MedImpact Healthcare Systems, a San Diego pharmacy benefit manager (PBM), is mailing breach notices about 11 months after it found an intruder in its network on October 18, 2025. The Qilin ransomware group claimed the attack and listed MedImpact on its dark web leak site in October 2025 (HIPAA Journal). The stolen data includes names, Social Security numbers, health insurance details and prescription and treatment information. MedImpact has not said how many people were affected. One lawyer-linked site, Corp & Tech, says records for "millions" of plan members were taken, but nothing on the record confirms that figure. Emery Reddy says MedImpact serves more than 50 million members worldwide. That is its total customer base, not the number of people in the breach.
What Happened
MedImpact found unauthorized activity in its systems on October 18, 2025. It says it secured the systems and brought in outside cybersecurity experts. Emery Reddy says the company issued a public statement on October 27, 2025, reporting that it had found ransomware on certain systems. The same day, Qilin claimed the attack. Edelson Lechtzin's release dates the leak-site posting to October 27, and HIPAA Journal places it in October 2025.
The sources broadly agree on the timeline after that:
- July 17, 2026: investigation finalized (HIPAA Journal, Edelson Lechtzin, ClassAction.org)
- August 13, 2026: affected client health plans notified
- September 23, 2026: MedImpact begins mailing letters to individuals on behalf of its clients
Accounts differ on when some members were first notified. Emery Reddy cites California Attorney General filing sb24-629789 and says the Leggett & Platt, Inc. Employee Benefits Plan reported the breach on September 15, 2026, 332 days after discovery. That is earlier than the September 23 mailing date in other reports. MedSecLedger lists the disclosure date as October 18, 2025 "per notification record," which looks like the discovery date entered in the wrong field. Because MedImpact mails notices under each client plan's name, members may see a letter from their employer's plan rather than from MedImpact. Edelson Lechtzin says members of plans run by MedImpact and/or Elixir Solutions were affected, including minor dependents.
What Was Taken
HIPAA Journal lists the exposed data as names plus some or all of the following, depending on the person:
- address and date of birth
- subscriber number
- Social Security number
- health insurance information
- prescription and treatment information, dates of service, service locations and provider names
Volume: Emery Reddy, citing Cybernews, says Qilin claimed about 160 GB of data. Researchers who reviewed Qilin's published sample said it was mostly financial and operational records, such as commission and claims remittance reports and a bank account summary, with little patient-level clinical data. The notification letters now show that member PHI and SSNs were affected, so the sample did not show everything that was taken.
Notice quality: Emery Reddy and MedSecLedger both say at least some Leggett & Platt letters went out with an unfilled mail-merge placeholder ("b2b_text_1 (first and last name and data elements)") where the list of exposed data should have been. MedSecLedger names Kroll as the notification vendor. The sources also disagree on credit monitoring. HIPAA Journal says people whose SSNs were exposed were offered free credit monitoring and identity protection. Emery Reddy says the Leggett & Platt letter it reviewed did not appear to include that offer. HIPAA Journal also reports that no misuse of the data had been found when the letters went out.
Why It Matters
- The breach comes through a vendor. PBMs process claims for many health plans and employers at once (Emery Reddy says MedImpact handles more than a million claims a day), so one intrusion reaches members of dozens of plans that were never breached themselves. Plan sponsors are sending notices for an incident outside their own networks.
- The data lasts. SSNs combined with prescription histories and insurance identifiers can be used for medical identity theft and insurance fraud, and for convincing phishing that references real medications and providers. Unlike a password, none of this can be changed.
- The notices are slow. Individual letters went out about 11 months after discovery. medcomply.ai says the delay "raises serious HIPAA breach notification rule compliance questions." HHS OCR has announced no enforcement action. At least two law firms, Edelson Lechtzin and Emery Reddy, are investigating possible class claims.
- Qilin keeps hitting healthcare. This fits Qilin's steady targeting of the sector, where both downtime and data exposure put heavy pressure on victims to pay.
The Attack Technique
MedImpact has not disclosed how the attackers got in, and MedSecLedger records the vector as "not disclosed." The known facts are that data was stolen and ransomware was deployed, which matches Qilin's usual double-extortion model: steal data, encrypt systems, then threaten to publish. Other Qilin intrusions have often started through remote access services and VPN appliances without MFA, stolen credentials, and exploited edge devices. There is no evidence that any of these were used against MedImpact, so treat them as likely possibilities, not findings.
What Organizations Should Do
- List every business associate that holds member SSNs and PHI, with PBMs at the top. Require contract terms on breach notice timing and on who drafts, proofs and mails individual letters.
- Check your vendors' identity controls. Ask for evidence of phishing-resistant MFA on all remote access, VPN and admin paths, plus tested, offline backups.
- Proof notification letters before they go out. Review a sample of rendered letters before mass mailing so members don't receive unresolved template fields or missing credit monitoring offers.
- Cut down the data you share. Send vendors only the SSNs and clinical fields they actually need, and replace SSNs with member IDs where possible.
- Warn your members about targeted phishing. Tell them attackers may mention real prescriptions or providers, and point them to credit freezes and to the explanation-of-benefits statements they should be checking.
- Watch for exfiltration. Alert on large outbound transfers from claims and reporting systems. Qilin's reported 160 GB haul would have had to leave the network before encryption.
Sources: MedImpact Breach Investigation Targets Potential Security Failures... | Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visi... | MedImpact Healthcare Systems Data Breach Lawsuit Emery Reddy | MEDIMPACT DATA BREACH: Edelson Lechtzin LLP Launches Investigation... | MedImpact Healthcare Systems Data Breach Exposes Health Info, SSNs | Leggett & Platt Benefits Plan Data Breach Lawsuit Emery Reddy | Leggett & Platt, Incorporated Employee Benefits Plan Data Breach An... | Pharmacy Benefit Manager MedImpact Healthcare Systems Begins Notify...