Understanding the difference between a data breach and identity theft can help with effectively responding to the incident. While the two terms are closely related, they describe different events. One is an incident, the other is a crime that can follow a data breach and has lasting ramifications for individual victims.

 

What is a data breach?

A data breach is an event in which sensitive, protected, or confidential information is accessed, stolen, or exposed without authorization. It's a security failure on the part of an organization, not something that happens directly to an individual, at least not at first.

Data breaches happen due to different reasons. Sometimes a hacker exploits a software vulnerability to break into a company's servers. Sometimes an employee accidentally leaves a database exposed on the internet without password protection. Sometimes malware infiltrates a network and siphons off data over weeks or months before anyone notices.

However, not every cyberattack qualifies as a data breach. According to IBM, the two terms often get used interchangeably, but a breach involves someone gaining unauthorized access to data, meaning an attack that disrupts a service without exposing information, like a denial-of-service attack that floods a website with traffic, doesn't count as a breach. A ransomware attack that locks up and threatens to leak customer data does. Furthermore, an accidental breach, like an administrator giving the wrong doctor patient information, qualifies as a data breach (however small), but is not a cyberattack.

The information exposed in a breach can include names, email addresses, passwords, Social Security numbers, credit card numbers, medical records, or account details depending on what the breached organization stored.

Learn more: Common causes of data breaches

 

 

How HIPAA defines a breach

Healthcare data gets its own legal definition of a breach, found in the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414). The HHS describes a breach as "an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information."

The definition comes with a presumption that any impermissible use or disclosure of protected health information (PHI) is automatically treated as a breach, unless the covered entity (or its business associate) can show there's a low probability the information was actually compromised. To prove that, they have to run a risk assessment that outlines four things, including what kind of information was involved and how easily it could be used to re-identify someone, who actually received or accessed it, whether it was actually viewed or acquired at all, and how much the organization has managed to contain the damage.

There are also some situations where something that looks like a breach doesn't legally count as one. The first is when a workforce member who unintentionally accesses PHI in good faith while acting within their normal authority. The second is an inadvertent disclosure between two people who are both already authorized to see PHI within the same organization or a shared care arrangement. The third applies when the organization has a good-faith belief that the person who received the information wouldn't have been able to hold onto it.

 

Who has to be told and when

The HIPAA rule provides notification timelines:

  • Affected individuals must be notified by mail (or email, if they've agreed to it) within 60 days of the breach being discovered. If contact information is missing or outdated for 10 or more people, the organization has to post a substitute notice on its website for at least 90 days, or use print/broadcast media, along with a toll-free number active for 90 days.
  • The media must be notified if a breach affects more than 500 residents of a single state or jurisdiction, within 60 days.
  • HHS must be notified within 60 days for breaches affecting 500 or more people. Smaller breaches can be reported in a yearly batch, due within 60 days of the end of the calendar year in which they were discovered.
  • Business associates (vendors and contractors handling PHI on an organization's behalf) must notify the covered entity within 60 days of discovering a breach, and should hand over as much detail as possible about who was affected.

Every notification is supposed to include a description of what happened, what type of information was involved, steps people should take to protect themselves, what the organization is doing about it, and how to get in touch with them.

 

The cost of a breach

IBM's Cost of a Data Breach 2025 report puts the global average cost of a breach at $4.44 million, though that figure varies by country and industry. Healthcare has had the highest average breach cost of any sector for 14 years; healthcare breaches average $7.4 million per incident, and breaches involving third-party vendors run higher at roughly $4.9 million per incident, according to IBM data cited in Paubox's 2026 Healthcare Email Security Report. That same report found that HHS recorded 170 email-related healthcare breaches in 2025, affecting more than 2.5 million individuals, a figure that shows how email is one of the most common causes of breaches in healthcare.

Those costs break down into categories, like lost business and customers, the expense of detecting and escalating an incident, post-breach cleanup like legal fees and free credit monitoring for affected customers, and the cost of notifying everyone who needs to know.

 

How breaches happen

According to IBM's 2025 findings, phishing remains the single most common way breaches start. Human error and IT failures account for a large share of breaches too, together responsible for roughly half of all incidents IBM tracked.

Paubox's analysis of 2025 HHS breach data identifies three recurring attack patterns behind nearly every email-related healthcare breach that year. The one that had the most impact was phishing-driven mailbox takeover whereby an attacker steals login credentials, then logs into the inbox as a legitimate user to search for billing, referral, or lab-related information, often going undetected for long periods because the activity looks routine. This tactic exposed more than 630,000 individuals in 2025.

The second pattern was business email compromise and impersonation, where an attacker poses as an executive, vendor, or internal staff member to convince someone to share sensitive information or take an unauthorized action. Microsoft's Digital Defense Report puts this as a shift in tactics because attackers exploit trust in familiar identities rather than relying on malicious attachments or links.

The third pattern in Paubox's 2025 data was vendor and business associate email exposure, responsible for 28% of all reported email incidents, either because a vendor's own account was compromised or because PHI was emailed to a partner without adequate protection.

Besides these attack patterns, Paubox's 2026 Healthcare Email Security Report found that breached organizations tended to share the same foundational configuration gaps, nearly three-quarters lacked effective DMARC enforcement (the policy that tells receiving servers whether to reject or quarantine emails that fail authentication), over half had permissive or missing SPF records (which verify whether a message actually came from an authorized server), and none enforced MTA-STS, the setting that requires encrypted connections between mail servers.

 

What is identity theft?

According to the Federal Trade Commission, identity theft happens when someone uses a person's personal or financial information without their permission. That could mean a thief gets hold of their name and address, their card or bank numbers, their Social Security number, or their medical insurance details and then uses them to make purchases, open new accounts in their name, file a fraudulent tax return, get a job, receive medical care, or even pose as them if they're stopped by police.

Identity theft is an active, deliberate act carried out by a criminal using stolen or otherwise obtained personal information. Unlike a data breach, which is a passive event that happens to a person’s data, identity theft is something that happens directly. Its consequences include damaged credit, drained bank accounts, tax complications, and sometimes months or years of effort to restore their name and financial standing.

 

Where to report it

If you believe your identity has been stolen, the FTC directs consumers to file a report at IdentityTheft.gov, which generates a free, personalized recovery plan, lets you track your progress, and provides pre-filled letters to send to credit bureaus, businesses, and debt collectors. The site offers guidance for more than 30 different types of identity theft, including what to do if your information was exposed in a data breach.

 

FAQs

Does a HIPAA breach have to involve email to be reportable?

No, breach notification obligations apply to any impermissible use or disclosure of unsecured PHI, regardless of whether it happened over email, paper, a lost device, or a system misconfiguration.

 

Is a covered entity liable for a breach that happens on a business associate's email system?

Yes, the covered entity remains accountable for PHI in transit and can face liability even when the technical failure occurred on a vendor's system.

 

Does having multiple security vendors guarantee stronger protection than a single platform?

Not necessarily, Paubox's 2025 breach analysis found the presence of multiple security tools didn't consistently correlate with stronger authentication posture or lower breach risk.