Basically, a business who receives information that they or a subset of their users have had their accounts compromised would have to register with this database, and provide an update when the password has been changed, also providing information as to whether the account has been accessed since the date the compromise was recognized.
Citizens would be able to say, for example "OK, has my [some provider] account been compromised? How was it compromised, and when was it first known? Has it been accessed since then? Has the company dealt with the intrusion in THEIR systems and have they mandated a credential update for my account and has the update been achieved?"



