RELEReleases

MedImpact Breach Investigation Targets Potential Security Failures

The Qilin ransomware group held MedImpact Healthcare Systems’ data hostage for months, forcing a public reckoning over the exposure of Social Security numbers and private health records. As notices reach impacted members nationwide, the law firm Edelson Lechtzin LLP is now scrutinizing whether the pharmacy benefit manager failed to maintain adequate digital defenses.

Bio & NewsSeptember 27, 2026356 reads0

Unauthorized actors infiltrated MedImpact systems on October 18, 2025, eventually claiming the theft of records belonging to millions of pharmacy benefit plan members. While the company finalized its internal investigation in July 2026, it waited until late September to begin mailing formal notices to those potentially compromised. The breach impacted participants in various plans, including the Leggett & Platt, Inc. Employee Benefits Plan.

Stolen data includes a high-risk combination of names, addresses, dates of birth, and health-related details such as prescription histories and treatment locations. Because Social Security numbers were among the records exfiltrated, victims face long-term risks of medical and insurance fraud. Edelson Lechtzin LLP is currently evaluating whether the firm’s security safeguards were sufficient to prevent this exposure. The firm advises affected individuals to freeze their credit reports and remain vigilant against targeted phishing attempts while legal assessments proceed.

Comments (0)

Leave a comment

No comments yet. Be the first!