Were you recently affected by a data breach?

WellDyne Data Breach

WellDyne, a pharmacy benefit management company, disclosed a data breach after a ransomware group claimed to have stolen internal files from its systems. The company reported the incident affected clients, including at least 500 Florida residents.

WellDyne
Date of Breach: Detected June 2026
CAU logo

Who was affected:

Clients of WellDyne

Impacted Data:

The company has not published a specific list of affected data categories for this incident, though pharmacy benefit records like those WellDyne manages typically include names, contact information, insurance details, and prescription history

WellDyne, a Florida-based pharmacy benefit management company that helps health plans, employers, and government programs manage prescription drug costs, has disclosed a data breach after a ransomware group claimed to have stolen data from its systems.

Companies that manage prescription benefits and health plan data are entrusted with some of the most sensitive personal and medical information a person has, and they carry a responsibility to keep that information secure from unauthorized access.

WellDyne’s Data Breach Investigation

According to public reporting, a ransomware group calling itself “payoutsking” added WellDyne to its dark-web leak site in mid-June 2026, claiming to have exfiltrated internal files during a ransomware attack. WellDyne subsequently notified the U.S. Department of Health and Human Services Office for Civil Rights of a hacking/IT incident involving a network server, reporting that the breach affected at least 500 Florida residents. Under Florida law, companies must report breaches affecting 500 or more state residents to the Florida Attorney General within 30 days of notifying individuals, which suggests the total number of people affected nationwide, across all the health plans and employers WellDyne serves, could be considerably higher than the Florida-specific figure reported.

Pharmacy benefit managers like WellDyne sit at the center of the healthcare data ecosystem, processing prescription claims, insurance eligibility information, and personal health details for millions of patients across the country. This central role makes them an attractive target for cybercriminals, since a single successful intrusion can expose records tied to numerous health plans and employer groups at once, rather than just one organization’s customer base.

Ransomware groups that steal data before encrypting systems, sometimes called double extortion attacks, increasingly use the threat of publishing stolen files as leverage to pressure victim companies into paying a ransom. Whether or not WellDyne paid, the underlying concern for affected individuals remains the same: personal and health-related information may have already been copied by unauthorized parties before any negotiation took place.

Notification timelines for incidents like this can stretch for months, as forensic investigators work to determine exactly whose data was involved and what specific categories of information were exposed. Individuals connected to WellDyne through a health plan, employer, or government program should watch for an official notification letter describing the specific information involved in their case.

When Did This Breach Occur?

Public reporting indicates the ransomware group first claimed responsibility for the attack around June 15, 2026, with the listing becoming more widely reported by early July 2026. WellDyne’s notification to the HHS Office for Civil Rights, which tracks healthcare data breaches affecting 500 or more individuals, was submitted on August 25, 2026. The exact date WellDyne’s systems were first compromised has not been publicly disclosed.

What Information Was Breached?

WellDyne has not publicly released a detailed list of the specific data elements involved in this incident. Given the nature of WellDyne’s business as a pharmacy benefit manager, the information it typically holds includes patient names, contact information, insurance and health plan details, and prescription records, though the company has not confirmed which of these categories, if any, were part of the files taken in this specific incident.

What You Can Do

If you receive a notification letter from WellDyne or a health plan that uses WellDyne’s services, read it carefully to understand exactly what information was involved in your case. Consider these steps:

  • Enroll in any free credit monitoring or identity protection services offered in the notification letter
  • Review your health insurance statements (Explanation of Benefits) for services you do not recognize
  • Place a fraud alert or credit freeze with the major credit bureaus if Social Security numbers may have been involved
  • Watch for phishing emails or calls referencing your prescription or insurance information
  • Keep any notification letter and related correspondence in case you need it later

File a Data Breach Lawsuit Against WellDyne

If your personal information was exposed as a result of this breach, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General's Office on September 23, 2026
Date of Breach: Capital Family Physicians reported the breach to the U.S. Department of Health and Human Services Office for Civil Rights, affecting 2,545 individuals in North Carolina. A ransomware group calling itself cmdorganization separately claimed responsibility, listing the practice on its leak site on or around May 29, 2026.
Date of Breach: AngMar discovered unusual activity on its network on July 20, 2026, and completed its review of affected data on September 10, 2026. Notification letters were mailed to affected individuals beginning September 22, 2026.
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.