MedImpact notifies patients a year after breach
Pharmacy benefit manager MedImpact found an intrusion in October 2025 but only mailed letters in September 2026. SSNs and prescriptions were exposed.
By Sam Reyes · Published · Updated · 5 min read

Pharmacy benefit manager MedImpact Healthcare Systems began mailing breach letters on September 23, 2026 — almost a year after it discovered a network intrusion, MedComply reports.
Timeline
- October 2025: intrusion discovered
- July 2026: investigation completed
- September 23, 2026: notification letters mailed
What was exposed
- Social Security numbers
- Prescription details
- Health insurance information
Healthcare software company Rosch Visionary Systems separately disclosed a breach in the same period. No fines have been announced.
Why the delay matters
US health privacy rules (HIPAA) generally require notification without unreasonable delay and no later than 60 days after discovering a breach. A year-long gap leaves people unaware that criminals may hold their data, so they cannot freeze credit or watch for fraud.
What affected people should do
- Freeze your credit with all three US bureaus.
- Check your insurance explanation-of-benefits statements for prescriptions you did not receive.
- Take up any identity monitoring offered in the letter.
Who MedImpact is
MedImpact is one of the larger independent pharmacy benefit managers (PBMs) in the US. PBMs sit between health plans, employers and pharmacies, processing prescription claims and deciding which drugs are covered. That means they hold detailed records on millions of people who may never have heard of them.
This is a common pattern in healthcare breaches: the organisation that loses the data is a behind-the-scenes contractor, so people receiving the letter often think it is a scam.
Why health data is so valuable to criminals
- Medical identity theft: criminals can use your insurance details to obtain prescriptions or treatment, leaving false information in your medical records.
- Long shelf life: unlike a card number, your Social Security number and medical history cannot be changed.
- Targeted fraud: knowing which medications someone takes allows highly convincing scams, such as fake pharmacy calls or fake insurance refunds.
Why investigations take so long
Companies often say they needed months to work out exactly which files were accessed and whose data was in them. Regulators have made clear, however, that the 60-day clock under HIPAA starts when a breach is discovered, not when the investigation ends. The US Department of Health and Human Services has fined organisations specifically for late notification in the past.
How to check a breach letter is genuine
Look up the company's official phone number yourself rather than using any number in an unexpected email, and check whether the breach is listed on the HHS Office for Civil Rights breach portal.


