Issue 16Nothing here is sponsored

The Steady Report

Useful detail on decisions that are hard to reverse.


FileTech

Four Months Between the Breach and the Letter: What That Gap Actually Costs a Patient

A composite account of an ordinary healthcare breach notice, why it took a season to arrive, and what the people who acted on it found when they did.

  • BySylvia Achterberg
  • Cut9/23/25
  • Length1,149 words
  • Read5 min
An opened letter on a kitchen counter beside a pair of reading glasses and a mug, the envelope set to one side
An opened letter on a kitchen counter beside a pair of reading glasses and a mug, the envelope set to one side

The envelope arrived in the second week of July, looked like a statement, and sat unopened on a counter for two days. Inside, a dental group with four offices in one metropolitan area explained that it had determined in March that a staff email account had been reachable by an outside party for several weeks, and that the mailbox held patient names, dates of birth, insurance identifiers and, for some patients, Social Security numbers. What follows is a composite, assembled from how such notices are typically written and what recipients typically find when they act on one, and nothing in it is unusual.

What the Notice Said, and the Three Things It Left Out

The letter ran to two pages. The first described the incident in the passive voice and the past tense: an account was accessed, the practice became aware, an investigation was conducted with outside specialists, the account was secured. The second page listed the categories of information that may have been involved and offered complimentary credit monitoring with an enrollment code and a deadline underneath it. Read quickly, the whole thing seems to say very little, and a recipient who skims it comes away with an impression of vagueness rather than a plan.

Three things were absent, and their absence is standard rather than evasive. The letter did not say whether this particular patient record had been in the mailbox, because in a mailbox compromise the practice frequently cannot tell. It did not say whether the data had been used, because nobody knows that at the time of writing. And it did not say how the account was compromised, which is generally omitted while the matter is still open. The one genuinely useful sentence is the one naming the categories, since names and insurance identifiers are one kind of exposure and a Social Security number is another kind entirely, calling for a different response.

Why the Interval Between Discovery and Mailing Runs Long

The gap between March and July is the part patients find hardest to accept, and it has a mundane explanation rather than a cynical one. A compromised mailbox has to be reviewed message by message, often across tens of thousands of items and attachments, to determine which individuals appear inside it and what was said about each. That review is slow, it is usually handed to an outside firm, and its output is the mailing list itself. The letter cannot go out before that list exists.

State laws generally require notification without unreasonable delay, subject to an outside limit, while allowing the time reasonably necessary to determine the scope of an incident. Four months from discovery to mailing sits inside what most states permit. It is also long enough that a patient acting in July is acting well after anyone who wanted the data has had it, which changes what the first week of response is for. The point is no longer to get ahead of the exposure, since that window closed in the spring, but to make the exposure difficult to convert into anything.

The Monitoring Offer Set Beside the Tool That Costs Nothing

Credit monitoring is worth enrolling in and worth understanding for what it actually is. It watches for new accounts and inquiries reported to the bureaus and tells you after the fact. That makes it a detection service rather than a protective one. It runs for a fixed term, converts to a paid subscription unless canceled, and carries an enrollment deadline that is real. None of that argues for declining it, but it does argue against treating the enrollment code as the whole of the response.

The stronger tool sits alongside it and costs nothing at all. A freeze is a standing instruction to each of the three nationwide bureaus to release nothing from your file, and almost nothing in consumer credit is granted without that file being read first. It holds until you lift it, and federal law requires the bureaus to place and lift it free of charge. Anyone weighing a paid subscription against a free freeze can compare the two directly at the identity theft site run by the Federal Trade Commission, which is also where the recovery plan for an account that has already been opened in your name begins.

The Half Hour That Does Most of the Work

Freeze first, then enroll, and the order matters because the freeze is the protective step while the monitoring is only the alarm. Placing all three freezes takes roughly half an hour across three bureau websites and can be done in one sitting. After that, check the insurance side rather than the credit side alone, since an exposed insurance identifier carries the risk of medical services billed under your coverage, and reading the next several explanation of benefits statements line by line is the only practical way to catch that. Then keep the letter itself, filed where it can be found.

Three common responses repay none of the effort they take. Requesting a new Social Security number is available only in narrow circumstances, requires considerable documentation, and produces a person with no credit history, which causes its own problems for years. Paying for a subscription identity service while a free freeze sits unused is buying notification rather than prevention. Closing bank accounts that were never involved addresses a category of information the letter did not mention. Worth resisting too is the follow-up contact, since notices are reliably followed by calls from people who know one went out and who ask you to confirm details in order to help.

Two Patients, One Practice, Two Different Letters

Two patients of the same dental group living forty minutes apart on opposite sides of a state line will often receive materially different letters. State breach notification statutes differ on what counts as personal information, on how quickly notice must go out, on whether the state attorney general has to be told, and on what the practice must offer the people it writes to. Some states require identity theft protection whenever a Social Security number is involved, while others leave that to the practice. That is why the enclosed page headed with a state name is frequently more informative than the letter it accompanies.

That variation is also why calling the practice is worth the twenty minutes it takes. A local office generally knows which state rules it followed and can often say whether a particular record was among those reviewed, even when the letter itself cannot commit to that in writing. The patients who came out of this episode well were not the ones who worried the most about it. They were the ones who opened the envelope, spent thirty minutes in the first week placing freezes, read the following months of benefit statements with an eye on the billing, and filed the letter somewhere they could find it again.


Elsewhere in the pile

  1. 01Formed the Company and Filed Nothing Since? The Obligations That Keep an LLC in Existence
  2. 02An Attic Air Handler Makes Gallons of Water a Day and One Pipe Carries It Away
  3. 03Which Documents Are Impossible to Get Once a Dispute Has Already Turned Contentious?
  4. 04Bookkeeper, Enrolled Agent or CPA: Which One You Need Is a Question About the Year