Blog > Data Breach & Privacy

MedImpact Data Breach: What Health Plan Members Need to Know

MedImpact Healthcare Systems, a pharmacy benefit manager serving health plans nationwide, identified unauthorized activity in its systems in October 2025 and in 2026 began notifying members of client health plans that their information may have been involved. Here is what has been disclosed and what affected members can consider doing.

MedImpact Data Breach: What Health Plan Members Need to Know

What Happened in the MedImpact Data Breach

Ransomware identified in October 2025, with notices following in 2026

According to notification letters filed with the California Attorney General on behalf of a client health plan, MedImpact Healthcare Systems, Inc. states that on October 18, 2025, it identified unauthorized activity within certain systems in its environment. MedImpact reports that it promptly took steps to secure the affected systems, engaged cybersecurity experts to assist with the investigation and response, and then conducted a detailed review of the data that may have been impacted to determine whose information was included.

In a public statement dated October 27, 2025, MedImpact said it had identified ransomware on certain systems, immediately began containment and mitigation measures, launched an investigation with a leading cybersecurity firm, and was notifying all applicable authorities. The company said it was restoring impacted systems in a new environment segregated from the prior infrastructure, and that pharmacy claims for all clients were again adjudicating. Around the same time, a ransomware group known as Qilin publicly claimed responsibility on its leak site; MedImpact has not publicly named a group, and the claim has not been confirmed by the company. Notification letters to plan members were filed with the California Attorney General in mid-September 2026, roughly eleven months after the activity was identified.

What Information May Have Been Involved

Names and additional data elements that vary by member

In its letters, MedImpact states that the information involved varied by individual and consisted of the member’s first and last name together with additional data elements identified in each recipient’s letter. The specific categories are not itemized in the sample notices filed with the California Attorney General, so exactly which information was involved for any given member has not been publicly detailed. MedImpact states it has no reason to believe the information has been or will be misused.

Because MedImpact processes pharmacy benefits, the data it holds about plan members can include prescription and claims details alongside identifying information, so members may wish to treat the situation with appropriate care even though the company has not confirmed specific categories. Reporting on the leak-site claim indicates the material posted consisted largely of business documents such as financial summaries and remittance logs rather than member health records; that reporting reflects the threat actor’s postings, not a statement by MedImpact.

Who May Be Affected by the MedImpact Breach

Members of client health plans, including adults and minor dependents

MedImpact is a San Diego-based pharmacy benefit manager that administers prescription drug benefits on behalf of health plans and employer-sponsored plans. Because it acts as a service provider to those plans, the individuals potentially affected are members of MedImpact’s client plans rather than direct customers of MedImpact. The California filing was made for members of the Leggett & Platt, Incorporated Employee Benefits Plan, and MedImpact issued separate notices for adult members and for the parents or guardians of minor dependents, indicating that children’s information may be among the data involved.

Other client plans may be notifying their members separately, and MedImpact has not published a total number of affected individuals. As of this writing, the incident does not appear on the U.S. Department of Health and Human Services breach portal under MedImpact’s name. If you or your child received a letter from MedImpact, or from your health plan referencing MedImpact, that notice may indicate your information was among the data reported to have been affected.

How MedImpact Responded and What Protections Are Offered

Enhanced safeguards, but no credit monitoring offer in the California notices

MedImpact reports that it secured the affected systems, engaged cybersecurity experts, notified applicable authorities, rebuilt impacted systems in a segregated environment, and has taken steps to further enhance its security safeguards and monitoring. The company states it has no evidence that any personal information has been or will be misused.

Notably, the sample notices filed with the California Attorney General do not include an offer of complimentary credit monitoring or identity protection services. Instead, the letters enclose general resources describing how to obtain free credit reports, place fraud alerts, and request a security freeze. Members should review their own letter, since terms can differ between plans and notification rounds.

Steps You Can Take to Protect Yourself

Practical precautions for members and parents of minor dependents

Given that no monitoring service is offered in the California notices, affected members may wish to take these steps on their own:

  • Consider a credit freeze or fraud alert. Both are free through Equifax, Experian, and TransUnion. Parents and guardians can also request a free security freeze on a minor child’s credit file, which can help prevent accounts from being opened in the child’s name.
  • Review your Explanation of Benefits and pharmacy statements. Watch for prescriptions, claims, or services you or your child did not receive, which can be a sign of medical identity theft.
  • Check your credit reports. You are entitled to free credit reports at annualcreditreport.com.
  • Keep your notice. It identifies the specific information involved for you or your child and may be important if you explore your options.
  • Stay alert to phishing. Be cautious of unexpected emails, calls, or texts referencing MedImpact, your health plan, or the incident, and verify any outreach independently before responding.

This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.

Talk to Wilshire Law Firm

Were you or your child affected by the MedImpact data breach?

If your personal or health information, or your child’s, may have been involved in the MedImpact data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.

Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.

FAQs

According to MedImpact’s notification letters, the company identified unauthorized activity within certain systems on October 18, 2025. MedImpact issued a public statement about a ransomware incident on October 27, 2025, and notification letters to health plan members were filed with the California Attorney General in mid-September 2026.

MedImpact’s public statement says it identified ransomware on certain systems; its letters describe unauthorized activity within its environment. A ransomware group known as Qilin claimed responsibility on its leak site, but MedImpact has not publicly attributed the incident to any group or confirmed that claim.

MedImpact states the information varied by individual and included the member’s first and last name plus additional data elements identified in each recipient’s letter. The specific categories were not itemized in the sample notices filed with the California Attorney General.

Members of health plans that use MedImpact as their pharmacy benefit manager. The California filing covers members of the Leggett & Platt, Incorporated Employee Benefits Plan, including minor dependents; other plans may notify their members separately. MedImpact has not published a total count.

The sample notices filed with the California Attorney General do not include an offer of credit monitoring or identity protection services; they provide general information about credit reports, fraud alerts, and security freezes. Members should check their own letter, as terms may differ.

Consider placing a credit freeze or fraud alert for yourself and any minor child named in a notice, review Explanation of Benefits and pharmacy statements, check your credit reports, keep the letter, and stay alert to phishing. You may also wish to speak with a legal professional about any rights or options that may apply to your situation.

Individuals who believe they were affected may have legal options, and breaches involving health plan members’ information, particularly where notification came many months after discovery and no monitoring was offered, can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,521 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance