Imagine the Possibilities, an Iowa nonprofit that provides community-based services to people with disabilities, reported a hacking incident affecting 1,693 people to federal health regulators on September 21, 2026. Its website points to a security incident at a vendor, PDCM Insurance.
Imagine the Possibilities’s Data Breach Investigation
Imagine the Possibilities, Inc. is an Iowa nonprofit organization that provides community-based services to people with disabilities across much of the state. Organizations like this hold health-related and personal information about the people they serve and about their staff, which means a security incident can expose details that are both sensitive and difficult to change.
The U.S. Department of Health and Human Services Office for Civil Rights, which publishes the list of health data breaches affecting 500 or more people, shows an entry for Imagine the Possibilities submitted on September 21, 2026. The entry lists the organization as a health plan in Iowa, reports 1,693 individuals affected, classifies the incident as hacking or an IT incident, and lists a network server as the location of the breached information. It also indicates that a business associate was present.
On its own website, the organization posts a notice about a security incident experienced by one of its vendors, PDCM Insurance, that affected customer data, and links to PDCM’s public notice. The federal listing itself does not name the vendor, so this page does not claim that every one of the 1,693 people was affected through the same event. The two items are described separately for that reason.
PDCM’s public notice says the company became aware of suspicious network activity on April 28, 2025. Its investigation found that there was unauthorized access to certain files and folders in its network between April 27, 2025 and April 28, 2025. PDCM states that it secured its network, notified law enforcement and reviewed the affected systems to determine what information they contained, and that it had no indication the information was subject to identity theft or fraud.
PDCM’s notice lists the kinds of information that were present on the involved systems, including names, Social Security numbers, financial account information and several categories of medical and health insurance information. Neither the federal listing nor the organization’s website says which of these categories apply to which people, so the notice letter you receive is the most reliable guide to your own situation.
The sources reviewed do not describe how the intruder gained access, whether Imagine the Possibilities has made its own statement beyond its website notice, or whether it is offering credit monitoring. This page does not fill those gaps with guesses, and it will be revisited if more information is published.
Incidents involving a vendor or business associate can be hard for individuals to follow, because the notice may come from a company you have never dealt with directly. If you received a letter from PDCM Insurance or from Imagine the Possibilities, keep it, and check it against the services you or a family member have received. A dedicated assistance line is listed in PDCM’s public notice for people with questions about the event.
When Did This Breach Occur?
PDCM’s public notice states that it became aware of suspicious network activity on April 28, 2025, and that unauthorized access to certain files and folders occurred between April 27, 2025 and April 28, 2025. The incident involving Imagine the Possibilities was submitted to federal regulators on September 21, 2026. Whether the two are the same event is not confirmed by the federal listing.
What Information Was Breached?
PDCM’s notice says the involved systems contained names, dates of birth, Social Security numbers, driver’s license numbers, state identification numbers, taxpayer identification numbers, financial account information, and medical and health insurance information such as treatment, diagnosis, prescription and policy numbers. Not every person necessarily had every type of information involved.
What You Can Do
If you received a notice, or believe you may be affected, consider these steps:
- Read the notice carefully and follow any instructions it gives, including any offer of credit monitoring or identity protection.
- Place a free fraud alert on your credit file, or consider a credit freeze, with Equifax, Experian and TransUnion.
- Review explanation of benefits statements and account statements for services or charges you do not recognize, and check your credit reports for free at annualcreditreport.com.
- Be cautious of calls, texts or emails that mention your health coverage or ask for personal details. Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against Imagine the Possibilities
If you received a notice about this incident, or believe your personal or health information was exposed, you may have legal options. Organizations that hold sensitive information are expected to protect it, and a class action can help hold them accountable when they fail to do so.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.