MedImpact Data Breach: Social Security Numbers and Health Information Exposed
Pharmacy benefit manager MedImpact Healthcare Systems has disclosed a significant data breach that may have exposed Social Security numbers and health information for millions of customers. A law firm has launched an investigation.

MedImpact Healthcare Systems, one of the largest independent pharmacy benefit managers in the United States, has disclosed a data breach that potentially exposed personal and health information stored within its systems. The company identified unauthorized activity on October 18, 2025, and a subsequent investigation concluded on July 17, 2026, confirmed the extent of the breach.
The incident is believed to have affected both current and former members of pharmacy benefit plans administered by MedImpact and/or Elixir Solutions. While the exact number of individuals impacted has not been publicly disclosed, the compromised data may include names, addresses, dates of birth, Social Security numbers, and health-related information such as prescriptions and treatment details.
MedImpact began notifying affected parties in August 2026. The exposure of sensitive data, including Social Security numbers and protected health information, poses a risk of identity theft, medical fraud, and targeted phishing attacks. The ransomware group Qilin has claimed responsibility for the breach.
Law firm Edelson Lechtzin LLP has launched an investigation into the data breach and is offering free case evaluations to affected individuals. The firm is examining whether MedImpact implemented reasonable cybersecurity safeguards and whether additional measures could have prevented or mitigated the breach's impact.