Technology
Four Kinds of Breach Letter Land in the Same Mailbox. Telling Them Apart Decides What You Do Next
Breach notices look interchangeable, but the law behind each one differs, and that difference decides your deadline, your remedy and how much of the letter you can trust.
Technology·Osman Duraklar

The envelope is thin, the type is small, and the first paragraph almost always says the same thing: an unauthorized party may have gained access to certain information. What the letter does not say, and what changes your response more than anything printed on the page, is which body of law forced it into your mailbox. Four separate regimes produce consumer breach notices in this country, they were built at different times for different reasons, and they hand you different things. Reading the letter for its origin takes about ninety seconds and saves the wasted afternoon.
Why the letter exists at all, and why it reads like a legal filing
Before 2003 a company that lost your Social Security number had no general obligation to tell you. California changed that with a statute requiring notice when unencrypted personal information was acquired by an unauthorized person, and the model spread state by state over the following fifteen years until every state had some version, with the last holdouts arriving in 2018. That history explains the prose. The letter is drafted to satisfy fifty overlapping statutes at once, which is why it hedges on what happened, leans on the word "may," and describes the incident in the passive voice. The vagueness is a compliance artifact rather than a cover-up, though the effect on a household reading it is the same.
It also explains the numbers. When a company announces that an incident affected two million people, treat the figure as provisional, because these counts are assembled from partial logs, they get revised as forensic work continues, and the suspiciously round ones are usually estimates dressed as findings. Second and third letters about the same incident, arriving months apart with a longer list of data elements, are common enough that you should file the first one rather than throw it away.
The four regimes, and what each one is actually about
The most common letter is the state-law consumer notice, triggered by loss of a defined set of identifiers, typically your name plus a Social Security number, driver's license number, or financial account number. Its purpose is narrow: alert you to identity theft risk so you can act. A second kind comes from a health care provider, insurer, or their business associate under the federal health privacy rules, which set a sixty day outer limit for individual notice and require the letter to describe the types of information involved and what the covered entity is doing about it. A third comes from a bank, credit union, brokerage, or lender, operating under federal financial regulator guidance and, more recently, an amended safeguards rule that pulls non-bank financial companies into a reporting duty as well. The fourth is voluntary, or close to it: a company discloses because a vendor it used was breached, because a securities filing already made the news, or because staying quiet would cost more than speaking.
The distinctions matter because the regimes protect different things. State law protects your identity. The health rules protect the record itself, including who has looked at it. Financial rules protect the account. A voluntary disclosure protects the company's relationship with you, which is not worthless, but it carries no floor on what must be told.
Comparing what each letter hands you
The state-law notice usually arrives with an enrollment code for credit monitoring, offered for a period that runs from one to two years in most letters and occasionally longer where a state attorney general pushed for it. Monitoring is surveillance, not prevention. The prevention tool is the security freeze, which became free at all three nationwide credit bureaus under federal law in 2018, and which the Federal Trade Commission, the agency responsible for consumer identity theft guidance, treats as the primary defense rather than a supplement. If your letter names a Social Security number, the freeze is the move and the enrollment code is secondary.
A health privacy letter gives you something the others do not: a right to ask the provider for an accounting of disclosures, and a route to complain to the federal health regulator if the answer is thin. There is no credit bureau equivalent for medical records, no freeze, no monitoring product that watches your chart, so the useful action is different. You request your records, you read them for treatment you did not receive, and you challenge the entries in writing, because a fraudulent claim inside a medical file changes what a future insurer and a future clinician believe about you.
A financial institution letter tends to be the most actionable and the least alarming, since card networks and banks absorb fraudulent charges under rules that cap your liability sharply, and reissuing a card closes the exposure. Zero liability is contractual for credit cards in practice and statutory in outline, while debit card protection depends heavily on how fast you report, which is the one deadline in this whole landscape that genuinely runs in days rather than months. The voluntary disclosure gives you information and nothing else, which is exactly why it deserves the most skeptical reading: check whether it names data elements at all, and if it does not, assume the scope is still being determined.
Reading for the data element, not the tone
Sort your letter by what was taken rather than by how worried it sounds. A password or login credential means the exposure is every other account where you reused it, and the fix is a pass through your reused passwords, starting with email. A card number means a reissue and a look at the statement. A Social Security number means a freeze at all three bureaus, and if you file taxes, awareness that fraudulent returns filed in your name are handled through a separate IRS process with its own identity protection PIN. A driver's license number means a note to your state motor vehicle agency, which is the step nearly everyone skips. Medical information means the records request.
The letters that name nothing specific are the ones to keep in a folder and revisit, because a follow-up notice with an expanded list is the normal pattern rather than the exception, and the enrollment window on the monitoring offer usually stays open long enough that you lose nothing by waiting for the second letter before you decide what the incident actually was.
Keep the notices together, dated, in one place. The value is not sentimental: when a fraudulent account surfaces two years out, the letter is the document that establishes you were exposed and when, and that turns a long argument with a creditor into a short one.