PanicStation.org
us Work & employment crises

What to do if…
your personal information is being shared at work without your consent

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Record exactly what was shared and ask the appropriate workplace contact in writing to stop further sharing, restrict access, and remove exposed material where possible. Secure any accounts or identity information that could be misused.

Do not do these things

  • Do not confront people publicly or repeat the information while trying to correct the situation.
  • Do not delete relevant emails, messages, screenshots, notices, or your own notes.
  • Do not copy, forward, or take workplace records that you are not authorized to keep.
  • Do not access restricted systems to investigate who viewed the information.
  • Do not make a hidden recording until you have checked the law in every state where the conversation occurs and any applicable workplace rules.
  • Do not resign, threaten legal action, or post accusations online in the first rush of panic.
  • Do not assume that every disclosure without consent is automatically unlawful, because the rules depend on the information, its source, the employer, and state and federal law.
  • Do not delay protecting accounts if passwords, financial details, identity documents, or a Social Security number were exposed.

What to do now

  1. If the disclosure creates an immediate risk of violence, stalking, or someone coming to your home, move to a safer place and call 911.

  2. Write down what you know while it is fresh. Record the information shared, who shared it, who received or saw it, when and where it appeared, and how you learned about it. Separate what you personally observed from what someone else reported.

  3. Preserve only material you are authorized to keep, such as messages sent directly to you, your own emails, or a photograph of information displayed where you were permitted to be. Keep a dated incident log.

  4. Report the disclosure in writing through the employer’s appropriate Human Resources, privacy, compliance, information-security, or management route. Use another designated contact if the person who shared the information normally receives complaints.

  5. Identify the information precisely and ask the employer to stop further sharing, restrict access, remove or recall exposed material where possible, preserve relevant access records, and confirm what immediate containment steps are being taken.

  6. State clearly if the disclosure includes medical information, genetic test information, or family medical history. Federal confidentiality rules may apply to some employer-held medical and genetic information, depending on employer coverage and how the information was obtained. HIPAA generally does not protect employment records merely because they contain health information.

  7. If login details, security answers, financial information, a Social Security number, or identity documents were exposed, change affected passwords, enable multi-factor authentication, and contact the relevant bank or account provider. Consider a credit freeze or fraud alert when information usable for identity theft was exposed.

  8. Check the employer’s confidentiality, privacy, data-security, anti-harassment, and complaint policies. Follow the listed reporting route and keep a copy of your report and any response.

  9. If the sharing appears connected to disability, genetic information, discrimination, harassment, or retaliation for raising an equal-employment concern, contact the Equal Employment Opportunity Commission promptly. Filing deadlines apply, and federal employees use a different complaint process.

  10. If the information has already been used to open accounts, make purchases, claim benefits, or impersonate you, use IdentityTheft.gov to create a recovery plan.

  11. If the employer does not contain a serious disclosure, check your state attorney general’s information or seek state-specific employment legal advice. State protections and complaint routes vary.

What can wait

You do not need to decide today whether to resign, file a lawsuit, contact the media, accuse someone publicly, or calculate every possible loss. A complete legal analysis and long-term career decisions can wait while you contain the disclosure, protect exposed information, and create a factual record.

Important reassurance

You do not need to prove the entire legal position before asking the employer to stop further sharing. A calm written report, careful documentation, and prompt account protection can reduce further harm and preserve your options.

Scope note

This guide covers immediate containment and documentation only. Later decisions may require help from an employment lawyer, union representative, privacy professional, regulator, or identity-theft specialist familiar with your state and workplace.

Important note

This is general information, not legal, financial, cybersecurity, or other professional advice. The rules depend on the type and source of the information, the employer’s coverage, the reason for disclosure, and applicable state and federal law.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us