DisclosureLens
HackingHealthcareHealthcareData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDMediumContained

MedImpact Healthcare

bd_935b807df52a877a · schema v1 · pii pii-v2

Severity

Medium

Discovered

Oct 18, 2025

Filed

Sep 15, 2026

To disclose

47 weeks

Affected

Not disclosed

Linked

3 filings

Confidence

68%
Full breach record for MedImpact Healthcare

California AG SB24-629789: MedImpact Healthcare Systems, Inc. reported unauthorized activity on its systems on October 18, 2025. The incident involved a pharmacy benefits manager serving the Leggett & Platt Employee Benefits Plan. Personal information, including names and government identifiers, was potentially impacted. No credit monitoring was offered. MedImpact engaged cybersecurity experts and enhanced security safeguards.

Leak gap clock Leak >180d47 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 47 weeks / 332 days

Oct 18, 2025

Begins

Oct 18, 2025

Discovered

Sep 15, 2026

Filed

vs. sector median

+35 wks slower

This filing is one of 3 about the same incident.View merged incident
A leak claim by qilin about this victim predates this filing by 338 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (2)

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.