Skip to main content
Jump to a category page

Members of the Leggett & Platt, Incorporated Employee Benefits Plan are receiving breach notices — but the breach didn’t happen at Leggett & Platt. It happened at MedImpact Healthcare Systems, the plan’s pharmacy benefits manager, and it took 332 days to reach plan members.

Leggett & Platt, Incorporated Employee Benefits Plan reported a data breach to the California Attorney General on September 15, 2026. But the incident behind the notice originated with MedImpact Healthcare Systems, Inc., the pharmacy benefits manager that administers prescription claims for the plan. MedImpact identified unauthorized activity within its systems on October 18, 2025. The notice reaching Leggett & Platt plan members didn’t go out until nearly eleven months later, on September 15, 2026 — a 332-day gap between MedImpact’s discovery and the letter in members’ mailboxes.

Source: California Attorney General breach notification, report sb24-629789, reported 09/15/2026; MedImpact Healthcare Systems consumer notification letters sent on behalf of the Leggett & Platt Employee Benefits Plan.

A Notice Letter With a Blank Where the Data Types Should Be

The notice letter sent to affected plan members has a defect worth flagging: in the section that should list exactly what personal information was exposed, the letter instead shows unresolved mail-merge text — a placeholder field that was never filled in before the letters went out. In practice, that means many recipients got a letter confirming their name was involved but leaving the rest of the picture blank. The letter reviewed also does not appear to offer credit monitoring, unlike many breach notices that include that offer as a matter of course.

You’re Not the Only Plan Getting This Letter

MedImpact is a large, San Diego-based pharmacy benefits manager that serves prescription claims for many different employer health plans, not just the Leggett & Platt Employee Benefits Plan. That means this notice is very likely one of many being sent out on similar timelines to members of other health plans across the country, all carrying different employer or plan-sponsor names on the letterhead while the actual incident sits with the shared vendor, MedImpact. If your coverage runs through a different employer but your pharmacy benefits are also administered by MedImpact, you may be part of this same event even if the letter you received doesn’t mention Leggett & Platt at all.

Why the Delay Matters

MedImpact’s own account states it “promptly took steps to secure the affected systems” after discovering the intrusion on October 18, 2025 — so this isn’t a case where detection was slow. What isn’t explained is the gap between that October 2025 discovery and the September 2026 notice to plan members. MedImpact has described conducting “a detailed review” of the affected data, but hasn’t stated when that review concluded, leaving an eleven-month gap without a clear accounting.

Do You Have Legal Options?

Employee benefit plans and the vendors they hire to administer pharmacy claims have a legal duty to secure sensitive plan-member information and to notify affected individuals without unreasonable delay.

If you received a notice letter naming the Leggett & Platt Employee Benefits Plan, contact Emery | Reddy today for a Free Case Review.

FAQ

Who is affected by this breach?

Members of the Leggett & Platt, Incorporated Employee Benefits Plan whose pharmacy benefits are administered by MedImpact Healthcare Systems. No total number of affected plan members has been disclosed.

What information was exposed?

The notice letter confirms names were involved, but the section meant to list additional exposed data categories was left as an unfilled template placeholder in the copies reviewed, so the full scope of what else was exposed for any individual member isn’t clear from the letter itself.

Why did it take 332 days to notify plan members?

MedImpact discovered the intrusion on October 18, 2025, and has said it acted promptly to secure its systems. Notice to Leggett & Platt plan members didn’t go out until September 15, 2026. MedImpact hasn’t disclosed when its data review concluded, which leaves the reason for most of that gap unexplained.

I’m not a Leggett & Platt employee, but my pharmacy benefits also go through MedImpact. Could I be affected?

Possibly. MedImpact serves many different employer health plans, and this incident is very likely generating similar notices to members of other plans on comparable timelines. If your plan uses MedImpact for pharmacy benefits, contact us even if your notice letter doesn’t mention Leggett & Platt by name.

Do I have a legal claim?

Employee benefit plans and the vendors they hire to administer pharmacy claims have a legal duty to secure sensitive plan-member information and to notify affected individuals without unreasonable delay. If you received a notice letter naming the Leggett & Platt Employee Benefits Plan, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now