, and outcomes vary considerably by country and by the specific facts.

Common Pitfalls

Assuming HIPAA lets you sue the hospital or insurer directly

It does not — HIPAA has no private right of action. Your realistic path runs through OCR complaints (no payout), state law (where available), or class litigation.

Missing the 180-day OCR complaint window

This clock starts when you knew about the issue, not when you get around to filing — file promptly if you want the complaint considered on time.

Assuming a health app or wearable is HIPAA-covered

Many consumer health apps aren't HIPAA-covered entities at all; the FTC Health Breach Notification Rule, not HIPAA, is usually the relevant framework there.

Not checking your specific state's law

A right that exists in California under the CMIA may simply not exist in your state — don't assume a nationwide private right of action.

Missing a class action settlement claim deadline

These notices can look like spam. Read anything referencing a data breach settlement carefully before discarding it.

Organize Your Healthcare Data Breach Records

Use the calculator to identify which legal route may apply to your situation and organize the notice, dates, and evidence you'll need.

Organize Your Healthcare Data Breach Records

Use the calculator to identify which legal route may apply to your situation and organize the notice, dates, and evidence you'll need.

This stays in your private workspace until you choose a next step.

This stays in your private workspace until you choose a next step. It does not submit a claim on your behalf on its own.

Official and Legal References

US (Federal + State) vs. EU/UK Rights After a Healthcare Breach

Federal HIPAA in the US mandates notification but gives no private right of action — your OCR complaint pressures the organization, but doesn't pay you. Individual states may fill that gap (California's CMIA is the clearest example); non-HIPAA health apps fall under the FTC's Health Breach Notification Rule instead. The EU and UK take a different approach: GDPR Article 82 gives you a direct, individualized right to compensation for material or non-material harm from a breach, enforced through national courts and backed by your national data protection authority. Check which regime actually governs your situation before assuming a right you don't have — or missing one you do.

Frequently Asked Questions

The questions people ask right after opening a breach notice

Can I sue my hospital or insurer directly under HIPAA?

My period-tracking or fitness app got breached — does HIPAA cover that?

I live in California — is the CMIA automatically going to pay me?

This page provides general information about healthcare data breach notification and compensation rights as of July 2026. It is not legal advice. HIPAA, state medical-privacy laws, the FTC Health Breach Notification Rule, and GDPR each work differently and change over time — confirm current rules and deadlines with an attorney, your state attorney general, HHS OCR, or your national data protection authority before relying on any specific figure or deadline.

Organize Your Healthcare Data Breach Records

Use the calculator to identify which legal route may apply to your situation and organize the notice, dates, and evidence you'll need.

Organize My Records