Were you recently affected by a data breach?

Leggett & Platt, Incorporated Employee Benefits Plan Data Breach

Leggett & Platt, Incorporated Employee Benefits Plan notified members that MedImpact Healthcare Systems, its pharmacy benefits manager, detected unauthorized system activity in October 2025 that may have exposed plan members’ personal information.

Leggett & Platt, Incorporated Employee Benefits Plan
Date of Breach: Unauthorized activity identified October 18, 2025; publicly disclosed October 27, 2025
CAU logo

Who was affected:

Clients of Leggett & Platt, Incorporated Employee Benefits Plan

Impacted Data:

Personal information tied to plan members’ pharmacy benefits accounts; the specific data elements affected for each individual have not been publicly itemized

Leggett & Platt, Incorporated Employee Benefits Plan recently notified plan members that MedImpact Healthcare Systems, Inc., the pharmacy benefits manager that administers pharmacy claims for the plan, identified unauthorized activity within certain systems in its environment.

Organizations that rely on outside vendors to process sensitive health and pharmacy information take on a responsibility to ensure those vendors safeguard that data, and when an incident like this occurs, affected individuals deserve clear answers about what happened and what steps they can take next.

Leggett & Platt, Incorporated Employee Benefits Plan’s Data Breach Investigation

According to a notification letter filed with the California Attorney General’s Office, MedImpact discovered unauthorized activity within its systems on or around October 18, 2025. MedImpact publicly confirmed the incident on October 27, 2025, stating it had identified ransomware on certain systems and immediately began implementing containment and mitigation measures. The company engaged outside cybersecurity experts to investigate the scope of the incident and notified applicable authorities.

MedImpact’s notification letter to affected plan members states that the specific information involved varied by individual, though the company has not publicly itemized a universal list of data elements affected for every person notified. MedImpact said it has no reason to believe the information has been or will be misused, though affected individuals are still encouraged to remain alert to potential misuse of their information.

Separately, a ransomware group calling itself Qilin publicly claimed responsibility for the intrusion and stated it had exfiltrated a substantial volume of data from MedImpact’s systems, including files related to the company’s business operations. MedImpact has not confirmed the full scope or nature of what the attackers may have accessed. As of its most recent public statement, MedImpact said it was rebuilding affected systems in a new, segregated environment protected by additional layers of security.

Ransomware attacks against pharmacy benefit managers and other healthcare-adjacent vendors have become increasingly common in recent years, largely because these companies sit at the center of large volumes of sensitive claims, eligibility, and member data flowing between health plans, employers, and pharmacies. A single compromised vendor can potentially affect the members of many different employer-sponsored benefit plans at once, since one vendor’s systems often service dozens or hundreds of separate client organizations simultaneously.

When a data breach notification does not specify the exact categories of information involved for every individual, it is often because the investigating company is still working through which specific records were affected for which specific people, a process that can take weeks or months following initial discovery of an intrusion. Regulatory notification laws generally require companies to notify affected individuals within a defined window after determining that personal information was likely compromised, even if forensic work to pin down every detail is still ongoing.

For individuals whose employer-sponsored benefits are administered through a pharmacy benefits manager, this kind of incident is a reminder that the risk from a data breach does not always originate from the employer or health plan itself, but can also originate from a third-party vendor entrusted with processing that data behind the scenes. Consumers are generally not in a position to evaluate a vendor’s security practices directly, which is part of why notification laws exist, to ensure affected individuals learn about incidents that occur outside their direct line of sight.

It is also worth noting that because MedImpact serves clients and plan members across the country, notifications related to this incident are likely being sent to individuals in multiple states through each state’s own regulatory process, even though the underlying incident and investigation are the same. A filing with one state’s Attorney General, such as California’s, does not mean the incident was limited to that state’s residents.

When Did This Breach Occur?

MedImpact identified unauthorized activity, later confirmed to involve ransomware, on or around October 18, 2025. The company publicly acknowledged the incident on October 27, 2025, and subsequently notified affected plan members, including those covered under the Leggett & Platt, Incorporated Employee Benefits Plan.

What Information Was Breached?

MedImpact’s notification letter to affected individuals states that the information involved varied by person, but the letter does not publicly specify a single universal list of data elements affected for every plan member notified. MedImpact has stated it has no reason to believe the information has been or will be misused.

What You Can Do

If you received a letter about this breach, consider taking the following steps:

  • Monitor your email, phone, and mail for suspicious contact attempts referencing your personal or health plan details.
  • Be cautious of unsolicited messages asking you to click a link, download an attachment, or provide additional personal information.
  • Review your financial accounts, health plan statements, and credit reports for unfamiliar activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus if you are concerned about identity theft.
  • Keep a copy of your notification letter and any related correspondence in case you need it later.

File a Data Breach Lawsuit Against Leggett & Platt, Incorporated Employee Benefits Plan

If you received a data breach notification letter regarding this incident, or if you believe your personal information was exposed as a result of the MedImpact breach, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Unauthorized access occurred December 2-18, 2025; discovered December 18, 2025; confirmed May 26, 2026; notifications began June 26, 2026
Date of Breach: Unauthorized access occurred October 8-15, 2025; discovered October 13, 2025; investigation completed August 18, 2026
Date of Breach: Unauthorized access occurred April 24-May 7, 2026; discovered May 7, 2026; investigation completed August 17, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.