Straight answers on hard choicesLast filed Sep 8, 2026

Tech

One Breach, Two States, Two Different Letters. Who Wrote Yours, and What They Owe You

A single incident produces different notices in different states because different people write them. Knowing who they are tells you which parts of your response you can still undo.

Tech||Cecelia Hartnoll

Two data breach notification letters from the same company laid side by side on a kitchen table, one noticeably longer than the other, with their opened enve...
Two data breach notification letters from the same company laid side by side on a kitchen table, one noticeably longer than the other, with their opened enve...

Two households received notice of the same incident three weeks apart. Same company, a regional billing processor with clients in a dozen states, same intrusion, same file of names, dates of birth and Social Security numbers. One letter arrived with a specific list of the data elements involved and an enrollment code for two years of credit monitoring. The other described the exposure as "certain personal information" and offered one year. Neither household was being treated badly. They lived in different states, and their letters were assembled by different people working to different rules.

What follows is a composite drawn from how these notifications are typically produced, not a single named case. The mechanics are consistent enough that the composite is useful.

The letter was written by four organizations, not one

The company whose name appears at the top of the envelope usually writes very little of it. Within days of discovery, most organizations retain outside breach counsel, who in turn engage a forensic firm to determine what was accessed and when. A separate notification vendor prints and mails at volume, stands up a dedicated call center, and often administers the credit monitoring enrollment through one of the bureaus. The letter you hold is the output of that chain, drafted by lawyers, constrained by forensic findings that may still be provisional, and printed by a company with no knowledge of your account.

This matters when you call the number on the page. The person answering is reading from a script the same lawyers approved, and the script exists partly to avoid saying anything the forensic work has not yet established. They are not being evasive; they genuinely do not have your file. What they can usually do is confirm which data elements applied to you specifically, which is often narrower than the categories listed in the letter, and reissue an enrollment code that failed. Ask for the first of those in writing. It is the single most useful sentence you can obtain, because it determines whether this is a monitoring problem or an identity problem.

Why the same incident produced two different letters

Breach notification in the United States is state law, and the obligation follows the residence of the affected person rather than the location of the company. A processor in one state notifying customers in twelve is complying with twelve statutes at once. Those statutes disagree on the points that shape the letter: what counts as personal information, whether the notice must describe the specific data elements involved, whether the state attorney general must receive a copy and at what threshold, and whether credit monitoring must be offered at all. A few states require a specified period of monitoring when Social Security numbers are involved. Most do not require any.

Timing diverges as well. Several states set a hard outer limit measured in weeks from discovery, while others require notice without unreasonable delay and leave the reasonableness to be argued later. Counsel drafting for a multistate population generally builds one base letter and then adds state-specific inserts, which is why your neighbor's version may carry a paragraph yours lacks. Where a state's rules are more demanding, residents of that state receive more. The practical read is that a thinner letter is frequently a jurisdictional artifact rather than a sign that less was taken from you.

Sector rules layer on top of geography. Health information carries federal notification duties with their own timelines and content requirements, and insurance and banking regulators impose additional reporting on the entities they license. If the breached organization sits in a regulated sector, someone in a compliance function is filing with a regulator on a clock that runs independently of your mailbox. The Federal Trade Commission oversees consumer data security practices and maintains the federal identity theft recovery process, which is the reference point most state notices ultimately funnel you toward regardless of which state wrote the insert.

The clocks in the letter belong to other people

Three separate deadlines usually sit inside a notification, and only one of them is yours to control. The enrollment window for the offered monitoring service is set by contract between the company and the bureau, commonly ninety days from the letter date, and it is enforced by a vendor with no discretion. The regulatory filing deadline has already passed by the time you read anything. And somewhere further out, if litigation follows, a claims deadline will be set by a court and publicized through a settlement administrator, which is a fourth organization you have not yet heard from.

Treat the enrollment date as the only hard one. Enrolling costs nothing and forecloses nothing, and declining it because you already run your own monitoring is a defensible choice that becomes hard to revisit once the window closes. The more consequential move is placing a security freeze with each of the three nationwide credit bureaus, which is free by federal law, does not depend on the letter, and does not expire. A freeze is fully reversible. You can lift it for an hour to let a lender pull your file and it re-seals itself. Nothing in that sequence commits you to anything.

What is still reversible in five years, and what is not

Take the five-year view, because the exposed data has a longer useful life than the response window. A password can be changed. A credit card number can be reissued within a week. A driver's license number can be replaced at the DMV, with friction and a fee. A Social Security number effectively cannot, and neither can a date of birth or a mother's maiden name, which is why the specific data elements matter more than the size of the incident. If the file contained only names and email addresses, the exposure decays as accounts turn over. If it contained the permanent identifiers, you are managing a condition rather than closing an event, and the tools for that are the freeze, the annual review of your credit reports, and an IRS identity protection PIN if fraudulent returns are a live concern.

One decision in the sequence is genuinely irreversible, and it usually arrives eighteen months to three years later. If a class action settles, the notice you receive will offer a payment or a benefit in exchange for a release of your claims. Accepting it ends your ability to sue over that incident, including for harm that has not surfaced yet. Excluding yourself preserves the claim and costs you the payment. Neither choice is wrong, but the release is permanent in a way that nothing else in this process is, and it deserves more attention than the check amount tends to attract.

Keeping the record that makes the later choice possible

The people who will need documentation from you are the settlement administrator, possibly a state attorney general's consumer protection unit, and, if fraud actually occurs, a bank's dispute department. All three ask for the same things and none of them will accept your recollection. Keep the envelope and the letter, because the postmark and the letter date establish which state's version you received and when the clock started. Note the incident description and any reference number. If you call, record the date, the name given and what you were told about your specific data elements.

That folder is small and it ages well. Two years on, when a notice arrives from a court-appointed administrator asking whether you were affected and what you spent in response, the households that kept the original letter file a claim in ten minutes and the ones that did not spend an afternoon trying to reconstruct it. The same folder answers the question a fraud investigator will eventually ask, which is when you first learned your identifiers were loose. Different states will have given you different letters. What you do with the one you got is the part that is entirely yours.

More from this edition