Were you recently affected by a data breach?

Risk Program Administrators Data Breach

Risk Program Administrators (RPA) discovered that an unauthorized person accessed an employee email account between late May and mid-June 2025, potentially exposing the names, Social Security numbers, financial details, and medical information of thousands of individuals whose data RPA handled as a third-party claims administrator.

Risk Program Administrators
Date of Breach: May 27, 2025 - June 16, 2025
CAU logo

Who was affected:

Clients of Risk Program Administrators

Impacted Data:

Full name, home address, Social Security number, driver’s license number, date of birth, financial account information, and medical and health insurance information, including treatment type, treatment location, treatment cost, physician information, and health plan subscriber number

Risk Program Administrators, a California-based third-party administrator that handles claims processing and risk management services for insurance carriers, employers, and self-insured groups, has confirmed that a security incident may have exposed the personal and medical information of thousands of individuals. Companies that manage sensitive claims data on behalf of others take on a heightened responsibility to keep that information secure, and any lapse in that duty can leave affected people vulnerable to fraud and identity theft.

Risk Program Administrators’s Data Breach Investigation

According to a notice posted by the company, Risk Program Administrators became aware of suspicious activity involving an employee email account and moved quickly to secure it. The company then retained outside cybersecurity specialists to investigate the scope of the incident. That investigation determined that an unauthorized individual was able to access certain emails over a roughly three-week window in the late spring of 2025.

Following the initial containment, Risk Program Administrators conducted what it described as a comprehensive review of the material that may have been accessed during that period. The company has stated that it is not currently aware of any confirmed instances of the information being misused, but it nonetheless determined that files containing sensitive personal and medical details connected to certain individuals could have been exposed. Risk Program Administrators reported the incident to the U.S. Department of Health and Human Services’ Office for Civil Rights, listing more than 8,300 individuals as affected, and also filed notice with the Nebraska Attorney General’s office in July 2026.

Third-party administrators like Risk Program Administrators occupy a uniquely sensitive position in the insurance and healthcare ecosystem. Because they process claims on behalf of multiple insurers, employers, and self-insured entities, a single company can end up holding detailed records that combine identity information, financial account data, and protected health information for a large number of people who may never have directly interacted with the administrator themselves. This concentration of data makes third-party administrators an attractive target for cybercriminals, since compromising one email account or system can potentially expose records tied to many different underlying policyholders and claimants at once.

Email-based intrusions of this kind are also particularly difficult to fully contain once they occur. Business email accounts frequently accumulate years of attachments, spreadsheets, and correspondence containing exactly the kind of information described here, including claims files, medical records, and account numbers, often without the same level of encryption or access control applied to a company’s core databases. When an unauthorized party gains access to an inbox for an extended period, as appears to have happened here, a forensic review is required to determine precisely which messages and attachments were actually viewed or copied, which is why notification can take weeks or months after the underlying intrusion is first discovered.

For individuals affected by this incident, the mix of data types involved is significant. The combination of Social Security numbers, driver’s license numbers, and dates of birth is often enough on its own to open new lines of credit or file fraudulent tax returns in someone else’s name, while the addition of financial account information and detailed medical and insurance records increases the risk of targeted phishing attempts that reference real claims, treatment dates, or policy details to appear more convincing. Because Risk Program Administrators primarily handles data on behalf of other organizations, affected individuals may not immediately recognize the company’s name, which can make it harder for people to connect a suspicious notice or unfamiliar activity back to this specific incident.

When Did This Breach Occur?

Risk Program Administrators has stated that the unauthorized access to the employee email account occurred between approximately May 27, 2025 and June 16, 2025. The company discovered the suspicious activity sometime after that window and worked with external cybersecurity specialists to investigate before determining, through a subsequent review, which individuals’ information may have been involved. The breach was formally reported to federal regulators on July 23, 2026, and filed with the Nebraska Attorney General around the same date, reflecting the substantial review period often required to identify exactly whose data was affected in an email-based incident.

What Information Was Breached?

The specific information involved varies by individual, but according to the company’s own notice, it may include full name, home address, Social Security number, driver’s license number, date of birth, and financial account information. For many affected individuals, the exposure also includes medical and health insurance information, such as treatment type, treatment location, treatment cost, physician information, mental or physical condition details, health plan subscriber or member numbers, and admission dates. Not every category applies to every affected person, since the exposed files reportedly varied depending on the specific claims and records involved.

What You Can Do

If you received a notice from Risk Program Administrators, there are several steps you can take to protect yourself:

  • Read the notice carefully and keep the original letter, since it may serve as evidence if you later need to pursue a claim.
  • Place a fraud alert or credit freeze with all three major credit bureaus (Equifax, Experian, and TransUnion), which is free and helps prevent new accounts from being opened in your name.
  • Enroll in any credit monitoring or identity protection services offered in the notice.
  • Review your bank and credit card statements, as well as any insurance explanation-of-benefits statements, for unfamiliar activity.
  • Be cautious of follow-up phishing emails, texts, or calls that reference this breach, your medical claims, or your insurance coverage, since scammers frequently use real breach details to make fraudulent contact appear legitimate.
  • Consider speaking with an attorney about your legal options if your information was exposed.

File a Data Breach Lawsuit Against Risk Program Administrators

If your personal or medical information was exposed in the Risk Program Administrators data breach, you may be entitled to compensation, even if you have not yet experienced direct financial harm. Companies that are entrusted with sensitive personal and medical data have a legal responsibility to protect it, and a breach of this scope raises real questions about whether adequate safeguards were in place.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported August 14, 2026 (incident allegedly occurred on or about August 13, 2026)
Date of Breach: Reported June 26, 2026
Date of Breach: May 27, 2025 - June 16, 2025
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.