Leggett & Platt Data Breach Impacts Adults and Minor Dependents: Personal Information Exposed

Published
September 21, 2026
Updated
September 21, 2026
Leggett & Platt Data Breach Impacts Adults and Minor Dependents: Personal Information Exposed
Leggett & Platt
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Leggett & Platt Inc., a manufacturer in the furniture industry, recently disclosed an October 2025 data breach at MedImpact Healthcare Systems Inc. that potentially impacted members of their employee benefits plan.

On Oct. 18, 2025, MedImpact, a pharmacy benefits manager, identified unauthorized activity within certain systems in its environment. Upon discovering the unauthorized activity, MedImpact took steps to secure the affected systems to prevent further unauthorized access.

MedImpact then engaged outside cybersecurity experts to assist with the investigation and response to the incident. MedImpact then conducted a detailed review of all data that was potentially impacted.

The review determined that certain data related to members of the Leggett & Platt Employee Benefits Plan was included in the set of potentially affected information. Because MedImpact manages pharmacy benefits for the plan, it maintains certain personal information about plan members and their covered dependents in order to process and administer their prescription drug benefits.

Both adult plan members and minor dependents were among those whose data was involved in the incident. MedImpact sent separate notification letters to affected adults and to the parents or guardians of affected minor children.

The types of personal information exposed varied from person to person but may have included first and last names and other personal information.

The breach was reported to the California Attorney General on Sept. 15, 2026.

MedImpact Healthcare Systems' response to the breach

MedImpact set up a dedicated phone line for individuals with questions about the incident. The number is 844-958-8925, available Monday through Friday from 8 a.m. to 5:30 p.m. Central Time.

MedImpact additionally encouraged affected individuals to use precautions with regard to all of their information.

The company notification to impacted individuals included contact information for the three major credit reporting agencies: Equifax, Experian and TransUnion. It explained how to obtain free annual credit reports, place initial or extended fraud alerts and request security freezes.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image