← Blog

MedImpact Breach: PBM PHI Notices Hit Members Sep 2026

Share on X

MedImpact Healthcare Systems spent nearly a year between spotting trouble and mailing the people whose pharmacy records sat in the blast radius. On October 18, 2025, the San Diego pharmacy benefit manager identified unauthorized activity inside certain systems. On July 17, 2026, it finalized the investigation. Clients heard on August 13. Individual mailings to members of plans administered by MedImpact and/or Elixir Solutions began around September 23–25, 2026, with MedImpact’s substitute notice dating the letter drop to September 25. That is a verified company disclosure — not a leak-site rumor — and the field list is serious: names plus address, date of birth, subscriber numbers, prescription and treatment details, insurance IDs, and in limited instances Social Security numbers. The nationwide census is still unpublished.

Canonical BreachHistory record: https://breachhistory.com/medimpact/medimpact2026. Primary source: MedImpact’s substitute website notice (PDF). Trade context: Insurance Business America (28 September 2026). Secondary coverage has also floated a Qilin ransomware claim from late October 2025. MedImpact has not confirmed that attribution. Treat Qilin as an unverified actor claim layered on top of a verified breach notice.

What happened — the MedImpact timeline

Strip the vendor-risk commentary and the sequence MedImpact attested is short and dated:

  • October 18, 2025: Unauthorized activity identified in certain MedImpact systems. The company says it secured affected systems, launched an investigation with outside cybersecurity experts, reviewed potentially impacted data, and notified law enforcement.
  • October 27, 2025 (unverified secondary claim): Insurance Business reports that the Qilin ransomware group claimed responsibility and alleged roughly 160 GB of data, with portions said to involve Elixir Solutions. MedImpact has not publicly verified Qilin’s claims or said whether a ransom was paid.
  • July 17, 2026: Investigation finalized. MedImpact determined that certain data relating to some individuals was inside the potentially impacted set.
  • August 13, 2026: Clients notified.
  • September 22, 2026: Dedicated toll-free call center opens at (844) 958-8925 (weekdays 8:00 a.m.–5:30 p.m. Central, major holidays excluded).
  • ~September 23–25, 2026: Member mailings begin on behalf of clients; MedImpact’s substitute notice states mailing began September 25, 2026.

Eleven months from detection to individual letters is the detail that made this a benefits-industry story as much as a cybersecurity story. HIPAA’s individual-notification clock is often summarized as 60 days from discovery — a frame Insurance Business highlighted when it noted MedImpact finalized forensics nine months after first detecting the activity. BreachHistory is not offering legal advice. The practical takeaway: if you only learned about the MedImpact data breach when a September 2026 envelope arrived, that lag matches the company’s own timeline.

What public sources have not supplied is a CVE, a named malware family in MedImpact’s own notice, a company-published dump size, or an attested headcount. Absence of those extras is a disclosure gap, not silence about the breach itself. MedImpact said unauthorized activity occurred, data relating to some individuals was in scope, and mailings went out. That is enough to act on.

What information may have been exposed

MedImpact is careful with “may have included” language, and the inventory varies by person. Based on the company’s review, fields that may sit in the potentially impacted set include:

  • First and last name
  • Address
  • Date of birth
  • Subscriber number
  • Limited health-related information, including prescription information
  • Treatment information (date of service, location, or provider name)
  • Insurance identification numbers
  • In limited instances, Social Security numbers

That mix is classic pharmacy-benefit PHI plus durable identifiers. A name, DOB, address, and Rx history is enough for medical-identity fraud, highly believable “your prior auth was cancelled” phishing, and scripts that already know which specialty drug you fill. Insurance IDs and subscriber numbers help attackers impersonate members to call centers. Limited SSNs raise the usual credit and tax-fraud stakes — which is why MedImpact offers complimentary credit monitoring and identity theft protection where an SSN was potentially in scope.

To be clear about what the notice does not claim: MedImpact is not saying every U.S. member’s full chart left the building. It is not publishing a field-by-field schema for every client. It is not stating that payment-card PANs were involved. It is not confirming Qilin’s 160 GB marketing figure. Read the letter you received; the categories listed for you are the ones that matter for your credit freeze and monitoring enrollment.

What was not disclosed

As of the substitute notice and late-September trade coverage:

  • No nationwide records-affected census (BreachHistory catalogs recordsAffected: 0 until a company, client filing, or regulator attests a count)
  • No MedImpact confirmation of Qilin as the actor
  • No company statement verifying the alleged ~160 GB exfiltration volume
  • No public confirmation that a ransom was paid or refused
  • No published technical root cause beyond “unauthorized activity” in certain systems
  • No statement that MedImpact is aware of misuse (the notice says it is not aware of misuse as of mailing)

Those gaps frustrate anyone searching “was I affected by the MedImpact breach.” They do not erase the notice. Client-by-client filings can surface local counts without a single national figure. Until someone attests a census, do not invent one from MedImpact’s marketing claim of tens of millions of members served.

Who MedImpact and Elixir are — and why a PBM breach hits differently

MedImpact is a large U.S. pharmacy benefit manager: it administers prescription drug benefits for health plans, self-insured employers, and government entities. Secondary coverage often cites scale figures north of 20 million U.S. members — useful context for why a PBM incident travels, useless as a substitute for a breach census. Elixir Solutions appears in the notice because members of plans administered by MedImpact and/or Elixir may be in scope; Insurance Business notes Elixir as a PBM MedImpact acquired from Rite Aid, and that Qilin’s unverified claim allegedly referenced Elixir-related data. Acquisition history matters for data-retention sprawl. It does not prove which tables were touched.

A breach at the PBM layer is not usually something an employer “did” on a corporate laptop. Member pharmacy data still flows through that vendor. Employees open letters that name the employer’s health plan and MedImpact in the same breath. Plan sponsors suddenly face vendor-risk questions — Insurance Business framed that ERISA-adjacent diligence conversation without calling this row an ERISA case. For members, the distinction is academic: your Rx history may have been in a vendor system you never logged into directly.

Who is at risk

Members of MedImpact- or Elixir-administered pharmacy benefit plans

If you held coverage whose PBM was MedImpact or Elixir during the relevant period, and you receive a letter listing data categories, treat yourself as in scope for those categories. Even without a letter yet, September 2026 mailings mean the notification wave is live. Watch employer HR portals and plan administrator channels, not random “MedImpact dump checker” sites that ask you to paste an SSN.

People whose letters list limited SSNs

That subset should enroll in the complimentary monitoring MedImpact describes, place fraud alerts or credit freezes, and assume tax-season and new-account fraud risk for years, not weeks. An SSN plus DOB and address is synthetic-identity fuel.

People whose letters emphasize Rx and treatment fields

Specialty drugs, HIV therapies, mental-health medications, fertility treatments, and oncology regimens create stigma and blackmail surfaces that a retail email dump does not. Expect phishing that already knows a drug name or a provider. Do not “confirm your specialty pharmacy enrollment” through a link in an unexpected text.

HR, benefits teams, pharmacies, and providers

Employers are fielding member questions and documenting vendor incident response. Freeze unusual bank-detail changes from anyone claiming to be “MedImpact remittance.” Pharmacies and call centers should expect member-impersonation attempts that already hold subscriber numbers and DOBs — out-of-band verification beats “the patient already gave us the ID on the breach letter.”

Qilin claim — unverified, keep it on a separate shelf

Unverified claim. Per Insurance Business America’s September 28, 2026 reporting, the Russia-linked Qilin ransomware group claimed responsibility on October 27, 2025, and alleged roughly 160 gigabytes of data, with portions said to involve Elixir Solutions. MedImpact’s substitute notice does not name Qilin. The company has not publicly confirmed the actor, the volume, or ransom negotiations in the sources used here.

BreachHistory’s rule for this row is deliberate: the MedImpact data breach is verified by company notice; the Qilin attribution remains secondary and unverified until MedImpact or a regulator says otherwise. Do not rewrite headlines as “MedImpact confirms Qilin stole 160 GB.” Do not ignore the company notice because the actor claim is fuzzy. Both can be true at once: unauthorized activity happened; the brand on the leak site is unproven. Telegram sellers hawking “MedImpact/Elixir 160GB proof packs” are malware or recycled junk until proven otherwise.

Industry context: healthcare intermediaries keep eating the blast radius

Pharmacy benefit managers sit in the same structural danger zone as claims processors: one platform holds dense identity plus clinical-adjacent fields for huge populations who never chose that vendor by name. The 2024 Change Healthcare ransomware event remains the reference trauma for U.S. healthcare intermediaries. MedImpact is not Change Healthcare, and this notice is not a 192-million-record attestation. The pattern that transfers is intermediary concentration: when the PBM is breached, employer plan members inherit the vendor’s timeline.

Other 2026 healthcare incidents in this catalog — AdaptHealth’s social-engineering patient-data event, Astrana Health’s phone-spoof intrusion, McKesson-adjacent ShinyHunters claims — illustrate different access paths. Use them for context, not as proof MedImpact shared an actor or a method. MedImpact’s public root-cause language is simply unauthorized activity in certain systems, investigated with outside experts, with additional technological safeguards implemented afterward. Attackers time lures to the September mailbox wave, not to the October 2025 detection date.

What MedImpact said — and what reporters added

From MedImpact’s substitute notice, in plain language: unauthorized activity on October 18, 2025; systems secured; outside experts and law enforcement notified; investigation finalized July 17, 2026; clients notified August 13; individual mailings began September 25 on behalf of clients; field list as above; complimentary monitoring where SSNs potentially impacted; not aware of misuse; call center (844) 958-8925 from September 22, 2026.

Insurance Business America restated that timeline for a benefits audience, emphasized the roughly eleven-month gap to member letters, placed self-insured employers in the vendor-risk frame, and reported the unverified Qilin/160 GB claim with the explicit caveat that MedImpact had not publicly confirmed ransom payment or the full scope of Qilin’s allegations. That is the right way to layer secondary actor chatter on a primary notice.

Was I affected by the MedImpact PBM breach?

Short answer: there is no public national lookup that returns a yes/no for every American. If you receive a MedImpact or employer/plan letter describing this incident, trust the categories on that letter after verifying phone numbers and URLs against known MedImpact channels — starting with the notice PDF and the published call center. If you have MedImpact or Elixir pharmacy benefits and have not received mail yet, watch HR and plan portals through the fall 2026 notification window; client-by-client mailing can stagger.

Dump-checker sites that demand your SSN “to search the MedImpact leak” are often phishing. Searching “MedImpact data breach,” “MedImpact PBM breach 2026,” or “Elixir Solutions breach notice” should lead you back to MedImpact’s own PDF and reputable trade press — not to crypto takedown services. Members whose letters list only name, address, and Rx fields still need medical-claims vigilance. Members whose letters list SSNs should treat credit freezes as the default.

Phishing and fraud patterns to expect

September mailings create perfect cover for fake ones. Concrete themes to reject:

  • “MedImpact Security: enroll in credit monitoring — enter your SSN and member ID here” on a lookalike domain.
  • “Your specialty prior auth was voided after the PBM breach — upload insurance card and DOB to restore fills.”
  • “Elixir / Rite Aid legacy portal reset required; click to keep your prescriptions.”
  • “HR benefits: update direct-deposit for MedImpact refunds after the cyberattack.”
  • Calls that recite your real pharmacy and already know a drug name, then ask for a one-time banking code.
  • Telegram sellers offering “Qilin MedImpact 160GB” zips — often malware — or cold callers demanding crypto to “remove your PHI row.”

Legitimate remediation will not ask for remote-access software, crypto, or your full SSN as a condition of “confirming you are not in the breach.” It will point to known MedImpact materials, the published call center, and employer/plan channels you already use.

What you should do

  1. Read the letter carefully. Note which data categories apply to you. Verify the call-center number against MedImpact’s substitute notice ((844) 958-8925) before dialing numbers in unexpected emails.
  2. If an SSN is listed: enroll in complimentary monitoring; place fraud alerts or credit freezes at Equifax, Experian, and TransUnion; treat fake IRS notices with extra skepticism.
  3. Review Explanation of Benefits and pharmacy claims for fills, providers, or locations you do not recognize. Medical identity theft often shows up as claims, not as a drained checking account.
  4. Lock down the email inbox tied to your benefits portal and turn on MFA — authenticator apps beat SMS when you can choose.
  5. Treat Rx-themed messages as hostile until verified out of band with your real pharmacy or plan using a published phone number.
  6. Do not paste SSNs, member IDs, or Rx histories into third-party “was I affected” search boxes that appeared the same week as the headlines.
  7. Do not pay anyone offering to scrub your row from an alleged Qilin dump.
  8. Employers and brokers: document vendor notices, coordinate FAQ language, and warn staff about fake “MedImpact remittance” invoice changes.
  9. Plan for a long tail. PHI and limited SSNs retain fraud value for years. Keep skepticism high through 2027 even after monitoring enrollment expires.

None of those steps require you to believe every secondary ransomware claim. They follow from MedImpact’s own field list and mailing timeline.

Why the unpublished census still matters

It is tempting to multiply “20 million members served” into “20 million breached.” That is freelancing beyond the disclosure. Marketing population ≠ records affected. BreachHistory keeps recordsAffected at 0 because MedImpact’s substitute notice and the Insurance Business write-up do not attest a national headcount. Client AG filings may eventually publish local numbers; those should update the catalog when they appear with substance.

For members, unpublished census means “was I affected” stays letter-driven. For journalists, it means quoting MedImpact’s “some individuals” language instead of inventing millions. For attackers, any number pasted into a lure is theater — reject the lure on process, not on whether the number “sounds right.”

Canonical record and sources

BreachHistory indexes this incident as a verified MedImpact disclosure: unauthorized activity identified October 18, 2025; investigation finalized July 17, 2026; clients notified August 13, 2026; individual mailings ~September 23–25, 2026 (company notice: mailing began September 25) for members of pharmacy benefit plans administered by MedImpact and/or Elixir Solutions; data may include name plus address/DOB/subscriber number, limited prescription and treatment information, insurance IDs, and limited SSNs; nationwide census unpublished; companyConfirmed: true; Qilin leak-site attribution reported in secondary coverage remains unverified. Full catalog entry: https://breachhistory.com/medimpact/medimpact2026 (relative: /medimpact/medimpact2026).

Primary and contemporaneous sources:

Related BreachHistory reading for healthcare intermediary and PHI context: AdaptHealth patient-data breach and Astrana Health social-engineering breach.

Bottom line: MedImpact confirmed an October 2025 intrusion into PBM systems, closed its investigation in July 2026, and started member PHI notices in late September 2026 that may include Rx details and limited SSNs — with no public national count, and with any Qilin claim still unverified. If a letter names you, freeze credit when SSNs appear, watch pharmacy phishing, and use MedImpact’s published call center — not the link in the panic forward.