WellDyne, a Florida-based pharmacy benefit management company that helps health plans, employers, and government programs manage prescription drug costs, has disclosed a data breach after a ransomware group claimed to have stolen data from its systems.
Companies that manage prescription benefits and health plan data are entrusted with some of the most sensitive personal and medical information a person has, and they carry a responsibility to keep that information secure from unauthorized access.
WellDyne’s Data Breach Investigation
According to public reporting, a ransomware group calling itself “payoutsking” added WellDyne to its dark-web leak site in mid-June 2026, claiming to have exfiltrated internal files during a ransomware attack. WellDyne subsequently notified the U.S. Department of Health and Human Services Office for Civil Rights of a hacking/IT incident involving a network server, reporting that the breach affected at least 500 Florida residents. Under Florida law, companies must report breaches affecting 500 or more state residents to the Florida Attorney General within 30 days of notifying individuals, which suggests the total number of people affected nationwide, across all the health plans and employers WellDyne serves, could be considerably higher than the Florida-specific figure reported.
Pharmacy benefit managers like WellDyne sit at the center of the healthcare data ecosystem, processing prescription claims, insurance eligibility information, and personal health details for millions of patients across the country. This central role makes them an attractive target for cybercriminals, since a single successful intrusion can expose records tied to numerous health plans and employer groups at once, rather than just one organization’s customer base.
Ransomware groups that steal data before encrypting systems, sometimes called double extortion attacks, increasingly use the threat of publishing stolen files as leverage to pressure victim companies into paying a ransom. Whether or not WellDyne paid, the underlying concern for affected individuals remains the same: personal and health-related information may have already been copied by unauthorized parties before any negotiation took place.
Notification timelines for incidents like this can stretch for months, as forensic investigators work to determine exactly whose data was involved and what specific categories of information were exposed. Individuals connected to WellDyne through a health plan, employer, or government program should watch for an official notification letter describing the specific information involved in their case.
When Did This Breach Occur?
Public reporting indicates the ransomware group first claimed responsibility for the attack around June 15, 2026, with the listing becoming more widely reported by early July 2026. WellDyne’s notification to the HHS Office for Civil Rights, which tracks healthcare data breaches affecting 500 or more individuals, was submitted on August 25, 2026. The exact date WellDyne’s systems were first compromised has not been publicly disclosed.
What Information Was Breached?
WellDyne has not publicly released a detailed list of the specific data elements involved in this incident. Given the nature of WellDyne’s business as a pharmacy benefit manager, the information it typically holds includes patient names, contact information, insurance and health plan details, and prescription records, though the company has not confirmed which of these categories, if any, were part of the files taken in this specific incident.
What You Can Do
If you receive a notification letter from WellDyne or a health plan that uses WellDyne’s services, read it carefully to understand exactly what information was involved in your case. Consider these steps:
- Enroll in any free credit monitoring or identity protection services offered in the notification letter
- Review your health insurance statements (Explanation of Benefits) for services you do not recognize
- Place a fraud alert or credit freeze with the major credit bureaus if Social Security numbers may have been involved
- Watch for phishing emails or calls referencing your prescription or insurance information
- Keep any notification letter and related correspondence in case you need it later
File a Data Breach Lawsuit Against WellDyne
If your personal information was exposed as a result of this breach, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.