
Leggett & Platt Inc., a manufacturer in the furniture industry, recently disclosed an October 2025 data breach at MedImpact Healthcare Systems Inc. that potentially impacted members of their employee benefits plan.
On Oct. 18, 2025, MedImpact, a pharmacy benefits manager, identified unauthorized activity within certain systems in its environment. Upon discovering the unauthorized activity, MedImpact took steps to secure the affected systems to prevent further unauthorized access.
MedImpact then engaged outside cybersecurity experts to assist with the investigation and response to the incident. MedImpact then conducted a detailed review of all data that was potentially impacted.
The review determined that certain data related to members of the Leggett & Platt Employee Benefits Plan was included in the set of potentially affected information. Because MedImpact manages pharmacy benefits for the plan, it maintains certain personal information about plan members and their covered dependents in order to process and administer their prescription drug benefits.
Both adult plan members and minor dependents were among those whose data was involved in the incident. MedImpact sent separate notification letters to affected adults and to the parents or guardians of affected minor children.
The types of personal information exposed varied from person to person but may have included first and last names and other personal information.
The breach was reported to the California Attorney General on Sept. 15, 2026.
MedImpact set up a dedicated phone line for individuals with questions about the incident. The number is 844-958-8925, available Monday through Friday from 8 a.m. to 5:30 p.m. Central Time.
MedImpact additionally encouraged affected individuals to use precautions with regard to all of their information.
The company notification to impacted individuals included contact information for the three major credit reporting agencies: Equifax, Experian and TransUnion. It explained how to obtain free annual credit reports, place initial or extended fraud alerts and request security freezes.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)