Insurance
Home›Insurance›Liability Insurance›MedImpact PBM ransomware attack delays health data bre…
MedImpact PBM ransomware attack delays health data breach notifications
Notification letters started reaching affected people on September 25, more than 11 months after the company detected the unauthorized activity on October 18, 2025.
A ransomware attack at MedImpact Healthcare Systems, a US pharmacy benefit manager, left some health plan members waiting nearly a year to learn that their personal and medical data may have been compromised, according to Insurance Business.
The outlet reports that MedImpact first detected unauthorized activity on October 18, 2025, while notification letters began reaching affected individuals on September 25, 2026. MedImpact finalized its investigation on July 17 and notified affected clients on August 13, before beginning to mail individual notices in late September.
Insurance Business also said MedImpact is a San Diego-based PBM that administers prescription drug benefits for health plans, self-insured employers, and government entities, serving more than 20 million members in the US and over 50 million worldwide. The company said the affected data could vary by individual and may include names, addresses, dates of birth, subscriber numbers, health insurance identification numbers, prescription information, and treatment details, with Social Security numbers compromised in limited instances.