MedImpact Data Breach Victims Have Been Notified

Pharmacy benefit manager MedImpact disclosed that personal member information was compromised in a ransomware attack.

Updated on Sept. 28, 2026 in Cybersecurity

Isometric editorial illustration of a secure server room with rows of racks, representing large-scale data storage infrastructure.
MedImpact Healthcare Systems has begun notifying patients following a ransomware attack by the Qilin group that exposed names and insurance records. AI Illustration. Upload story photo >

Live Poll

Do you trust third-party companies to properly secure your personal health information?

MedImpact Healthcare Systems has begun sending notification letters to individuals affected by a significant data breach. The incident, for which the Qilin ransomware group claimed responsibility, exposed sensitive personal and health-related records.

Why it matters

The breach highlights the persistent vulnerability of major healthcare service providers to cyber extortion. Protecting the vast amounts of medical and insurance data stored by these firms remains a critical priority for national digital security.

The breach involved the alleged exfiltration of 160 gigabytes of data by the Qilin ransomware group. MedImpact manages pharmacy benefits for over 20 million members across the United States.

The players

MedImpact Healthcare Systems

This San Diego-based company provides pharmacy benefit management services for health plans, government entities, and self-insured employers.

Qilin

This is a ransomware group that has claimed responsibility for various cyberattacks involving the exfiltration of sensitive organizational data.

The details

Unauthorized access to company systems allowed the Qilin group to compromise names, dates of birth, prescription details, and insurance numbers. While Social Security numbers were breached in limited instances, MedImpact is offering complimentary credit monitoring and identity theft protection to those affected.

Timeline

  1. October 18, 2025: MedImpact detected unauthorized system activity.

  2. October 27, 2025: The Qilin ransomware group claimed responsibility for the cyberattack.

  3. July 17, 2026: MedImpact finalized its internal investigation into the incident.

  4. August 13, 2026: MedImpact notified its clients of the security breach.

  5. September 25, 2026: Notification letters were sent to affected individuals.

The Tech Race

The incident highlights the growing challenge of data security within the healthcare sector as organizations struggle to meet the mandates of the HIPAA Breach Notification Rule. Rapid advancements in ransomware tactics continue to outpace existing defensive infrastructure.

Affected members should watch for the official notification letter to determine if their sensitive information was compromised. Individuals are encouraged to utilize the provided complimentary credit monitoring services to protect against identity theft.

The takeaway

Maintaining vigilance regarding personal data is essential following major corporate security incidents. Consumers should proactively monitor their medical and financial statements for any evidence of unauthorized activity.

Further reading

For more information on trends in digital defense, visit the Cybersecurity section.

Source note: This article includes information reported by Insurance Business.

Live Poll

Do you trust third-party companies to properly secure your personal health information?