Ask the hospital what it found about access and data theft, exactly which of your information was involved, and how you can protect yourself and get your records. A ransomware attack can lock systems without proving that patient data was stolen—but ransomware operators or related malware may also copy or destroy data. The hospital’s findings, not the label “ransomware,” determine what you should do next.
Start with what the hospital knows about the incident
Ask for the hospital’s findings about your specific incident, and distinguish confirmed facts from what is still under investigation. Encryption can make records inaccessible; it does not, by itself, establish whether anyone viewed or copied them. HHS explains that ransomware may also involve data destruction, exfiltration, or other malware that does so (HHS ransomware guidance).
- When did you discover the incident, and what dates do you currently believe the intrusion or exposure occurred?
- Did your investigation find unauthorized access, viewing, copying, or exfiltration of patient information, or was the confirmed impact limited to encryption or disruption?
- What evidence supports that conclusion, and is the investigation complete or ongoing?
- Was the information encrypted or otherwise rendered unusable, unreadable, or indecipherable to unauthorized people?
- Did outside forensic investigators or law enforcement assist, and what can you share without compromising an investigation?
Under HIPAA, the Breach Notification Rule concerns breaches of unsecured protected health information (PHI). An impermissible use or disclosure is generally presumed to be a breach unless the organization establishes a low probability that the PHI was compromised using the rule’s risk factors, including the information involved, who received or used it, whether it was acquired or viewed, and mitigation. See HHS’s breach notification guidance. An attack alone does not answer whether your information was exposed or whether the notice rule applies.
Find out exactly which information was involved
Ask the hospital to identify the categories of unsecured PHI involved and whether your own records were among them. A general statement that “patient data” was affected is not enough to decide which precautions make sense.
#1 Best Overall
- Were my name, contact details, date of birth, Social Security number, medical record number, diagnoses, treatment details, prescriptions, insurance information, or financial information involved?
- Were my dependents’ or family members’ records involved?
- Was the information linked to enough identifiers to identify me?
- Were patient portal accounts, billing systems, paper records, or third-party vendor systems affected?
- Can you confirm in writing whether my account or a particular encounter was affected?
The kinds of information at stake can differ from one incident to another. In a 2026 enforcement announcement concerning a 2021 OSF Healthcare System attack, HHS’s Office for Civil Rights (OCR) said PHI for 53,907 individuals was exfiltrated. The agency listed driver’s license numbers, diagnoses and treatment, prescriptions, medical record numbers, provider names, service dates, financial account details, and health insurance information among the data types in that case. Those details describe that incident only; they do not establish what another hospital’s attackers accessed (HHS OCR’s OSF announcement).
Check the notice and the hospital’s response
If the hospital says a reportable breach of unsecured PHI occurred, ask when it discovered the breach, when it identified you as affected, and when it sent or plans to send your notice. Under the federal HIPAA baseline, individual notice must be provided without unreasonable delay and generally no later than 60 days after discovery, subject to a narrow law-enforcement delay provision.
Rank #2
The notice should briefly describe what happened, the types of information involved, steps you can take to protect yourself, the organization’s investigation and response actions, and contact information for questions. Written notice by first-class mail is standard; email may be used if you agreed to electronic notice. Ask:
- What containment, investigation, mitigation, and prevention steps have you taken?
- Which systems were unavailable, and has the incident affected my appointments, prescriptions, bills, or records?
- Who is the privacy officer or incident contact, and what verified phone number, email, or website should I use?
- If the investigation changes what you know about my data, how will you tell affected patients?
For federal reporting, the hospital—not the patient—is responsible for notifying the HHS Secretary. A breach affecting 500 or more people must be reported without unreasonable delay and within 60 days; a breach affecting fewer than 500 may be reported within 60 days after the end of the calendar year in which it was discovered. A covered entity also must notify prominent media outlets serving the area when a breach affects more than 500 residents of a state or jurisdiction. These are distinct from the individual notice deadline (HHS breach reporting guidance).
Recommended Free Tools
Choose precautions based on the exposed information
Ask what action the hospital recommends for the particular information involved. HIPAA requires a notice to identify steps affected people should take to protect themselves from potential harm, but the sources do not establish that every patient needs credit monitoring or that a hospital must provide it.
- If financial account or insurance information was involved, ask which bank, card issuer, insurer, or plan administrator you should contact.
- If portal credentials or other login information were involved, ask whether you should reset your password and use any account protections the hospital offers.
- If the hospital offers identity or credit monitoring, verify the offer through an official hospital contact before enrolling. Ask what data it monitors, what support it provides, how long it lasts, whether there are fees after a free period, and what data-sharing or cancellation terms apply.
Do not treat a monitoring offer as proof of what was stolen or as a universal remedy. Its relevance depends on the information involved and the actual terms of the service.
Rank #4
Keep access to your records and privacy information
A cyber incident may disrupt a portal or other system without ending your right to request records. Ask how to submit an access request and whether the hospital can provide records securely through another route while systems are restored. You can also request the hospital’s Notice of Privacy Practices, which explains permitted uses and disclosures, privacy duties, patient rights, complaint rights, and how to contact the organization (HHS Notice of Privacy Practices guidance).
Individuals generally do not have to explain why they want access to their records. HIPAA permits denial only in limited circumstances. If the hospital denies your request, ask for the reason in writing and for an explanation of any review or complaint options that apply (HHS guidance on access denials).
Best Value
Know where to raise a HIPAA concern
If you believe a covered entity or business associate violated HIPAA privacy, security, or breach-notification requirements, you can submit a complaint to HHS OCR through its online complaint portal. The portal says OCR generally may act on complaints filed within 180 days of the alleged violation or when you should have known of it, with possible exceptions. OCR may assess its legal authority, investigate, refer or resolve a matter with assistance, or close a complaint; filing does not guarantee an investigation.
Keep the questions and answers together
Save the notice, record the date and name of each hospital contact, and keep copies of written responses. If an answer is incomplete, ask the hospital to identify what is confirmed, what remains unknown, and when it expects to provide an update. Federal HIPAA is a baseline: state law, the facts in your notice, and any ongoing law-enforcement investigation may affect the details. No particular state or hospital is assumed here.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

