If a company just sent you a data breach notification letter, the first instinct is usually confusion — is this real, is it urgent, what am I actually supposed to do? This guide walks through what these letters legally have to include, what each section means, and how to confirm the letter matches an actual filing before you act on it.
A data breach notification letter is a legally required notice a company sends when your personal information was exposed in a security incident. Most states require companies to notify both affected individuals and the state Attorney General's office — which is why these letters usually reference a specific filing date and state.
This is not a marketing email and not a scam attempt by default — though scammers do sometimes impersonate real breach notices, which is exactly why verifying the letter matters (see the last section below).
Most state laws require these letters to include specific information. If a letter you received is missing several of these, that's worth noticing:
A description of the security incident — how the exposure occurred, whether it was a hack, an employee error, or a vendor breach.
Exactly which categories of your data were exposed — for example, Social Security number, financial account number, medical record information, or login credentials. This matters because your next steps depend heavily on what was exposed. A password leak calls for different action than an SSN leak.
Companies are often required to disclose both the date of the breach and the date they discovered it — and sometimes there's a meaningful gap between the two, which can be legally relevant.
Many letters offer free credit monitoring or identity theft protection for a set period (commonly 1–2 years). This is worth taking advantage of — it typically costs you nothing to enroll.
Recommended steps like placing a fraud alert, freezing your credit, or monitoring your accounts.
Because breach notices reference real incidents, scammers sometimes send fake versions designed to look like a legitimate notice in order to phish for more information. The safest way to check: cross-reference the company name in your letter against the actual state Attorney General filing — not against a link or phone number provided in the letter itself.
Search our free breach registry → to check the company name from your letter against our database of official state AG filings, updated daily. If the company appears there with a matching filing date, the letter is real.
No — there's typically no required action on your part. The letter is informational and protective, not something requiring a signature or response. That said, taking the protective steps above (credit freeze, password changes, account monitoring) is strongly advisable.
Not necessarily. It means your data was exposed, which raises the risk — it doesn't guarantee misuse will occur. That said, the type of data exposed (especially SSNs or financial account numbers) affects how seriously to take precautions. Act as though the data is in the wrong hands, even if you haven't seen fraud yet.
Depending on the breach and what was exposed, affected individuals sometimes have legal options, including participating in a class action lawsuit. Get a free case review → to find out if you may have options for your specific situation. There is no cost to you unless we recover compensation on your behalf.
Related: Search the Breach Registry · What Is a Breach Notification Letter? · Data Breach Notification Letter Guide
The Law Office of David S. Harris offers free consultations — no fee unless we win.
No fee unless we win your case. Licensed in Florida — nationwide cases.
(786) 306-7278Get a Free Case ReviewData Breach Class Action: A Comprehensive Guide to Your Rights and Recovery
July 19, 2026 · 14 min read
Data Breach Notification Letter Guide: What Your Notice Means and How to Respond in 2026
July 19, 2026 · 12 min read
Class Action Lawsuit Settlement Guide: How to Claim Your Recovery in 2026
July 19, 2026 · 13 min read