If your hospital or health system tells you it was hit by a cyberattack, treat the exposure as real and act on three fronts: freeze your credit, lock down your online accounts, and watch your medical records. The Federal Trade Commission directs breach victims to IdentityTheft.gov/databreach for a personalized step list, and if a Social Security number was exposed, that walkthrough covers fraud alerts, freezes, and free credit reports. A hospital cyberattack usually means a breach of protected health information — the medical, insurance, and identity data a provider holds. This checklist tells you what to do first, what protects you, and where those protections stop.
Table of Contents
- Freeze your credit at all three bureaus
- Freeze or fraud alert — which do you need?
- Lock down passwords and existing accounts
- Watch your medical records, not just your credit
- Why act before you get an official notice
- Frequently Asked Questions
Freeze your credit at all three bureaus
A credit freeze blocks new lenders from pulling your file, which stops most new-account fraud before it starts. Since a 2018 federal law, anyone can place, lift, or remove a freeze for free — you no longer need to be a confirmed fraud victim, and a freeze does not affect your credit score, per the Federal Trade Commission.
The catch is that a freeze does not carry over between bureaus. You must set it separately at each of the three: By law, a bureau must place a freeze within one business day when you ask online or by phone, and lift it within one hour the same way, the FTC says. That one-hour thaw matters: you can unfreeze briefly to apply for a loan, then re-freeze.
- Equifax — 1-800-685-1111
- Experian — 1-888-397-3742
- TransUnion
Freeze or fraud alert — which do you need?
These are two different tools, and you can use both. A freeze blocks access to your credit file entirely. A fraud alert leaves the file open but forces businesses to verify your identity before issuing new credit. The fraud alert has one convenience the freeze lacks.
Contacting just one of the three bureaus places a free alert on all three, according to FTC consumer guidance — no separate calls required. A freeze is stronger protection; a fraud alert is faster to set and easier to live with. For a hospital breach that exposed identity data, the freeze is the higher-confidence choice. Use a fraud alert as a lighter step if you expect to apply for credit soon and don't want to manage three separate thaws.
Lock down passwords and existing accounts
A freeze protects new accounts, not the ones you already have. The FTC is explicit that victims must still change passwords, turn on multi-factor authentication, and monitor current statements, because a freeze does nothing for existing accounts or medical records. Start with the accounts tied to the breached provider and any that share a password with it:.
- Change the password on your patient portal and insurer login first.
- Replace any password you reused elsewhere — attackers try stolen credentials across sites.
- Turn on multi-factor authentication wherever it is offered.
- Watch for phishing calls and emails that reference the breach; criminals use real incidents as cover.
Watch your medical records, not just your credit
Medical breaches enable medical identity theft — someone using your details to get care, drugs, or billing under your name. That fraud shows up in places a credit report never does. Security firm Bitdefender advises reviewing your insurer's Explanation of Benefits statements and your patient-portal records for care you did not receive.
Read those documents line by line. A prescription you never filled, a visit you never made, or a claim from an unfamiliar provider is a warning sign worth reporting to your insurer immediately. You may also be owed help. Organizations that suffer a breach involving personal information are often required to offer free credit monitoring and identity-theft protection, which the FTC says patients should request directly from the breached provider.
Why act before you get an official notice
Notification can lawfully lag the attack by weeks. The HIPAA Breach Notification Rule gives covered entities and their business associates up to 60 calendar days from discovering a breach to notify affected individuals, HHS, and — for incidents of 500 or more records — the media, per figures compiled by the HIPAA Journal.
The scale explains why waiting is a poor bet. At least 61.5 million individuals had protected health information exposed in 2025, with the year's largest incidents including Yale New Haven Health at more than 5.5 million people, PIH Health at 2,947,264, and DaVita at 2,689,826, according to the HIPAA Journal's 2025 report. Freezing credit and rotating passwords costs you little and protects you during the gap between the attack and the letter.
Frequently Asked Questions
Does freezing my credit hurt my credit score?
No. The FTC confirms a freeze does not affect your credit score, and placing, lifting, or removing one is free at every bureau.
Should I wait for the hospital's breach notification letter before acting?
No. HIPAA allows up to 60 days to notify you, so freezing credit and changing passwords now closes the window attackers can exploit.
A freeze is in place — am I fully protected?
No. A freeze stops most new-account fraud but not misuse of existing accounts or medical records, so keep monitoring statements and Explanation of Benefits forms.
You Might Also Like
- Hacked Response Checklist: Passwords, Accounts, and Credit
- Healthcare Data Breach Explained: Timeline, Exposure, and Response
- Healthcare Agency Provides Complimentary Credit Monitoring Following Patient Data Security Incident