PDCM Insurance Data Breach Exposes Protected Health and Personal Information

Published
July 10, 2025
Updated
August 24, 2026
PDCM Insurance Data Breach Exposes Protected Health and Personal Information
PDCM Insurance
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Iowa-based PDCM Insurance disclosed a data breach involving sensitive personal and health information following a ransomware attack that occured in April 2025.

The breach was a ransomware attack carried out by the threat group known as LockBit 3.0. According to the company's notification, there was unauthorized access to certain files and folders within PDCM's network between April 27 and April 28, 2025.

The group posted on the Tor network that it had obtained the organization's data and intended to publish it within 13 to 14 days.

The company stated that upon learning of suspicious network activity involving certain computer systems, it began an investigation to determine the nature and scope of the incident. As part of this process, PDCM Insurance conducted an extensive review of the affected systems to determine whether they contained protected information.

The investigation revealed that the affected systems contained a broad range of both personally identifiable information (PII) and protected health information (PHI). The exposed PII included names, dates of birth, Social Security numbers, driver's license numbers, state identification numbers, taxpayer identification numbers and financial account information.

The exposed PHI included treatment information, diagnoses, treating or referring physician information, prescription and medication information, group health insurance subscriber numbers, medical policy numbers, individual health insurance subscriber numbers and medical record numbers.

The breach was disclosed to the Iowa Attorney General and to the U.S. Department of Health and Human Services. PDCM Insurance discovered the breach on April 28, 2025, and posted a notice on its website.

So far, the incident impacted 4,734 Iowa residents.

PDCM Insurance's response

As part of its response, the company implemented additional security measures and reviewed relevant policies and procedures to reduce the likelihood of a similar event in the future. According to the notification, these steps were taken as part of the company's ongoing commitment to the protection of personal information in its care.

The company's notification also provided detailed information about resources available to consumers, including their right to free annual credit reports from each of the three major credit reporting bureaus and the ability to place fraud alerts on their credit files at no cost.

PDCM Insurance set up a dedicated assistance line for individuals with questions about the incident. Affected individuals can call 844-958-8900 between 9:00 a.m. and 6:30 p.m. EST, Monday through Friday, excluding U.S. holidays.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
PDCM Insurance
Consumers Notification date
Date of Breach
Between April 27, 2025 and April 28, 2025
Breach Discovered Date
April 28, 2025
Total People Affected
Information Types Exposed
  • name
  • date of birth
  • Social Security number
  • driver’s license number
  • state identification numbers
  • taxpayer identification number
  • financial account information
  • treatment information
  • diagnosis
  • treating/referring physician
  • prescription/
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image