A breach notification letter is a short document written by lawyers to satisfy a state statute, and it is nearly always structured the same way. Read it in that order and it tells you more than a first pass suggests.
Take a typical one: a company that had handled a medical billing account, writing months after the incident, notifying a household that names, dates of birth, addresses and Social Security numbers had been in an exposed file.
"We have no evidence of misuse"
This sentence appears in almost every letter and it is precise. It says the company has not seen misuse. It does not say none has occurred, and the company has no way of seeing it if it has, because misuse shows up on your credit file rather than on theirs.
Treat it as a statement about their visibility rather than about your risk.
The list of what was involved
The most important paragraph, and usually the shortest. There is a large practical difference between a card number, an email address, and a Social Security number, and the letter will name which.
A card number is replaceable in a week and the liability rules protect you. An email address gets you spam and better-targeted phishing. A Social Security number, a date of birth and an address together are the combination used to open credit in someone else's name, and unlike a card they cannot be reissued.
This letter named the third combination, which sets everything that follows.
The dates, read against each other
Two dates appear: when the incident occurred or was discovered, and when the letter was sent. The gap is frequently months, and it is worth noticing because it tells you how long the information has been in circulation before you learned anything.
It also tells you that any monitoring which begins now begins late. That is not a reason to skip it. It is a reason not to treat it as a fence around the whole problem.
The monitoring offer, and the enrollment deadline
The offer is usually a year or two of credit monitoring, activated by a code, with a deadline to enroll printed near the bottom in the same type as everything else. Miss it and the offer lapses.
Monitoring watches and reports. It tells you after a new account appears. That is useful, and it is a smoke alarm rather than a lock.
Read the paragraph about the identity theft insurance that often comes with it. The figure quoted is a limit on reimbursement of specified out-of-pocket costs, not a payout, and the exclusions are worth the two minutes.
The four things worth doing that week
Put a freeze on your credit file. That means doing it three times, once at each of the nationwide bureaus, because the lender deciding on a fraudulent application may check any one of them. A freeze costs nothing, federal law entitles you to one, and it stops the fraudulent account from being opened at all, because a file nobody can read is a file nobody will lend against. It takes a few minutes per bureau online and it can be lifted temporarily when you actually want credit. A fraud alert is the lighter alternative and does considerably less.
Freeze the credit of any child named in the letter. Children's identities are attractive precisely because nobody checks them for eighteen years.
Change the password on the account involved, and on every other account where you used the same one. This is the step that matters even when the breach did not include passwords, because attackers combine what they get with what they already have.
Expect the follow-on call. A breach is publicized, and within weeks people receive calls from someone claiming to be the company, the bank or a government agency, referencing the breach to sound credible. The rule that protects you is simple: hang up and call the number on your own card or statement. If an account has actually moved, file the federal identity theft report first. The Federal Trade Commission takes it online in a few minutes, and a bank or a bureau will ask to see it before it will do anything else.
The letter is also a document worth keeping
File it. If fraudulent credit does appear later, a dated notification naming your information is useful evidence that the exposure was not yours to prevent, and it is what an identity theft report gets built around.
Note also what the letter does not do: accepting the monitoring offer does not sign away any right to join a claim later, though a separate settlement notice arriving months afterward may ask you to choose. Those are different documents with different deadlines, and the second one is the one people throw away as junk mail.
What the household did with it
They froze four credit files including two children's, enrolled in the monitoring on the day the letter arrived rather than near the deadline, and changed nine passwords that had shared a common root.
The whole exercise took an evening. The freezes are the part still working two years later, quietly, at no cost, and they are the reason the letter turned out to be paperwork rather than the beginning of something long.
