Medical records leak: what to do when your health data is exposed

Breach / exposure. Updated 2026-09-13. About 5 minutes to read.

Read every benefit or claims statement for the next year and request your records from the provider named in the breach, because medical identity theft shows up there first.

Health data breaches are now routine and very large. The 2024 ransomware attack on Change Healthcare, a US claims processor, affected about 192.7 million people according to its filing with federal regulators. In Australia, the 2022 Medibank breach affected 9.7 million current and former customers. In the UK, criminals published stolen NHS pathology data from Synnovis in June 2024.

You cannot change a diagnosis the way you change a password. What you can do is catch anyone using your insurance or identity for treatment, correct your records, and shut down the scams that follow. This guide shows how, in order.

What recent health breaches exposed

  • Change Healthcare (discovered February 2024): health insurance details, diagnoses, Social Security numbers, driver's licence and passport numbers, and billing and payment data. The parent company paid a ransom and the data was still not deleted.
  • Medibank (October 2022): names, dates of birth, Medicare numbers and claims data, some of it published by the attackers. The OAIC began civil penalty proceedings in June 2024.
  • Synnovis (June 2024): an attack on the NHS pathology supplier disrupted London hospitals, and the criminals published patient names, NHS numbers and descriptions of blood tests.

A breach notice often arrives months after the attack. Synnovis's investigation took more than a year because the stolen data was unstructured. Start checking now rather than waiting for a letter.

What leaked health data lets criminals do

  • Medical identity theft: using your name and insurance number to get treatment, prescriptions or equipment, which puts false entries in your record.
  • Insurance and billing fraud, which can use up benefit limits or send debts to collectors in your name.
  • Extortion: criminals may threaten to publish sensitive conditions. In Finland in 2020, therapy patients of Vastaamo were emailed ransom demands after its records were stolen.
  • Convincing phishing: a caller who knows your doctor, your test date and your member number sounds genuine.
  • Standard identity theft when government ID or Social Security numbers are included.

Check for medical identity theft

  1. United States: read every Explanation of Benefits from your insurer and every Medicare Summary Notice. Look for providers, dates and services you do not recognise.
  2. Australia: open your Medicare online account through myGov and review your claims history, then check your private health fund's claims list in its app.
  3. United Kingdom: open the NHS App and check your GP record, prescriptions and appointments for anything you did not have.
  4. Pull your credit reports and look for medical collections you do not recognise. In the US use AnnualCreditReport.com.
  5. Watch for warning signs the FTC lists: bills for care you did not receive, calls from debt collectors about medical debt, or a notice that you have reached your benefit limit.

Request your records and correct errors

  1. United States: ask each provider and insurer for a copy of your records under HIPAA. They generally must respond within 30 days, with one 30-day extension allowed. Ask for an accounting of disclosures as well.
  2. United Kingdom: send a subject access request to the organisation. The ICO says organisations usually have one month to respond, and it is normally free.
  3. Australia: ask the provider for access under the Australian Privacy Principles. Government health services must generally respond within 30 days.
  4. Dispute errors in writing, by tracked or certified post, and keep copies. The FTC says a US provider must respond to a correction request within 30 days.

Wrong blood types, allergies or diagnoses added by an impostor can affect your real treatment. Ask your provider to flag the disputed entries while they investigate.

Lock down the numbers that were exposed

  1. Ask your insurer or health fund for a new member number if yours was in the breach.
  2. US Medicare: call 1-800-MEDICARE and ask about a new Medicare number if yours is being misused. Australian Medicare cards can be replaced through Services Australia.
  3. If a Social Security number was exposed, freeze your credit at all three US bureaus and get an IRS Identity Protection PIN.
  4. In Australia, call IDCARE on 1800 595 160. In the UK, consider Cifas Protective Registration if ID documents were included.
  5. Report misuse at IdentityTheft.gov in the US, or to Report Fraud in the UK at reportfraud.police.uk or 0300 123 2040.

If criminals contact you about your health data

Do not reply, pay or click links in an extortion email. Keep it, report it to police and tell the organisation that was breached. Paying does not delete stolen data, as Change Healthcare's own ransom payment showed.

Treat any call about your treatment, test results or refunds as suspect. Hang up and call the number on your insurance card or your provider's website.

Keep a breach file with the notice letter, the dates you checked statements, every call you made and the reference numbers you were given. If a false debt or wrong record appears a year later, that file is what gets it removed quickly.

Frequently asked questions

Can I get my health data removed after a breach?

No. Once copied, it cannot be recalled. You can correct your records, change insurance numbers and watch for misuse.

Who regulates health data breaches?

In the US, the HHS Office for Civil Rights. It investigates breaches affecting 500 or more people. In Australia, the OAIC runs the Notifiable Data Breaches scheme, and health service providers were the top reporting sector in its January to June 2025 figures. In the UK, it is the ICO.

Can my NHS number be changed?

Generally no. It is an identifier, not a password. Focus on watching your NHS App record and being wary of calls that quote it.

Is credit monitoring enough?

No. Medical identity theft often never touches your credit file. Reading benefit and claims statements catches far more of it.

Should I accept the free monitoring in the breach letter?

Usually yes, as long as you enrol by typing the provider's web address yourself rather than following a link, and you use the code printed in the letter. Monitoring alerts you after something happens, so keep reading your statements as well.

Tools that help

Related guides

Sources