Were you recently affected by a data breach?

MedImpact Data Breach

MedImpact Healthcare Systems, a pharmacy benefits manager serving over 50 million members nationwide, detected unauthorized activity in its systems in October 2025 that may have exposed personal information belonging to plan members of the employer and health plan clients it serves.

MedImpact
Date of Breach: Unauthorized activity identified October 18, 2025; publicly disclosed October 27, 2025
CAU logo

Who was affected:

Clients of MedImpact

Impacted Data:

Names and other personal information that varied by individual; the company has not publicly itemized a universal list of data elements affected for every person notified

MedImpact Healthcare Systems, Inc., a pharmacy benefits manager that administers prescription drug programs for health plans, employers, and government agencies across the country, has disclosed a data breach after detecting unauthorized activity within its systems. Companies entrusted with the prescription and health information of tens of millions of people have a responsibility to safeguard that information and to notify affected individuals when it is compromised.

MedImpact’s Data Breach Investigation

According to a notification letter filed with the California Attorney General’s Office, MedImpact discovered unauthorized activity within its systems on or around October 18, 2025. The company publicly confirmed the incident on October 27, 2025, stating that it had identified ransomware on certain systems and immediately began implementing containment and mitigation measures. A ransomware group calling itself Qilin separately claimed responsibility for the intrusion and stated that it had exfiltrated data from MedImpact’s systems, including files described as related to the company’s business operations, though it has not confirmed that patient-level personal health information was included in what it obtained.

Because MedImpact serves clients and plan members across the country as a third-party pharmacy benefits administrator, notifications related to this incident are being sent to affected individuals through the notification and regulatory processes of multiple states, even though the underlying incident and investigation are the same. A filing with one state’s Attorney General, such as California’s, does not mean the incident was limited to that state’s residents, and MedImpact’s own client companies, such as employers and health plans that use its services, are separately notifying their own plan members whose data was involved.

Pharmacy benefit managers and other healthcare-adjacent vendors are frequent targets for ransomware groups because they centralize large volumes of sensitive information, including prescription histories, insurance identifiers, and demographic data, on behalf of many downstream client organizations at once. A single successful intrusion into a vendor like MedImpact can therefore expose the personal information of individuals across many unrelated employers and health plans simultaneously, which is part of what makes vendor-level breaches like this one especially consequential compared to a breach at a single employer.

MedImpact has stated it has no reason to believe the information involved has been or will be misused, though the company is still encouraging affected individuals to remain alert to potential misuse of their personal information following notification. The specific data elements exposed reportedly varied from person to person, and MedImpact has not publicly itemized a single universal list of information types affected for every individual who received a notice.

When Did This Breach Occur?

MedImpact identified the unauthorized system activity on or around October 18, 2025, and publicly confirmed the ransomware incident on October 27, 2025. A notification letter describing the incident was filed with the California Attorney General’s Office on September 15, 2026, roughly eleven months after the activity was first identified, reflecting the extended investigation and notification timeline common to large-scale vendor breaches affecting many downstream client organizations.

What Information Was Breached?

MedImpact has stated that the specific information involved varied by affected individual, and the company has not publicly disclosed a single universal list of data elements affected for every person notified. Both adult plan members and, in at least some client relationships, minor dependents were among those whose data was involved, with MedImpact sending separate notification letters to affected adults and to the parents or guardians of affected minors.

What You Can Do

  • Read any notification letter you receive from MedImpact or from your employer/health plan carefully.
  • Monitor your financial accounts, insurance claims, and credit reports for signs of unfamiliar activity.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus.
  • Watch for phishing attempts referencing MedImpact, your pharmacy benefits, or your health plan.
  • Keep copies of any notices or correspondence related to this incident.

File a Data Breach Lawsuit Against MedImpact

If you received a notice about this incident, or believe your personal information may have been exposed through MedImpact’s systems, you may have legal options. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 21, 2026
Date of Breach: October 27, 2025
Date of Breach: Unauthorized activity identified October 18, 2025; publicly disclosed October 27, 2025
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.