← Blog

Profmed Data Breach: 200,000 South African Medical Aid Members Exposed

Share on X

PPS Healthcare Administrators (PPSHA), the administrator of South Africa's Profmed medical aid scheme, disclosed a data breach on the evening of June 25, 2026. The breach affected Profmed's approximately 200,000 members — South Africa's largest graduate professional medical aid — and potentially members across five other schemes PPSHA administers.

What Happened

PPSHA identified that an unauthorized individual gained access to a third-party service-provider environment using compromised login credentials. The attacker may have accessed and removed personal member data. The affected service provider has isolated compromised systems, reset all access credentials, and brought in external cybersecurity specialists.

What Data Was Exposed

According to the notification sent to Profmed members on June 25, 2026, the potentially compromised data includes:

  • Full names
  • Identity (ID) numbers
  • Contact details (phone, email, address)
  • Membership numbers
  • Scheme option information (plan tier)

PPSHA confirmed no financial account or clinical treatment data was identified as compromised at the time of notification.

Who Is at Risk

PPSHA administers six major medical aid schemes in South Africa: Profmed, KeyHealth Medical Scheme, SEDMED, De Beers Benefit Society, a sixth anonymous scheme, and provides services to the South African National Defence Force's Regular Force Medical Continuation Fund (RFMCF). The full scope of members across all schemes had not been published at the time of this writing; only Profmed notified members publicly on June 25.

The combination of South African ID numbers with medical aid details and contact information creates serious risk for:

  • Targeted phishing and vishing (phone phishing) attacks
  • Identity fraud using your ID number
  • Social engineering attempts impersonating Profmed or PPSHA
  • Banking fraud using combined identity data

What Was Not Exposed

PPSHA stated that there is no indication that banking or financial account details were accessed, nor that clinical medical records were compromised in this incident.

Regulatory Response

PPSHA has initiated notification to the Information Regulator of South Africa under section 22 of the Protection of Personal Information Act (POPIA), which requires notification when personal information is compromised and individuals may be adversely affected.

Action Items

  1. Be skeptical of all unsolicited contact claiming to be from Profmed or PPS — verify by calling the official Profmed number directly.
  2. Watch for phishing emails referencing your membership details, scheme option, or renewal — attackers may use these to appear credible.
  3. Monitor your credit profile via TransUnion, Experian, or XDS — your ID number was potentially exposed.
  4. Report suspicious activity to Profmed via official channels and to the South African Police Service (SAPS) if you suspect fraud.
  5. Do not confirm personal details to any caller claiming to verify your Profmed membership unless you initiated the call.

About Profmed and PPSHA

Profmed is South Africa's largest restricted medical aid scheme and the largest graduate professional scheme in the country, requiring members to hold a recognized professional qualification. PPS Healthcare Administrators, its administrator, is the fourth-largest medical scheme administrator in South Africa.

Full breach record: breachhistory.com/profmed/profmed-ppsha-breach2026

Sources: MyBroadband (June 25, 2026) | PPS Group