Consumer LawSource Verified

What Is a Breach of Privacy? Understanding U.S. Privacy Rights

Navigating the U.S. sectoral privacy framework, Fourth Amendment protections, HIPAA, the CCPA/CPRA, and common law privacy torts.

Updated: Sep 23, 2026
10 min read
Rev. 1
Direct Short Answer

In the United States, privacy rights are not governed by a single comprehensive federal privacy statute. Instead, American privacy law is a decentralized sectoral framework combining constitutional protections against government surveillance (under the Fourth Amendment), federal statutes targeting specific industries (such as HIPAA for healthcare, GLBA for banking, and COPPA for children's data), modern state consumer data privacy statutes (led by California's CCPA/CPRA), and common law torts (such as intrusion upon seclusion and public disclosure of private facts). Whether an unauthorized disclosure or data collection constitutes an actionable breach of privacy depends strictly on the context, the entity involved, and the applicable jurisdiction.

Key Takeaways
  • The United States utilizes a 'sectoral' privacy model, regulating data by industry (healthcare, banking, communications) rather than through one single omnibus federal law.
  • The Fourth Amendment protects citizens against unreasonable government searches and electronic surveillance, but does not apply to private corporations.
  • Federal sectoral statutes include HIPAA (protected health information), GLBA (financial records), COPPA (children under 13), and the FCRA (consumer credit reports).
  • Comprehensive state consumer privacy laws—beginning with California (CCPA/CPRA) and expanding to over 15 states—grant consumers rights to access, delete, and opt out of data sales.
  • Common law recognizes four distinct privacy torts: intrusion upon seclusion, public disclosure of private facts, false light, and commercial appropriation of likeness.

The American Privacy Architecture: A Sectoral Patchwork

In the European Union and many common law democracies, data privacy is governed by comprehensive, omnibus legislation—most notably the General Data Protection Regulation (GDPR)—that establishes uniform data rights across all commercial and public sectors.

By contrast, the United States legal framework lacks a single, all-encompassing national data privacy statute. Instead, privacy rights in the United States are defined by a complex, decentralized sectoral model. Different industries, data types, and jurisdictions are governed by distinct federal statutes, targeted state legislation, regulatory enforcement agencies (primarily the Federal Trade Commission), and state common law tort doctrines.

To determine whether an individual's privacy rights have been breached, one must analyze three primary questions:

  1. Who committed the intrusion? (A governmental law enforcement actor vs. a private commercial corporation);
  2. What category of information was compromised? (Healthcare records, consumer financial data, children's online activity, or general browsing telemetry); and
  3. In which state does the affected individual reside?

Constitutional Privacy Rights: The Fourth Amendment Barrier

At the federal constitutional level, privacy rights protect citizens strictly against governmental overreach and state-sponsored surveillance. The Bill of Rights does not contain the literal word 'privacy,' but the United States Supreme Court has repeatedly held that constitutional liberties safeguard a vital sphere of personal autonomy.

The primary constitutional shield is the Fourth Amendment, which guarantees:

In the landmark precedent of Katz v. United States (389 U.S. 347, 1967), Justice John Marshall Harlan established the foundational Reasonable Expectation of Privacy Test:

  1. The individual must have exhibited an actual (subjective) expectation of privacy; and
  2. The expectation must be one that society is prepared to recognize as objectively reasonable.

In modern digital jurisprudence, the Supreme Court has extended Fourth Amendment protections to cellular location records (Carpenter v. United States, 138 S. Ct. 2206, 2018) and smartphone data (Riley v. California, 573 U.S. 373, 2014), mandating that law enforcement procure a judicial search warrant based on probable cause before searching personal digital devices.

Critical Limitation: The Fourth Amendment restricts only government agents (police officers, federal investigators, public school administrators). It provides zero constitutional protection against private tech corporations, employer monitoring, or commercial data brokers.

Major Federal Sectoral Privacy Statutes

Congress has enacted targeted, industry-specific statutes that establish strict data safeguarding obligations across critical commercial sectors:

Federal StatuteRegulated Subject MatterPrimary Regulatory AuthorityPrivate Right of Action?
HIPAA (45 C.F.R. Parts 160/164)Protected Health Information (PHI) held by covered entitiesU.S. Dept. of Health & Human Services (OCR)No (Enforced by HHS & State AGs)
GLBA (15 U.S.C. § 6801 et seq.)Nonpublic personal financial information held by financial institutionsFTC, CFPB, Federal ReserveNo (Enforced by banking regulators)
COPPA (15 U.S.C. § 6501 et seq.)Online collection of personal data from children under 13Federal Trade Commission (FTC)No (Enforced by FTC & State AGs)
FCRA (15 U.S.C. § 1681 et seq.)Consumer credit reports and background screening filesFTC & CFPBYes (Statutory & actual damages)
FERPA (34 C.F.R. Part 99)Student educational records in federally funded institutionsU.S. Department of EducationNo (Enforced by Dept. of Education)
ECPA (18 U.S.C. § 2510 et seq.)Interception of wire, oral, and electronic communicationsU.S. Department of JusticeYes (Civil damages & criminal penalties)

1. Healthcare Privacy: HIPAA

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its Privacy and Security Rules strictly govern Protected Health Information (PHI). HIPAA applies exclusively to 'covered entities' (hospitals, doctors, pharmacies, health insurance plans) and their 'business associates.' It mandates administrative, physical, and technical safeguards, and requires patients to be notified of data breaches.

Common Misconception: HIPAA does not apply to consumer fitness tracking apps, direct-to-consumer DNA testing platforms, or general health blogs, as these entities are not covered healthcare providers.

2. Financial Privacy: The Gramm-Leach-Bliley Act (GLBA)

The Gramm-Leach-Bliley Act of 1999 requires financial institutions (banks, credit card lenders, mortgage brokers) to explain their information-sharing practices through annual privacy notices and grant consumers the right to opt-out of data sharing with non-affiliated third parties.

3. Children's Online Privacy: COPPA

The Children's Online Privacy Protection Act of 1998 prohibits commercial websites and online services directed to children from collecting personal information from children under the age of 13 without verifiable parental consent.

The State Consumer Privacy Revolution

In the absence of a comprehensive federal consumer privacy law, individual states have stepped into the regulatory vacuum, fundamentally transforming corporate data governance.

The California Framework (CCPA and CPRA)

Enacted in 2018 and significantly expanded by the California Privacy Rights Act (CPRA) in 2020, the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.) established the nation's premier consumer privacy regime:

  • Right to Know: Consumers can demand an accounting of the specific categories of personal information a business collects, uses, and sells.
  • Right to Delete: Consumers can compel businesses to permanently erase their personal information from internal records and third-party vendors.
  • Right to Opt-Out: Businesses must display a clear, conspicuous link titled 'Do Not Sell or Share My Personal Information,' allowing consumers to halt the commercial sharing of their data.
  • Right to Correct: Consumers can compel businesses to correct inaccurate personal data.
  • Private Right of Action for Data Breaches: If a business fails to maintain reasonable security practices resulting in the exfiltration or unauthorized access of sensitive personal data, California consumers can sue directly under Cal. Civ. Code § 1798.150 for statutory damages of up to $750 per consumer per incident, creating massive class-action exposure.

Following California's lead, more than fifteen states—including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and Florida (FDBR)—have enacted comprehensive consumer data privacy statutes, establishing a nationwide patchwork of compliance mandates.

Common Law Privacy Torts: Suing for Civil Privacy Invasions

Long before the advent of digital internet tracking, American common law recognized the right to be protected against private intrusions. In his celebrated 1960 California Law Review treatise, Dean William Prosser categorized common law invasion of privacy into four distinct civil torts, adopted in the Restatement (Second) of Torts:

1. Intrusion Upon Seclusion (§ 652B)

An intentional, physical or electronic intrusion into the private affairs or private space of an individual, where the intrusion would be highly offensive to a reasonable person.

  • Examples: Installing unauthorized hidden video cameras in a private home, eavesdropping on private telephone calls, or hacking into a private email account.

2. Public Disclosure of Private Facts (§ 652D)

The public dissemination of private, non-newsworthy facts concerning an individual, where the disclosure would be highly offensive to a reasonable person and is not of legitimate public concern.

  • Examples: Publishing an individual's private medical history, disclosing confidential intimate photographs (non-consensual imagery), or publicizing private financial insolvency details.

3. False Light Invasion of Privacy (§ 652E)

Publicly attributing to an individual false characteristics, beliefs, or actions that place them in a highly offensive false position in the public eye, even if the statement does not meet the strict technical standards of common law defamation.

4. Commercial Misappropriation of Name or Likeness (§ 652C)

The unauthorized commercial use of an individual's name, photograph, voice, or persona for commercial advantage or advertising purposes without their consent (the foundation of the modern 'Right of Publicity').

What to Do If Your Privacy Has Been Breached

If you discover that your personal records, sensitive communications, or confidential data have been compromised:

  1. Document the Intrusion: Capture timestamped screenshots, preserve system audit logs, and download compromised files immediately.
  2. Determine the Applicable Legal Channel: If the breach was committed by a healthcare provider, submit an administrative complaint to the HHS Office for Civil Rights; if committed by a financial institution, notify the Consumer Financial Protection Bureau (CFPB).
  3. Exercise Statutory Consumer Rights: If you reside in California or an equivalent consumer privacy state, submit a formal verified consumer request demanding the deletion or cessation of data sharing.
  4. Evaluate Civil Litigation Options: Consult a personal injury or privacy litigation attorney to determine whether the conduct supports a civil lawsuit for common law intrusion upon seclusion, statutory data breach damages, or breach of contract.

For additional authoritative information regarding related United States legal principles, review our companion guides:

  • [What Is the Fair Credit Reporting Act?](/consumer-law/fair-credit-reporting-act): Understand consumer credit privacy, background check rules, and dispute procedures under the FCRA.
  • [What Is Probable Cause in U.S. Law?](/criminal-law/probable-cause): Explore Fourth Amendment search warrant requirements for cellular devices and digital records.
  • [What Are Civil Rights in the United States?](/civil-rights/what-are-civil-rights): Learn how the Bill of Rights safeguards individual liberty and personal autonomy from state surveillance.
  • [What Is the Americans with Disabilities Act?](/civil-rights/americans-with-disabilities-act): Understand statutory medical confidentiality protections in the workplace under the ADA.

Authoritative Sources & Citations

Verified Citations

LawScope strictly cites primary government, court, and statutory records to substantiate legal analyses.

  • RegulationU.S. Department of Health and Human Services

    Health Insurance Portability and Accountability Act (HIPAA), 45 C.F.R. Part 160 & 164

    View Source
  • StatuteCalifornia Department of Justice

    California Consumer Privacy Act of 2018 (CCPA/CPRA), Cal. Civ. Code § 1798.100 et seq.

    View Source
  • TreatiseAmerican Law Institute

    Restatement (Second) of Torts § 652A - General Principle of Privacy

    View Source

Frequently Asked Questions

No. The word 'privacy' does not appear in the text of the United States Constitution. However, the Supreme Court has recognized a constitutional right to privacy emanating from the 'penumbras' of the First, Third, Fourth, Fifth, and Ninth Amendments (Griswold v. Connecticut, 381 U.S. 479), with the Fourth Amendment explicitly protecting the right of people to be secure in their persons, houses, papers, and effects against unreasonable searches.
Elena Vance
Elena Vance(Senior Legal Research Editor)

Elena Vance has over a decade of experience analyzing federal statutes, administrative regulations, and appellate jurisprudence. She specializes in translating complex civil rights, employment, and constitutional law topics into accessible, research-backed public knowledge resources.

Editorial staff researcher; does not provide legal representation or attorney-client advice.

Legal Information Notice

LawScope provides general educational information about United States law and legal procedures. This content does not constitute formal legal representation, legal advice, or attorney-client communications. State statutory interpretations and municipal regulations vary significantly. For advice regarding a specific legal matter, consult a licensed attorney in your jurisdiction.