PDCM Insurance, an insurance agency headquartered in Waterloo, Iowa, that provides business insurance, personal insurance, and employee benefits services, has notified 4,734 individuals that their personal and health-related information may have been exposed after unauthorized access to its computer network.
Companies that handle sensitive personal and medical information as part of insurance and benefits administration have a responsibility to protect that data, and any failure to do so can leave affected individuals vulnerable to identity theft and financial fraud.
PDCM Insurance’s Data Breach Investigation
PDCM Insurance has stated that it became aware of suspicious activity involving certain computer systems on April 28, 2025. Upon learning of this activity, the company took steps to secure its network, notified law enforcement, and began an investigation to determine the nature and scope of what occurred. That investigation determined that unauthorized access to certain files and folders on PDCM’s network took place between April 27, 2025, and April 28, 2025. PDCM then conducted an extensive review of the involved systems to determine whether they contained protected personal information. According to a notice filed with the Iowa Attorney General, the incident affected approximately 4,734 individuals, and PDCM began mailing notification letters to affected individuals on or around August 3, 2026, more than a year after the initial unauthorized access occurred. PDCM has not publicly disclosed the specific technical method the unauthorized party used to gain access to its systems, nor has it identified a specific cause such as ransomware or a phishing-based intrusion.
The lengthy gap between the April 2025 unauthorized access and the August 2026 notification date is not unusual for incidents involving large volumes of mixed personal and health-related records. Reviewing files for this type of information is typically a much slower process than reviewing files containing only a single data category, because investigators must manually or semi-automatically confirm whose records were affected and which specific data elements, out of a wide range of possible categories, actually appear in each file. When treatment information, diagnosis codes, insurance subscriber numbers, and government identification numbers are all potentially present in the same data set, the review can stretch out considerably longer than a more straightforward breach involving, for example, only payment card numbers.
Insurance agencies and brokers are an increasingly attractive target for cybercriminals precisely because of the breadth of information they routinely collect and store on behalf of their clients. Unlike many other types of companies, an insurance agency’s files can combine core identifying information, such as Social Security numbers and driver’s license numbers, with detailed financial account information and, in the case of an agency handling health and employee benefits plans, an individual’s actual medical treatment history, diagnoses, prescription records, and insurance subscriber and policy numbers. This combination is unusually valuable to identity thieves and fraudsters, since it can support not only traditional financial fraud, such as opening new credit lines or filing fraudulent tax returns, but also medical identity theft, in which a criminal uses someone else’s identifying and insurance information to obtain fraudulent medical services or prescriptions in that person’s name.
Because PDCM has not disclosed the specific method of intrusion, affected individuals are left without clear information about how the breach happened or whether similar vulnerabilities might affect other companies they do business with. Regulatory notification requirements generally require companies to disclose what categories of information were exposed and how many people were affected, but they do not always require public disclosure of the underlying vulnerability or attack vector, which can leave consumers uncertain about their overall risk exposure even after receiving a formal notification letter.
When Did This Breach Occur?
According to PDCM Insurance, unauthorized access to its network systems occurred between April 27, 2025, and April 28, 2025. The company states it became aware of the activity on April 28, 2025, and subsequently conducted an investigation and data review before beginning to mail notification letters to affected individuals on or around August 3, 2026.
What Information Was Breached?
Based on PDCM’s notice and its filing with the Iowa Attorney General, the information present on the affected systems included names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers, state identification numbers, taxpayer identification numbers, financial account information, treatment information, diagnosis, treating or referring physician information, prescription or medication information, group health insurance and subscriber numbers, medical policy numbers, individual health insurance and subscriber numbers, and medical record numbers.
What You Can Do
If you received a notification letter from PDCM Insurance, consider taking the following steps to protect yourself:
- Enroll in any complimentary credit monitoring or identity protection services referenced in your notification letter.
- Review your financial account statements and insurance explanation-of-benefits statements for unauthorized activity or services you did not receive.
- Place a fraud alert or security freeze on your credit files with the three major credit bureaus.
- Watch for signs of medical identity theft, such as unfamiliar medical bills, insurance claims, or prescriptions in your name.
- Contact PDCM Insurance’s dedicated assistance line or your financial institution if you notice suspicious activity.
File a Data Breach Lawsuit Against PDCM Insurance
If your personal information was exposed as a result of this data security incident, you may be entitled to compensation. Companies that collect and store sensitive personal, financial, and medical information have a legal obligation to protect it, and failing to do so can leave affected individuals exposed to fraud and identity theft.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.