CSIDB logo
Incident

MedImpact Healthcare Systems Inc.

Incident posture

Attack window
Oct 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-24 21:16

Linked entities

Victim
MedImpact Healthcare Systems Inc.
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

MedImpact Healthcare Systems Inc. disclosed a data breach after discovering unauthorized activity in its systems. The company provides pharmacy benefit management services to health plans, self‑insured employers and government entities, serving millions of members nationwide. The breach impacted adults and minor dependent members of the Legget & Platt Employee Benefits Plan, though the total number of affected individuals has not been disclosed. Upon discovery, the company secured the affected systems and enlisted cybersecurity experts to investigate. A ransomware group known as Qilin claimed responsibility for the attack. Notification letters were sent to affected individuals via U.S. Mail, with separate notices for parents and guardians of minor children. The company also established a dedicated phone line for questions from those who received the notices.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

MedImpact Healthcare Systems Inc., a privately held pharmacy benefit manager in the United States, provides pharmacy benefit management services to health plans, self‑insured employers and government entities, serving millions of members nationwide. In October 2025 the company discovered unauthorized activity in its systems, specifically identifying the intrusion on October 18, 2025. Upon detection MedImpact took steps to secure the affected systems and engaged cybersecurity experts to assist with the investigation and response. The incident has so far impacted adults and minor dependent members of the Legget & Platt, Inc. Employee Benefits Plan, although the total number of individuals affected has not been disclosed.

MedImpact began notifying affected individuals about the breach through U.S. Mail, sending separate notices to parents and guardians of affected minor children. The notification letters included general guidance on steps affected consumers can take to protect their information, such as placing fraud alerts, requesting credit freezes and monitoring credit reports. To assist those with questions, MedImpact established a dedicated phone line reachable at 844-958-8925, available Monday through Friday from 8 a.m. to 5:30 p.m. Central Time. The company also conducted a review of data potentially impacted by the incident to determine what information had been exposed.

The types of information exposed varied by individual but included names along with other personal data elements, though the specific categories were not detailed in the public notice. On October 27, 2025 a ransomware group known as Qilin claimed responsibility for the attack in a posting on the Tor dark web, asserting that it had obtained MedImpact's data. No further details about the group's claims or any subsequent developments were provided in the source material.

Sources

Sources available to members: 1 source.

CSIDB