Data Breach · Lawsuit Filed

MedImpact Sued Over Data Breach That Exposed SSNs, Medical and Health Insurance Data

Published October 7, 2026

Health plan members whose information was involved in the MedImpact Healthcare Systems data breach may be covered by a proposed class action alleging the pharmacy benefit manager failed to protect names, Social Security numbers, medical and health insurance information exposed in a breach it identified on October 18, 2025. No class has been certified and there is nothing to file yet.

Prescription pills, illustrating the MedImpact pharmacy benefit manager data breach lawsuit
▼ Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements below are unproven allegations. MedImpact Healthcare Systems, Inc. has not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.

What Happened at MedImpact?

MedImpact Healthcare Systems, Inc. is a San Diego pharmacy benefit manager that runs prescription drug benefits for health plans and employers. According to the sample breach notice MedImpact filed with the California Attorney General, the company identified unauthorized activity in certain systems on October 18, 2025, secured them, brought in cybersecurity experts, and found that data relating to plan members was in the set of potentially affected information. MedImpact reported the incident to California on September 25, 2026, nearly a year after it was discovered. The letter says MedImpact has no reason to believe the information has been or will be misused.

On October 5, 2026, a former employee of one of MedImpact’s clients sued in the U.S. District Court for the Southern District of California. The case is Sockwell v. MedImpact Healthcare Systems, Inc., No. 3:26-cv-05693. No court has ruled on any of the allegations.

Status Complaint Filed October 5, 2026 · S.D. Cal. · no class certified
Data Exposed Names, addresses, SSNs, dates of birth, medical and health insurance information Per the complaint, citing MedImpact’s Texas and Massachusetts filings · varies by person
Free Identity Monitoring Offered through Kroll Length and activation deadline are printed in each notice letter
Can I Claim? No — nothing to claim yet

What the Lawsuit Alleges

The plaintiff, a Missouri resident, says his information reached MedImpact through his former employer, a MedImpact client. The complaint alleges that:
MedImpact has not responded in court, and none of the allegations has been tested.

Who Is in the Proposed Class?

The complaint proposes a nationwide class of all individuals in the United States whose private information was affected by the data breach. MedImpact, its parents and subsidiaries, and the judge assigned to the case are excluded. The definition is a proposal; a court would have to certify a class before anyone is formally part of the case.

Legal Claims and What the Lawsuit Seeks

The complaint brings four claims: negligence, negligence per se, breach of third-party beneficiary contract (based on MedImpact’s contracts with its clients) and unjust enrichment. It asks for damages, an order requiring MedImpact to improve its data security and submit to audits, lifetime credit monitoring and identity theft insurance for class members, and attorneys’ fees. Those are requests, not amounts anyone has been awarded.

What Is Still Unknown

Neither the complaint nor MedImpact’s sample letter says how many people were affected, and no nationwide count appears in the official records reviewed for this page. The letter also does not say which health plans’ members were involved; the notice each person received names the data elements for that person. Breach notices are filed state by state, so more detail may emerge as filings are posted.

Health-related vendors have been a frequent target this year. Benefits administrator Kelly Benefits has reached a $5 million data breach settlement over a December 2024 breach, and dental benefits company DentaQuest faces consolidated suits over a 2026 breach.

What Happens Next

MedImpact must be served and respond, often with a motion to dismiss. If other suits over the same breach are filed, they are commonly consolidated into one case. The case could also settle; data breach settlements typically reimburse documented losses, sometimes pay a flat amount, and require a claim form. There is nothing to file in the lawsuit now. The Kroll identity monitoring offered in MedImpact’s letter is a separate, company-run program with its own activation deadline.

Questions

Is there a MedImpact data breach class action?

Yes. Sockwell v. MedImpact Healthcare Systems, Inc., No. 3:26-cv-05693, was filed on October 5, 2026 in the U.S. District Court for the Southern District of California. It is at the complaint stage. No class has been certified, there is no settlement, and there is nothing to claim yet.

Why did MedImpact have my information?

MedImpact is a pharmacy benefit manager that runs prescription drug benefits for health plans and employers. People whose plans use MedImpact may never have dealt with the company directly. MedImpact’s notice letter describes it as a pharmacy benefits manager that provides services to the recipient’s health plan.

What information was exposed in the MedImpact breach?

The complaint, citing MedImpact’s reports to the Texas Attorney General and Massachusetts regulators, says names, addresses, Social Security numbers, dates of birth, medical information and health insurance information were compromised. MedImpact’s notice letter says the information involved varied by person.

What is MedImpact offering people who got a breach notice?

MedImpact’s sample notice offers complimentary identity monitoring through Kroll, including credit monitoring, fraud consultation and identity theft restoration, with an activation deadline printed in each letter. The offer is separate from the lawsuit.

Sources

• Class Action Complaint, Sockwell v. MedImpact Healthcare Systems, Inc., No. 3:26-cv-05693 (S.D. Cal., filed October 5, 2026): complaint (PDF) and docket.
• MedImpact sample consumer notice filed with the California Attorney General (reported September 25, 2026; breach date October 18, 2025): MedImpact breach notice (PDF).

For more class actions keep scrolling below.
Status Complaint Filed — No Class Certified
Case Title Sockwell v. MedImpact Healthcare Systems, Inc.
Case Number 3:26-cv-05693
Court U.S. District Court, Southern District of California
Date Filed October 5, 2026
Breach Identified October 18, 2025

More Data Breach Lawsuits