Leggett & Platt, Incorporated Employee Benefits Plan recently notified plan members that MedImpact Healthcare Systems, Inc., the pharmacy benefits manager that administers pharmacy claims for the plan, identified unauthorized activity within certain systems in its environment.
Organizations that rely on outside vendors to process sensitive health and pharmacy information take on a responsibility to ensure those vendors safeguard that data, and when an incident like this occurs, affected individuals deserve clear answers about what happened and what steps they can take next.
Leggett & Platt, Incorporated Employee Benefits Plan’s Data Breach Investigation
According to a notification letter filed with the California Attorney General’s Office, MedImpact discovered unauthorized activity within its systems on or around October 18, 2025. MedImpact publicly confirmed the incident on October 27, 2025, stating it had identified ransomware on certain systems and immediately began implementing containment and mitigation measures. The company engaged outside cybersecurity experts to investigate the scope of the incident and notified applicable authorities.
MedImpact’s notification letter to affected plan members states that the specific information involved varied by individual, though the company has not publicly itemized a universal list of data elements affected for every person notified. MedImpact said it has no reason to believe the information has been or will be misused, though affected individuals are still encouraged to remain alert to potential misuse of their information.
Separately, a ransomware group calling itself Qilin publicly claimed responsibility for the intrusion and stated it had exfiltrated a substantial volume of data from MedImpact’s systems, including files related to the company’s business operations. MedImpact has not confirmed the full scope or nature of what the attackers may have accessed. As of its most recent public statement, MedImpact said it was rebuilding affected systems in a new, segregated environment protected by additional layers of security.
Ransomware attacks against pharmacy benefit managers and other healthcare-adjacent vendors have become increasingly common in recent years, largely because these companies sit at the center of large volumes of sensitive claims, eligibility, and member data flowing between health plans, employers, and pharmacies. A single compromised vendor can potentially affect the members of many different employer-sponsored benefit plans at once, since one vendor’s systems often service dozens or hundreds of separate client organizations simultaneously.
When a data breach notification does not specify the exact categories of information involved for every individual, it is often because the investigating company is still working through which specific records were affected for which specific people, a process that can take weeks or months following initial discovery of an intrusion. Regulatory notification laws generally require companies to notify affected individuals within a defined window after determining that personal information was likely compromised, even if forensic work to pin down every detail is still ongoing.
For individuals whose employer-sponsored benefits are administered through a pharmacy benefits manager, this kind of incident is a reminder that the risk from a data breach does not always originate from the employer or health plan itself, but can also originate from a third-party vendor entrusted with processing that data behind the scenes. Consumers are generally not in a position to evaluate a vendor’s security practices directly, which is part of why notification laws exist, to ensure affected individuals learn about incidents that occur outside their direct line of sight.
It is also worth noting that because MedImpact serves clients and plan members across the country, notifications related to this incident are likely being sent to individuals in multiple states through each state’s own regulatory process, even though the underlying incident and investigation are the same. A filing with one state’s Attorney General, such as California’s, does not mean the incident was limited to that state’s residents.
When Did This Breach Occur?
MedImpact identified unauthorized activity, later confirmed to involve ransomware, on or around October 18, 2025. The company publicly acknowledged the incident on October 27, 2025, and subsequently notified affected plan members, including those covered under the Leggett & Platt, Incorporated Employee Benefits Plan.
What Information Was Breached?
MedImpact’s notification letter to affected individuals states that the information involved varied by person, but the letter does not publicly specify a single universal list of data elements affected for every plan member notified. MedImpact has stated it has no reason to believe the information has been or will be misused.
What You Can Do
If you received a letter about this breach, consider taking the following steps:
- Monitor your email, phone, and mail for suspicious contact attempts referencing your personal or health plan details.
- Be cautious of unsolicited messages asking you to click a link, download an attachment, or provide additional personal information.
- Review your financial accounts, health plan statements, and credit reports for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus if you are concerned about identity theft.
- Keep a copy of your notification letter and any related correspondence in case you need it later.
File a Data Breach Lawsuit Against Leggett & Platt, Incorporated Employee Benefits Plan
If you received a data breach notification letter regarding this incident, or if you believe your personal information was exposed as a result of the MedImpact breach, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.