If a company tells you that your personal information may have been exposed, send a short, factual complaint to the privacy, security, or customer-support contact in the breach notice or on the company's official website.

Ask what happened, when the company discovered it, which categories of information were involved, and what protection or reimbursement process is available. Use a partial account reference. Don't put your full Social Security number, password, full account number, medical records, or identity documents in an ordinary email.

Your message can establish a useful timeline, but it doesn't prove that the company violated a law or guarantee compensation. If the incident could lead to identity theft or unauthorized transactions, protect your accounts and contact the relevant financial institution at the same time.

Quick actions after a data breach

Before you send a complaint, or while you're waiting for a response:

  1. Save the notice and other evidence. Keep the original letter or email, screenshots, account alerts, transaction records, and a list of relevant dates.
  2. Change exposed passwords. Use a password you don't use anywhere else. Turn on multifactor authentication if the service offers it.
  3. Consider a credit freeze. A freeze is free and generally prevents prospective creditors from accessing your credit report to open new credit. It stays in place until you ask the bureaus to remove it. You generally need to contact Equifax, Experian, and TransUnion separately.
  4. Consider a fraud alert. An initial fraud alert generally lasts one year. An extended alert can last seven years when supported by an identity-theft report.
  5. Check your credit reports. Look for unfamiliar accounts, inquiries, addresses, or collection activity.
  6. Use the correct payment-dispute process. Report an unauthorized credit-card charge to the card issuer through its billing-dispute process. For an unauthorized debit, ACH transfer, wire, or peer-to-peer payment, contact the bank or payment service's fraud department immediately. An email to the breached company may not satisfy a payment-dispute deadline.

The FTC's guidance on credit freezes and fraud alerts explains how freezes and alerts work and where to start.

What rule controls a data breach complaint?

The United States has no single breach-notification deadline that applies to every company. The controlling requirement might come from a state breach law, a sector-specific federal law, a contract, or the company's own policy.

Situation Rule or process that may control What your complaint can and cannot do
Ordinary consumer or account data State breach-notification law and possibly a sector-specific rule Ask for facts, protective measures, and a response. There is no universal 30-day deadline for the company to answer you.
Protected health information held by a HIPAA-covered organization HIPAA breach-notification requirements The 60-day HIPAA notice limit is generally the organization's deadline, not your deadline to complain.
Personal health records held by certain non-HIPAA businesses FTC Health Breach Notification Rule Use the FTC's official process if the business falls within that rule. A health-data incident is not automatically a HIPAA breach.
A company or incident covered by the GDPR GDPR requirements and the relevant supervisory authority The commonly cited 72-hour authority-notification rule is not a general U.S. consumer deadline.
Identity theft or fraud Credit bureaus, banks, card issuers, payment services, law enforcement, and consumer-reporting agencies A regulator complaint can create a record, but it may not reverse a transaction or recover your money.

A regulator may decide to review a complaint under the laws within its authority. It usually won't act as your private lawyer, and it doesn't replace the fraud or billing-dispute process of a bank or card issuer.

HIPAA timing

A HIPAA-covered entity generally must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach involving unsecured protected health information. A breach affecting at least 500 people usually must also be reported promptly to the U.S. Department of Health and Human Services, subject to the same 60-day outer limit. Smaller breaches generally follow an annual reporting process.

Those are duties of the covered organization. They don't give you 60 days to report a suspected privacy violation, and they don't require the organization to send you a complete forensic report. A permitted law-enforcement delay or other applicable requirement can affect the timing of a notice.

FTC health-data reporting

The FTC has a separate Health Breach Notification Rule for certain businesses that offer or maintain personal health records and related products. It doesn't apply to every company that handles health information, and it isn't a substitute for HIPAA rules.

A business covered by the rule should use the FTC's current reporting process. The FTC Notice of Breach of Health Information form includes the instructions and asks whether the business is offering or maintaining personal health records as defined by the rule.

For a breach affecting fewer than 500 people, the FTC form generally uses an annual reporting deadline: the business submits the report by the 60th day of the calendar year following the year in which it discovered the breach. A business should check the current form for the applicable instructions. Don't rely on an old email address copied from a template.

Before you copy a data breach complaint email

A useful complaint gives the company enough information to find the relevant account without giving away more than it needs. Include:

If the company hasn't confirmed a breach, write "suspected data breach" or "suspected privacy incident." Keep facts separate from assumptions. "I received an alert for an account I did not open" is more useful than "your hackers stole my identity."

Use the company's secure portal when it asks for identity documents or sensitive records. Before attaching evidence, redact unnecessary Social Security numbers, full payment numbers, passwords, health details, and information belonging to other people.

Template 1: Formal data breach complaint to a company

Use this version when you want the company to investigate the incident, explain whether your information was involved, or describe the protection it offers.

Subject: Formal complaint about suspected data breach - [account reference]

Hello [privacy officer, security team, or company contact],

I am [full name], a current or former customer of [company name]. I am writing to make a formal complaint about a suspected data breach or privacy incident involving my account.

On [date], I [received a breach notice, saw an unauthorized login, noticed an unfamiliar account, or learned of the incident from another source]. The relevant account or reference is [partial account number or customer ID].

Please confirm in writing:

1. Whether an incident affected my account or information
2. The date range of the incident and the date the company discovered it
3. The categories of information involved
4. Whether my information was accessed, acquired, or only stored in an affected system
5. The steps taken to contain the incident and prevent a recurrence
6. Any credit monitoring, identity-theft assistance, reimbursement process, or other protection available to me
7. The correct contact for follow-up questions

I have attached or described the following evidence: [brief list]. I have not included my full Social Security number, password, or full payment details in this email.

Please acknowledge receipt by [date] and provide a case number. If some facts are still under investigation, please identify what remains unknown and when I should expect the next update.

Please send any sensitive information through a secure channel.

Regards,

[Full name]
[Email address]
[Phone number]
[Mailing address, if needed]
[Partial account reference]

Template 2: Follow-up when the company has not responded

Send one concise follow-up after the acknowledgment date the company gave you or the reasonable date in your first message. Include the original case number if you have one.

Subject: Follow-up on data breach complaint - [case number]

Hello [contact or privacy team],

I am following up on my data breach complaint sent on [date]. I have not received [an acknowledgment, a case number, or the requested information].

For reference, the incident involved [short factual description], and my account reference is [partial reference]. Please confirm:

- Whether my information was affected
- What information may have been involved
- The current status of the investigation
- What protective services or reimbursement process is available
- The name or team handling this matter

If the investigation is not finished, please tell me which answers are still pending and the next expected update date. Please use a secure channel for any sensitive information.

Thank you,

[Full name]
[Contact information]
[Original complaint date]

Template 3: Report an unauthorized account or transaction

Use the breached company's email as a record, but contact your bank, card issuer, or payment service through its official fraud channel first. Identify the payment rail clearly.

Subject: Unauthorized account activity following suspected data exposure

Hello [fraud department or security team],

I am reporting activity that I did not authorize:

- Payment method or account ending in: [last four digits only]
- Transaction, application, or account reference: [reference]
- Date and amount: [date and amount]
- What I observed: [brief description]

I did not authorize this activity and did not give permission for anyone else to use my account. Please secure the account, investigate the activity, preserve the relevant records, and tell me how to submit a formal dispute.

Please also confirm whether this activity may be connected to the security incident reported on [date]. I am taking separate steps with [bank, card issuer, payment service, or credit bureau].

I have attached [redacted records]. I have not included my password, full account number, or full Social Security number.

Please provide a case number and instructions for any additional documents you need.

Regards,

[Full name]
[Safe contact information]

For an unauthorized credit-card charge, use the issuer's billing-dispute address or procedure as well as email. For a debit, ACH, wire, or peer-to-peer payment, ask the provider how it wants the fraud reported and what evidence it requires.

Template 4: Consumer complaint to a regulator

A regulator complaint works best as a timeline. It shouldn't read like a demand that the agency award damages. Paste the facts into the regulator's official online form or other approved submission method.

Subject: Consumer complaint about suspected data breach at [company]

To [state attorney general, state privacy regulator, or other applicable agency]:

I am a U.S. consumer in [state]. I am asking for review of a suspected data breach or privacy-handling problem involving [company name].

What happened:
- Date I learned of the issue: [date]
- How I learned of it: [breach notice, account alert, unauthorized account, or other source]
- Information potentially involved: [categories only]
- Harm or risk I observed: [identity-theft warning, unauthorized transaction, account lockout, or documented loss]

I contacted the company on [date] using [email, portal, phone, or mailing address]. The company [did not respond, provided an incomplete response, confirmed the incident, or supplied the following explanation: brief summary].

I am asking the agency to review whether the company handled the incident and my complaint appropriately under the laws or rules within the agency's authority. I understand that the agency may not be able to investigate, obtain compensation, or resolve a private dispute.

Attached are:
- A copy of the breach notice
- My dated communications with the company
- A short chronology
- Redacted records supporting my complaint

I have not included my full Social Security number, password, or full financial account number. Please tell me if the agency requires sensitive information through a secure submission method.

Sincerely,

[Full name]
[State and city]
[Safe contact information]
[Company case number, if any]

Possible escalation routes include your state attorney general, a state privacy regulator where one exists, the HHS Office for Civil Rights for a possible HIPAA issue, or the FTC for a consumer fraud report. Choose the agency whose authority matches the problem. A regulator complaint is different from disputing an unauthorized payment or reporting identity theft.

Template 5: Customer data breach notification and apology

This version is for a business notifying customers. The incident-response, legal, security, and communications teams should review it before delivery. The FTC's data breach response guide for businesses recommends involving the appropriate experts, preserving evidence, containing the incident, and clearly describing what is known.

Subject: Important notice about a security incident at [company]

Dear [customer name],

We are writing to tell you about a security incident involving [company name]. We detected the incident on [date] and determined on [date] that it may have involved information connected to you.

What happened:
[Plain-language description of the incident and relevant dates. Include only facts that have been verified.]

Information involved:
[State the categories of information, such as name, email address, account credentials, or payment information. Do not list information that was not involved.]

What we have done:
- [Contained the affected system]
- [Reset credentials or blocked unauthorized access]
- [Engaged forensic or security specialists]
- [Notified the appropriate authorities, if required]
- [Added other protections]

What you can do:
- Change your password if you reused it elsewhere
- Turn on multifactor authentication
- Watch for unfamiliar account activity
- Contact us at [official phone number, email, or secure portal]
- [Use the monitoring or identity-protection service offered, if applicable]

At this time, [state the current evidence about misuse only if verified]. Our investigation is continuing, and we will provide additional information if the facts change.

We're sorry this happened and regret the concern it may cause. For questions, contact [team] at [contact details]. Please do not send passwords or full financial account numbers by email.

Sincerely,

[Authorized company representative]
[Company name]

Don't promise free monitoring, reimbursement, a particular investigation result, or that no misuse occurred unless the company has actually arranged or verified it. If state law requires a particular notice method or wording, this email may need to be accompanied by a letter or another approved notice.

Template 6: HIPAA breach notification email sample

A HIPAA-covered organization should not use an ordinary email as a substitute for a legally required notice. It should follow its approved notification method and avoid putting protected health information in the subject line or an unsecured message.

Subject: Notice of privacy breach involving your health information

Dear [patient name],

We are writing to notify you about a privacy or security incident involving your protected health information.

We discovered the incident on [date]. It occurred or may have occurred between [date range]. The information involved may have included [categories of information, such as name, address, medical record number, diagnosis, treatment information, or health insurance information].

What we have done:
[Describe containment, investigation, access restriction, password reset, vendor action, or other verified steps.]

What you can do:
[Give practical steps that apply, such as reviewing explanation-of-benefits statements, contacting the organization, or using an identity-protection service.]

We are notifying you because [brief explanation of why the organization believes your information was involved]. We will provide additional information if our investigation identifies a material change.

For questions, contact [privacy officer or dedicated response team] at [phone number] or [secure website]. Please do not send medical records or other sensitive health information by ordinary email.

Sincerely,

[Authorized representative]
[Covered entity name]
[Mailing address]

A HIPAA notice generally needs to describe what happened, the types of information involved, steps the affected person can take, steps the organization has taken, and contact information. The organization should review the notification rule and any law-enforcement delay before sending it.

Template 7: GDPR supervisory-authority breach report

Use this only when the organization or incident is subject to the GDPR. A report normally goes to the relevant supervisory authority through its official form or portal. The data protection officer may be the incident contact, but an ordinary U.S. consumer-protection inbox isn't a substitute for the proper authority.

The commonly cited 72-hour rule concerns a controller's notification to a supervisory authority when notification is required. It isn't a deadline for an individual to email a company or regulator.

Subject: Initial personal data breach notification - [controller name] - [incident reference]

To [supervisory authority]:

Controller:
[Legal name, address, contact person, and applicable representative]

Incident:
[Brief description of what happened]

Dates:
- Breach began or may have begun: [date and time]
- Breach discovered: [date and time]
- Notification submitted: [date and time]

Data and people affected:
- Categories of personal data: [list]
- Approximate number of people: [number or estimate]
- Countries or regions affected: [locations]
- Likely consequences: [identity theft, account takeover, exposure, or other documented risk]

Measures taken:
[Containment, credential resets, access restrictions, investigation, customer notification, and other completed actions.]

Information still being investigated:
[List the unknown facts and the planned date or method for providing an update.]

Contact:
[Data protection officer or incident-response contact]

We will provide additional information as it becomes available.

Sincerely,

[Name and role]
[Controller name]
[Contact details]

Template 8: FTC health-breach reporting worksheet

The FTC Health Breach Notification Rule uses an official form rather than a standard complaint email. A business can gather these facts before opening the form:

Entity name and contact:
[Legal name, address, telephone number, and incident contact]

Business description:
[How the business offers or maintains personal health records or related products]

Incident dates:
[Date the breach occurred or began, date discovered, and date contained]

People affected:
[Estimated total and affected states or jurisdictions]

Information involved:
[Categories of health information and identifiers involved]

What happened:
[Concise, verified description]

Protection and remediation:
[Containment, investigation, customer notice, credential resets, monitoring, and other steps]

Law-enforcement or operational issues:
[Only if relevant and documented]

Consumer contact:
[Phone number, secure website, mailing address, and hours]

Supporting records:
[Notice, incident timeline, forensic findings, and communication log]

Submit the information through the FTC's official health-information breach form only if the business falls within the rule. Don't treat that form as a substitute for a HIPAA report to HHS or a state-required notice.

How to send and document your complaint

1. Verify the recipient

Use the contact information in the original breach notice, the company's official website, your account portal, or a statement. Be cautious with a reply that asks you to click an unexpected link, provide a password, or send identity documents. A breach notice can itself be impersonated.

2. Use a precise subject line

Examples:

Keep your Social Security number, medical information, and full account number out of the subject line.

3. Keep the whole record

Save the sent message, attachments, delivery confirmation, response, case number, and a dated chronology. If you use an online form, save the confirmation page or download the receipt.

4. Follow up once, then choose the right escalation

If the company misses the acknowledgment date it gave you, send a concise follow-up. If the response remains incomplete, use the official process of the state or federal regulator with authority over the issue.

Don't wait for the privacy team if money or an account is involved. Contact the bank, card issuer, credit bureau, or payment service immediately.

Mistakes that weaken a data breach complaint

Frequently asked questions

Can I demand compensation in a data breach complaint email?

You can request reimbursement for documented losses or ask what assistance the company offers. There is no universal rule that every data breach automatically creates a payment right. Keep receipts, fraud reports, fees, lost-time records, and other evidence connected to the incident.

Is email enough to report a data breach?

Email is useful for creating a record, but it may not be the required method for a regulator, a HIPAA notice, or a payment dispute. Use the company's secure portal and the official process of the agency or financial institution involved.

What should I do if the company never responds?

Send a dated follow-up with the original case number and your unanswered questions. Then consider a complaint to the appropriate state or federal regulator. If money or an account is involved, contact the relevant bank, card issuer, credit bureau, or payment service immediately.

Should I freeze my credit after a breach?

A freeze can be especially useful if your Social Security number, financial information, or other information that could support identity theft was exposed. It's free, and you can remove it later. A fraud alert is different: it asks businesses to verify your identity before extending credit but doesn't block access to your credit report.

Does a 60-day HIPAA deadline mean I must complain within 60 days?

No. That deadline generally applies to an organization's notice obligations after discovering a qualifying breach. Your complaint, identity-theft response, and payment-dispute deadlines may follow different rules.

Does the GDPR 72-hour rule apply to every U.S. breach?

No. It applies to organizations and incidents covered by the GDPR and concerns notification to a supervisory authority when required. It isn't a general deadline for a U.S. consumer to email a company or regulator.

Start by saving the breach notice and sending Template 1 with only the details needed to identify your account. If you see an unauthorized charge or account, open the separate dispute with the responsible bank or payment service that same day.