If a company says your information was exposed, take two tracks at once: reduce the risk to your accounts and report the part of the problem to the office that handles it. There isn't one federal consumer form for every data breach.
The best route depends on what happened. The Federal Trade Commission (FTC) is a common starting point for fraud, identity theft, or potentially misleading privacy and security claims. HHS's Office for Civil Rights (OCR) handles possible HIPAA violations. A state attorney general may handle state privacy or consumer-protection concerns. The Consumer Financial Protection Bureau (CFPB) may help when a bank or another consumer financial company mishandles your account or fraud claim. The FBI's Internet Crime Complaint Center (IC3) is designed for suspected hacking and other internet crimes.
A complaint can give an agency useful information for enforcement. It usually won't replace a bank fraud claim, recover your money automatically, or prove that the company broke the law.
Choose the complaint route that fits
| What happened | Where to start | What to keep in mind |
|---|---|---|
| You suspect identity theft, fraud, or misleading privacy or security claims | FTC's fraud reporting service | The FTC generally does not act as your private lawyer or resolve an individual dispute |
| A health plan, health care provider, clearinghouse, or business associate may have mishandled protected health information | HHS's HIPAA information and the OCR complaint portal | HIPAA does not cover every company that stores or processes health-related information |
| A bank, lender, payment app, debt collector, or other financial company mishandled your account or fraud claim | The company's fraud department, followed by the CFPB complaint portal when appropriate | A CFPB complaint does not replace the provider's fraud or transaction-dispute process |
| You suspect hacking, unauthorized system access, ransomware, or extortion | IC3's data breach guidance | IC3 is a reporting channel, not emergency response or a guaranteed recovery service |
| A business may have violated your state's breach-notification, privacy, or consumer-protection law | The official consumer complaint page for your state attorney general | Authority, deadlines, and available remedies vary by state |
You can use more than one route when the reports concern different conduct. For example, an unauthorized bank-account transfer may justify a claim with the bank, an IC3 report, and an FTC report. Keep each report factual. Don't send the same unsupported accusation to every agency.
Secure your accounts before filing
Don't wait for a regulator to respond before reducing the chance of more harm.
- Start with your email account. Change the compromised password and any other password you reused. Sign out of unfamiliar sessions, turn on multifactor authentication, and replace exposed recovery codes or security questions.
- Call your bank or card issuer. Use the number on your card, statement, or the institution's official website. Ask how to block or replace the affected payment method and follow the provider's fraud or transaction-dispute process.
- Consider a credit freeze. The FTC says freezes are free and remain in place until you ask the credit bureaus to remove them. A freeze can help prevent someone from opening new credit accounts in your name. Place one separately with Equifax, Experian, and TransUnion. It won't secure an existing account, so keep checking statements and credit reports.
- Compare a fraud alert with a freeze. They are different tools. The FTC's guidance on credit freezes and fraud alerts explains what each one does and how to place or renew it.
- Expect follow-up scams. Someone may call or message you pretending to offer monitoring, a refund, or account assistance. Don't give an unsolicited contact your password, one-time code, full Social Security number, or complete bank-account number.
- Save the breach notice. Keep the original email, letter, or account message, along with the company's case number and the date you received it.
Free credit monitoring offered after a breach may be useful, but signing up doesn't replace changing passwords, freezing credit, or disputing unauthorized transactions.
Read the breach notice carefully
The notice may not answer every question, but it should give you a starting timeline. Look for:
- The incident date, discovery date, and notice date
- The company or legal entity responsible for the affected service
- The categories of information involved, such as an email address, login credential, Social Security number, payment data, or medical information
- Whether the company says the information was accessed, acquired, or only potentially exposed
- What the company has done to contain the incident
- Any monitoring, support, or other protection it is offering
- A breach-response phone number, website, or reference code
If the notice is vague, ask the company for clarification in writing. Questions that may help include:
- What specific types of information about me were involved?
- Was the information accessed, copied, downloaded, or only stored on an affected system?
- When did the unauthorized activity occur, and when was it discovered?
- Was my password, security question, payment information, or government identifier exposed?
- What steps have you taken to contain the incident?
- How should I report suspected misuse or request help?
Don't turn an unanswered question into a confirmed fact. In your complaint, separate the three categories: what you know, what the company says, and what you suspect.
Build a simple evidence file
A short timeline is easier for an agency, bank, or company to follow than a folder of unsorted screenshots. Use four columns:
| Date | What happened | Evidence | Action taken |
|---|---|---|---|
| [date] | Received the breach notice | Saved email or letter | Contacted the company |
| [date] | Saw an unfamiliar login or account change | Screenshot or account record | Changed password and enabled MFA |
| [date] | Noticed an unauthorized transaction | Bank alert and claim number | Reported it to the bank |
Collect the records that relate to your complaint:
- The breach notice and follow-up messages
- Screenshots of suspicious logins, account changes, or error messages
- Emails, letters, chat transcripts, and call dates
- Names of company representatives and case numbers
- Records of unauthorized transactions or new accounts
- Credit-report entries you don't recognize
- Identity-theft or police reports, if you made them
- A description of financial loss, time spent, or continuing risk
Redact unnecessary sensitive information before uploading or mailing anything. Unless an official form specifically asks for it, don't include a full Social Security number, full bank-account number, complete payment-card number, password, or entire medical record. Keep the unredacted originals in a secure place in case an agency later requests a specific document.
Give the company a chance to respond
The company may control the account, the fraud investigation, or the explanation of what happened. Contact it using information from the breach notice or the company's official website, not from a suspicious email or text.
Ask for a written response. State:
- When you learned about the incident
- Which account or service is involved
- What information the notice says may have been exposed
- Any suspicious activity, loss, or continuing risk you have observed
- The action you want, such as account restoration, a written explanation, or fraud assistance
You don't have to wait for the company's answer before filing with an agency. If the company doesn't respond, record the dates and methods of your attempts and include that information in the complaint.
Reporting fraud, identity theft, or misleading claims to the FTC
The FTC may be a suitable route when a breach is connected to identity theft, fraud, or claims about privacy or security that may have misled consumers. A breach notice by itself doesn't establish that the company violated a particular FTC rule.
To submit a report:
- Open the FTC's fraud reporting service.
- Select the category that most closely matches the problem, such as identity theft, fraud, or a deceptive business practice.
- Identify the company, website, app, or service involved.
- Provide the incident and discovery dates if you know them, the information involved, and a concise account of what happened.
- Describe suspicious activity or financial loss separately from the possible security failure.
- Upload only relevant, redacted documents if the form accepts attachments.
- Save the confirmation number and a copy of what you submitted.
Consumer reports help the FTC identify patterns and support possible enforcement. The FTC generally won't determine whether you are owed compensation or negotiate a personal settlement. If you lost money, contact the bank, card issuer, payment provider, or other company responsible for the transaction separately. The FTC contact page has additional directions if the online reporting route doesn't fit.
Avoid declaring that a company violated a specific FTC rule simply because it lacked a security feature. That conclusion depends on the company, the information involved, the promises it made, and the facts of the incident.
Filing a HIPAA complaint with HHS OCR
HIPAA applies to covered entities such as health plans, health care providers that conduct certain electronic transactions, health care clearinghouses, and their business associates. It does not automatically cover every health app, employer, school, life insurer, or technology company that handles health-related information.
A complaint may fit when a covered organization improperly used or disclosed protected health information, failed to provide required access, or may have violated the HIPAA Privacy, Security, or Breach Notification Rules.
Before filing, check that:
- The organization is likely a covered entity or business associate
- The conduct involves protected health information
- You can identify the organization, its location, and the relevant dates
- You can describe an ongoing risk, such as continued account access or repeated disclosure
You can use the OCR complaint portal, or start with HHS's HIPAA information. Include the breach notice and limited supporting evidence. Don't send an entire medical file unless the form or OCR specifically requests it.
OCR generally expects a complaint within 180 days after you knew, or should have known, about the possible violation. It may allow more time for good cause, but an extension isn't something to assume.
The 60-day period often associated with HIPAA is generally the organization's deadline to notify affected people of a reportable breach. It is not a 60-day deadline for a patient to file an OCR complaint. A breach notice also doesn't prove that a HIPAA violation occurred. OCR may find no violation, request corrective action, provide technical assistance, or pursue enforcement based on the facts.
An employer acting only as an employer, for example, may not be covered by HIPAA even if it has health information about its workers. Another law or complaint route could still apply.
Complaining to a state attorney general
A state attorney general may accept complaints about unfair business practices, inadequate breach notices, or conduct that may violate state privacy or data-security law. Find the official consumer-protection page for the state where you live, where the company operates, or where the harm occurred. The office may refer the matter elsewhere or decide not to open an individual investigation.
Give the office a clear record of:
- Your state and, when relevant, the company's state
- The company's name and service
- The breach notice and timeline
- The types of personal information involved
- Your attempts to resolve the issue with the company
- The result you want, such as an explanation or review of the company's practices
State laws don't create identical rights or remedies. California's privacy and security rules, for example, shouldn't be treated as a promise that every breach produces a payment to each affected person. A government penalty and a private damages claim are separate issues. California residents can review the California Attorney General's CCPA information, while still checking how the facts and current law apply to their situation.
When the CFPB belongs in the picture
Use the CFPB route when a consumer financial company mishandles your account, fails to address identity theft, or gives you trouble after a security incident. Possible examples include a bank, lender, payment app, debt collector, or consumer reporting company.
For an unauthorized transfer or card transaction, file the bank or provider's fraud claim first. Then use the CFPB complaint portal if the company fails to handle the claim, investigate the issue, or otherwise address a problem with a covered financial product or service.
A CFPB complaint is sent to the company for a response, but the timing and result can vary. Don't assume that filing with the CFPB replaces or extends the deadline or procedure for disputing an electronic transfer, debit transaction, or credit-card charge. Keep the provider's claim number and every transaction record.
A retailer's data breach doesn't automatically become a CFPB matter because you used a card to pay. The payment dispute belongs with the card issuer or bank. The retailer's security practices may be better suited to an FTC or state complaint.
Reporting hacking or internet crime to IC3
Use IC3's data breach guidance for suspected hacking, unauthorized system access, ransomware, extortion, or another internet crime. Include the company or account involved, dates, affected systems if known, the types of data involved, communications from the attacker, and any financial loss. IC3 asks filers to use the words "data breach" in the incident description when appropriate.
IC3 and local law enforcement reports can support an investigation, but neither guarantees that stolen money or data will be recovered. Continue working with your bank, card issuer, or account provider.
Contact local law enforcement for identity theft, threats, stalking, or an immediate safety concern. Call emergency services for an emergency; an online report isn't a substitute for urgent help.
Complaint letter template
Use the structure below for an agency form or a mailed complaint when that agency accepts one. Adjust it to the office and leave out information the form doesn't require.
Subject: Complaint about a suspected data breach at [Company]
I am a resident of [state]. On [date], I received a notice from [company] stating that [briefly describe the incident]. The notice says that the following information may have been involved: [list only the categories identified].
I observed or experienced the following: [describe suspicious activity, account changes, financial loss, or continuing risk]. I contacted [company] on [dates] using [method]. The company responded that [summarize the response], or did not respond.
I have taken these steps: [password changes, MFA, credit freeze, bank fraud claim, police report, or other action]. I request that your agency review whether the company's conduct complied with the laws or rules within your authority and advise me of any next steps available to me.
Attached are: [breach notice, timeline, correspondence, screenshots, and claim numbers]. I have redacted unnecessary account and identity information.
Sincerely,
[Name]
[Safe contact information]
Stick to dates, documents, and observable events. A factual timeline is more useful than a long list of penalties or legal conclusions.
After you submit
Save the confirmation page, case number, submitted text, and attachments. Add each agency contact to your incident log.
An agency may:
- Acknowledge the complaint or ask for more information
- Refer it to another agency
- Contact the business
- Combine it with similar complaints
- Provide technical assistance or take enforcement action
- Close the matter without sharing every investigative detail
A complaint doesn't guarantee a refund, credit-monitoring service, settlement, or finding of wrongdoing. If the situation changes, update the existing complaint with new facts and its case number instead of filing a duplicate report that leaves out the earlier history.
Mistakes that can make the report less useful
- Waiting for a regulator before securing accounts or freezing credit
- Treating a breach notice as proof that you are owed a fixed payment
- Sending a full Social Security number, password, complete payment-card number, or medical file through ordinary email
- Using contact information from a suspicious message
- Filing with HHS when the organization isn't subject to HIPAA
- Treating HIPAA's 60-day notification rule as the deadline for your OCR complaint
- Asking the FTC to resolve a bank transaction dispute
- Describing a suspicion as a confirmed fact
- Losing the company's case number or the agency confirmation
- Assuming a credit freeze protects existing accounts or prevents every kind of identity theft
If you live outside the United States
This article covers U.S. complaint routes. If you live in the European Union, the United Kingdom, or another country, use the official data-protection or consumer authority for your country or region. A U.S. complaint won't substitute for a local GDPR, UK data-protection, or other local complaint.
For substantial financial loss, an ongoing account takeover, or a dispute about a legal claim, consider advice from a qualified professional. This is practical consumer information, not legal advice. Start with the account provider for any live fraud, save the claim number, and then send the narrowest well-documented complaint that matches the facts.