Skip to main content
Jump to a category page

MedImpact Healthcare Systems, a pharmacy benefits manager serving more than 50 million members worldwide, discovered ransomware on its systems in October 2025. Nearly a year later, the notices are still going out — under other companies’ names.

MedImpact Healthcare Systems, Inc., a San Diego-based pharmacy benefits manager that administers prescription drug claims for health plans, employers, and government programs, disclosed on October 27, 2025 that it had identified ransomware on certain systems. In its own public statement, MedImpact said it “immediately” began containment and mitigation measures, launched an investigation with outside cybersecurity experts, and began notifying “all applicable authorities.” The ransomware group Qilin claimed responsibility on its dark web leak site around the same time, alleging it had exfiltrated approximately 160 gigabytes of data.

Source: MedImpact Healthcare Systems’ own public statement, issued October 27, 2025 (medimpact.com); Cybernews reporting on the Qilin ransomware group’s leak-site claim.

What the Attackers Actually Posted

According to cybersecurity researchers who reviewed the sample data Qilin posted, the leaked material largely consisted of financial and operational records — commission and claims remittance reports shared between MedImpact and its partner companies, along with a bank account summary. That sample didn’t include detailed patient-level clinical information. But MedImpact processes more than a million healthcare claims a day, and the sample Qilin chose to publish doesn’t necessarily reflect everything the attackers actually obtained — or what MedImpact has since confirmed was exposed for specific health plan members.

Source: Cybernews reporting and analysis of the Qilin leak-site sample.

Individual Notices Are Going Out — On Other Companies’ Letterhead

Nearly a year after MedImpact discovered the intrusion, individual health plan members are starting to receive breach notices. One example: MedImpact’s own consumer notification letters have gone out on behalf of the Leggett & Platt, Incorporated Employee Benefits Plan, which reported the incident to the California Attorney General on September 15, 2026 — 332 days after MedImpact’s own discovery date. Because MedImpact serves as the pharmacy benefits manager for many different employer health plans, this is very likely just one of many similar notices going out to members of other plans nationwide, each carrying a different employer or plan name instead of MedImpact’s.

Source: California Attorney General breach notification, report sb24-629789, reported 09/15/2026 (filed in the name of the Leggett & Platt, Incorporated Employee Benefits Plan); MedSecLedger analysis of the MedImpact-originated notification pattern.

MedImpact Itself Has No Breach Filing of Its Own

Here’s what’s unusual: as the company at the actual center of this incident, MedImpact does not appear on California’s or Washington’s public breach notification databases under its own name. The notices reaching the public are being filed by MedImpact’s downstream client health plans — like the Leggett & Platt Employee Benefits Plan — rather than by MedImpact directly. That makes it hard for any single regulator, or any affected individual, to see the full scope of this incident from public records alone. If you received a letter that mentions MedImpact, regardless of what employer or health plan name appears on the letterhead, you’re likely part of this same event.

Do You Have Legal Options?

Pharmacy benefits managers that process claims data for tens of millions of members have a legal duty to secure that information and to notify affected individuals without unreasonable delay.

If you received a notice letter mentioning MedImpact Healthcare Systems — on any employer’s or health plan’s letterhead — contact Emery | Reddy today for a Free Case Review.

FAQ

What happened at MedImpact?

MedImpact identified ransomware on certain systems and disclosed the incident on October 27, 2025. The Qilin ransomware group claimed responsibility and alleged it stole approximately 160 gigabytes of data.

How many people are affected?

MedImpact has not disclosed a total number of affected individuals. Given that MedImpact serves more than 50 million members worldwide across many different client health plans, the true scope could be substantial, but no public figure exists.

I got a breach letter, but it doesn’t mention MedImpact by name — could this still be it?

Possibly. MedImpact serves as the pharmacy benefits manager behind many employer and health plan names. If your letter mentions a pharmacy benefits incident, a review that took many months, or references MedImpact anywhere in the fine print, it may be connected to this same event.

What information was exposed?

The sample of data posted publicly by the Qilin ransomware group consisted mainly of financial and operational records, not detailed patient information. However, the specific data exposed for individual plan members, as described in notification letters sent on MedImpact’s behalf, is not fully itemized in the copies reviewed for this post.

Do I have a legal claim?

Pharmacy benefits managers that process claims data for tens of millions of members have a legal duty to secure that information and to notify affected individuals without unreasonable delay. If you received a notice letter mentioning MedImpact Healthcare Systems, on any employer’s or health plan’s letterhead, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now