Start by identifying exactly which data was exposed, then immediately change the compromised credentials on every account where that password was reused. PHI breaches trigger mandatory notification obligations to affected patients, the HHS Office for Civil Rights, and, in large-scale incidents,…
