MedImpact Disclosed Data Breach After Ransomware Attack
The pharmacy benefit manager has begun notifying members of a 2025 data exfiltration event.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust third-party companies to properly secure your personal health information?
MedImpact Healthcare Systems has confirmed that sensitive member information was compromised during a cyberattack detected in October 2025. The breach resulted in the alleged exfiltration of 160 gigabytes of data by the Qilin ransomware group.
Why it matters
The incident highlights ongoing security risks for pharmacy benefit managers that aggregate personal health information for millions of Americans. It follows an investigation that concluded months after the initial unauthorized activity was detected.
The breach exposed names, addresses, dates of birth, insurance numbers, and prescription details for a portion of the 20 million US members MedImpact serves. The notification process began 11 months after the October 2025 detection, exceeding the standard 60-day HIPAA requirement for breach notification.
The players
MedImpact Healthcare Systems
A pharmacy benefit manager that handles claims and prescription data for 20 million US members.
Qilin
A ransomware group that targets enterprise networks to exfiltrate and encrypt sensitive internal data.
The details
The Qilin ransomware group, a cybercriminal collective linked to infrastructure in Russia, allegedly gained access to the system and removed 160 gigabytes of corporate and member data. MedImpact, based in San Diego, manages pharmacy benefits through a complex stack that integrates health plans, employers, and government entities. The company has since initiated an investigation to secure its network and is providing identity theft protection services to those affected.
Timeline
October 18, 2025: MedImpact detected unauthorized system activity.
October 27, 2025: Qilin ransomware group claimed responsibility for the attack.
July 17, 2026: MedImpact finalized its internal investigation.
August 13, 2026: The company notified clients of the breach.
September 25, 2026: Notification letters were sent to affected individuals.
The Tech Race
This breach highlights the persistent vulnerability of large-scale pharmacy benefit managers to ransomware groups like Qilin. It marks a departure from the 60-day breach notification requirement mandated by the Health Insurance Portability and Accountability Act.
Individuals who receive notification letters are eligible for complimentary credit monitoring and identity theft protection provided by MedImpact. Readers should watch for suspicious communication regarding insurance or prescription information as a result of this data exposure.
The takeaway
The delayed disclosure underscores the challenge of incident response in complex healthcare data environments. Affected members should verify their identity theft protection status through the materials provided by the company.
Further reading
For broader trends in enterprise defense, visit Cybersecurity.
Source note: This article includes information reported by Insurance Business.
Live Poll
Do you trust third-party companies to properly secure your personal health information?









