
MedImpact Healthcare Systems Inc., a privately held pharmacy benefit manager in the United States, disclosed a data breach after discovering unauthorized activity in its systems on October 2025. The total number of people impacted by the breach has not been disclosed.
The company provides pharmacy benefit management services to health plans, self-insured employers and government entities, serving millions of members nationwide. The incident has so far impacted adults and minor dependent members of the Legget & Platt, Inc. Employee Benefits Plan.
MedImpact began notifying affected individuals about the incident through U.S. Mail. Separate notices were sent to parents and guardians of affected minor children.
On Oct. 18, 2025, MedImpact identified unauthorized activity within certain systems in its environment. Upon discovery, the company took steps to secure the affected systems and engaged cybersecurity experts to assist with the investigation and response. MedImpact additionally conducted a review of data potentially impacted by the incident.
The types of information exposed varied by individual but included names along with other personal data elements.
On Oct. 27, 2025, a ransomware group known as Qilin claimed responsibility for the attack in a posting on the Tor dark web. The group claimed to have obtained the organization's data.
In its notification letters, MedImpact included general guidance on steps affected consumers can take to protect their information, such as placing fraud alerts, requesting credit freezes and monitoring credit reports.
MedImpact set up a dedicated phone line for affected individuals with questions. Individuals who received a notification letter can call 844-958-8925, Monday through Friday from 8 a.m. to 5:30 p.m. Central Time.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)