MedImpact PBM breach leaves employer plan members' health data exposed
The firm's 11-month notification gap raises vendor risk questions for employer plan sponsors
MedImpact PBM breach leaves employer plan members' health data exposed
GROUP BENEFITS
By Mark Rosanes
28 Sep 2026

A ransomware attack on MedImpact Healthcare Systems, one of the largest pharmacy benefit managers (PBMs) in the US, left an undisclosed number of health plan members waiting nearly a year to learn their personal and medical data may have been compromised. Notification letters began reaching affected individuals on September 25, more than 11 months after MedImpact first detected unauthorized activity on October 18, 2025.

MedImpact is a San Diego-based PBM that administers prescription drug benefits for health plans, self-insured employers, and government entities. It serves more than 20 million members in the US and over 50 million worldwide, according to ComplexDiscovery, a legal and cybersecurity research publication. The company finalized its investigation on July 17, notified affected clients on August 13, and began mailing individual notices in late September.

Data involved varied by individual but could include names, addresses, dates of birth, subscriber numbers, health insurance identification numbers, prescription information, and treatment details such as dates of service and provider names. Social Security numbers were compromised in limited instances. MedImpact is offering complimentary credit monitoring and identity theft protection to those whose Social Security numbers were potentially in scope.

Plan sponsors in the breach's path

MedImpact's clients include self-insured employers that contract directly with PBMs to manage their prescription drug programs. A breach at the PBM level is not one the employer caused, but member pharmacy benefit data flows through that vendor relationship. Affected employees are receiving breach notification letters that name their employer's health plan as the source of the incident.

The Qilin ransomware group, a Russia-linked criminal organization, claimed responsibility for the attack on October 27, 2025. The group alleged it had exfiltrated approximately 160 gigabytes of data, portions of which appeared to be from Elixir Solutions, a PBM that MedImpact had acquired from RiteAid. MedImpact has not publicly confirmed whether a ransom was paid or verified the full scope of Qilin's claims.

The notification timeline adds a separate dimension. Under the Health Insurance Portability and Accountability Act (HIPAA), covered entities and business associates are required to notify affected individuals within 60 days of discovering a breach. MedImpact finalized its investigation nine months after detecting the incident.

Healthcare vendor attacks widen

The MedImpact breach follows a pattern of ransomware attacks on healthcare intermediaries. The 2024 attack on Change Healthcare, a claims processing company owned by UnitedHealth Group, compromised approximately 192.7 million records and involved a reported $22 million ransom payment, according to Comparitech, a cybersecurity research firm.

Self-insured employers carry the direct contractual relationship with vendors like PBMs. When those vendors are breached, the plan sponsor's fiduciary duty to monitor benefits service providers under the Employee Retirement Income Security Act (ERISA) comes into view. The MedImpact breach is not an ERISA case, but the frequency of healthcare vendor compromises is sharpening scrutiny of what plan sponsors are expected to know about their vendors' data practices.

Vendor data security is not a new risk category for employer plans, but recent incidents are moving it from background concern to active due diligence question. Self-funded employer plans already face cost exposure from benefit administration gaps that go undetected by third-party administrators, and the MedImpact breach adds another layer to the vendor monitoring conversation plan sponsors and their advisers are having.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB US.