MedImpact Healthcare Systems Data Breach Reported in 2026
MedImpact Healthcare Systems, Inc. disclosed an unspecified data breach that occurred in October 2025, reported in September 2026. This incident exposed sensitive personal information, including Full Name, Date of Birth, Social Security Number, and various health-related data, raising significant concerns for affected individuals.
- State
- California
- Breach date
- October 18, 2025
- Reported
- September 25, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Health Insurance ID Number
- Prescription Information
- Medical Claims History
- Provider and Treatment Dates
- Home Address
MedImpact Healthcare Systems, Inc. reported a data breach to regulators in California on September 25, 2026. The incident, which occurred on October 18, 2025, involved an unspecified breach type. MedImpact, a prominent Pharmacy Benefit Manager, processes and stores extensive volumes of confidential healthcare and personal identifying information.
The disclosed information includes Full Name, Date of Birth, Social Security Number, Health Insurance ID Number, Prescription Information, Medical Claims History, Provider and Treatment Dates, and Home Address. This array of personal and health data is significant due to its sensitive nature and potential for misuse.
The exposure of this type of personal and health data can carry substantial risks. Unlike easily replaceable financial credentials, sensitive information like health records and Social Security Numbers cannot be changed. This could lead to concerns such as medical identity theft, where unauthorized parties might attempt to obtain treatment or services using another individual's identity, or targeted fraudulent schemes.
Individuals who receive a breach notification from MedImpact Healthcare Systems, Inc. should carefully review its contents for specific details. It is generally recommended to remain vigilant for any suspicious activity across personal accounts and to consider placing a fraud alert or credit freeze with credit reporting agencies. Regularly monitoring explanation of benefits (EOB) statements from insurers can also help detect unauthorized medical services.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- ZZ Diag Probe
- San Bernardino County on behalf of Arrowhead Regional Medical Center
- Upbound Group, Inc.
- Kings United Way
- Financial Administrative Support Services
- 5Star Life Insurance Company
- Peña and Bromberg
- NSE Insurance Agencies
- HILT-Trust 2020-A and its underlying trusts and affiliates ("HILT")
- Fairwinds Credit Union
- Modoc Medical Center
- Ethan Conrad Properties
- Friesen Group
- Ridgeway Pharmacy Ltd