Risk Program Administrators Data Breach Affects 8,309

Published
August 20, 2026
Updated
August 20, 2026
Risk Program Administrators Data Breach Affects 8,309
Risk Program Administrators
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Risk Program Administrators LLC, an insurance program administration and management firm, disclosed a data breach that affected 8,309 individuals in the United States.

The company specializes in pooled and program-based insurance arrangements for public entities, private organizations, faith-based groups and nonprofits. Its services include program administration, risk management, coverage placement and design, member services, accounting, vendor management, staff augmentation and claims management.

The breach was reported to the U.S. Department of Health and Human Services on July 23, 2026. Risk Program Administrators posted a notice of the data privacy event on its website on July 22, 2026.

On or about May 27, 2025, unauthorized activity occurred within Risk Program Administrators' systems, continuing through June 16, 2025.

The breach exposed both personally identifiable information, commonly known as PII, and protected health information, known as PHI.

The personally identifiable information that may have been exposed included full names, Social Security numbers, home addresses, dates of birth, driver's license numbers, financial account information and payment details.

The breach also involved a broad range of protected health information including admission dates, health insurance information, medical conditions, medical information, physician information, subscriber or member numbers, treatment details, treatment costs and treatment locations.

Risk Program Administrators' response to the breach

Risk Program Administrators notified individuals whose personal and medical information may have been affected by the breach. The company described the incident as a "data privacy event" in its public notice.

The company's reporting of this breach to the U.S. Department of Health and Human Services came approximately three years after it first identified the unauthorized activity in its systems.

Individuals who have received or who expect to receive a notice from Risk Program Administrators can refer to the company's notice page for the most current details about the incident, including information about any protective resources being offered and instructions for how to enroll in them.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
July 22, 2026
Date of Breach
on or about May 27, 2025, to June 16, 2025
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Social Security number
  • address
  • admission date
  • date of birth
  • driver’s license number
  • financial account information
  • full name
  • health insurance information
  • medical condition
  • medical information
  • payment
  • physician
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image