2026 Profmed / PPS Healthcare — compromised third-party credentials; 200,000 medical-aid members (South Africa)
Data compromised
Member names, identity numbers, contact details, membership numbers, and scheme option information; no financial data or clinical records confirmed at time of notification
Technical writeup
PPS Healthcare Administrators (PPSHA), South Africa's fourth-largest medical scheme administrator, notified Profmed members of a data breach on the evening of June 25, 2026. An unauthorized individual gained access to a third-party service-provider environment using compromised login credentials and may have accessed and exfiltrated personal member data. PPSHA administers six medical aid schemes including Profmed (South Africa's largest graduate professional medical aid), KeyHealth, SEDMED, De Beers Benefit Society, SANDF RFMCF, and one anonymous scheme—total exposure across the ecosystem is not yet published. The company is notifying the Information Regulator of South Africa under POPIA section 22, has isolated affected systems, reset access credentials, and engaged external cybersecurity specialists. Profmed alone covers more than 200,000 clients. Members have been warned to be vigilant for phishing, impersonation, and social engineering.
Root cause
Unauthorized access to third-party service-provider systems via compromised login credentials; attacker may have exfiltrated member personal data