▼
Allegations Only · No Settlement Yet
This article describes a class action complaint. The statements below are unproven
allegations. MedImpact Healthcare Systems, Inc. has not been found liable, there is no certified
class, and nothing to claim at this time. This page is informational and is not legal advice.
MedImpact Healthcare Systems, Inc. is a San Diego pharmacy benefit manager that runs prescription drug benefits
for health plans and employers. According to the sample breach notice MedImpact filed with the California Attorney
General, the company identified unauthorized activity in certain systems on October 18, 2025, secured them, brought
in cybersecurity experts, and found that data relating to plan members was in the set of potentially affected
information. MedImpact reported the incident to California on September 25, 2026, nearly a year after it was
discovered. The letter says MedImpact has no reason to believe the information has been or will be misused.
On October 5, 2026, a former employee of one of MedImpact’s clients sued in the U.S. District Court for the
Southern District of California. The case is Sockwell v. MedImpact Healthcare Systems, Inc., No.
3:26-cv-05693. No court has ruled on any of the allegations.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Status
Complaint Filed
October 5, 2026 · S.D. Cal. · no class certified
Data Exposed
Names, addresses, SSNs, dates of birth, medical and health insurance information
Per the complaint, citing MedImpact’s Texas and Massachusetts filings · varies by person
Free Identity Monitoring
Offered through Kroll
Length and activation deadline are printed in each notice letter
Can I Claim?
No — nothing to claim yet
The plaintiff, a Missouri resident, says his information reached MedImpact through his former employer, a
MedImpact client. The complaint alleges that:
- MedImpact required its clients to hand over plan members’ personal and health information and was
responsible for keeping it secure
- MedImpact did not use reasonable data security, despite well-known risks to companies that handle
health data
- MedImpact waited too long to notify affected people and did not fully explain what was taken
- Plan members now face a lasting risk of identity theft, medical fraud and other misuse, because Social
Security numbers and medical histories cannot be changed
MedImpact has not responded in court, and none of the allegations has been tested.
The complaint proposes a nationwide class of all individuals in the United States whose private information was
affected by the data breach. MedImpact, its parents and subsidiaries, and the judge assigned to the case are
excluded. The definition is a proposal; a court would have to certify a class before anyone is formally part of
the case.
The complaint brings four claims: negligence, negligence per se, breach of third-party beneficiary contract (based
on MedImpact’s contracts with its clients) and unjust enrichment. It asks for damages, an order requiring MedImpact
to improve its data security and submit to audits, lifetime credit monitoring and identity theft insurance for
class members, and attorneys’ fees. Those are requests, not amounts anyone has been awarded.
Neither the complaint nor MedImpact’s sample letter says how many people were affected, and no nationwide count
appears in the official records reviewed for this page. The letter also does not say which health plans’ members
were involved; the notice each person received names the data elements for that person. Breach notices are filed
state by state, so more detail may emerge as filings are posted.
Health-related vendors have been a frequent target this year. Benefits administrator Kelly Benefits has reached a
$5 million data breach settlement
over a December 2024 breach, and dental benefits company DentaQuest faces
consolidated suits
over a 2026 breach.
MedImpact must be served and respond, often with a motion to dismiss. If other suits over the same breach are
filed, they are commonly consolidated into one case. The case could also settle; data breach settlements typically
reimburse documented losses, sometimes pay a flat amount, and require a claim form. There is nothing to file in the
lawsuit now. The Kroll identity monitoring offered in MedImpact’s letter is a separate, company-run program with its
own activation deadline.
Is there a MedImpact data breach class action?
Yes. Sockwell v. MedImpact Healthcare Systems, Inc., No. 3:26-cv-05693, was filed on October 5, 2026 in the U.S. District Court for the Southern District of California. It is at the complaint stage. No class has been certified, there is no settlement, and there is nothing to claim yet.
Why did MedImpact have my information?
MedImpact is a pharmacy benefit manager that runs prescription drug benefits for health plans and employers. People whose plans use MedImpact may never have dealt with the company directly. MedImpact’s notice letter describes it as a pharmacy benefits manager that provides services to the recipient’s health plan.
What information was exposed in the MedImpact breach?
The complaint, citing MedImpact’s reports to the Texas Attorney General and Massachusetts regulators, says names, addresses, Social Security numbers, dates of birth, medical information and health insurance information were compromised. MedImpact’s notice letter says the information involved varied by person.
What is MedImpact offering people who got a breach notice?
MedImpact’s sample notice offers complimentary identity monitoring through Kroll, including credit monitoring, fraud consultation and identity theft restoration, with an activation deadline printed in each letter. The offer is separate from the lawsuit.
• Class Action Complaint, Sockwell v. MedImpact Healthcare Systems, Inc., No. 3:26-cv-05693 (S.D. Cal., filed October 5, 2026):
complaint (PDF)
and docket.
• MedImpact sample consumer notice filed with the California Attorney General (reported September 25, 2026; breach date October 18, 2025):
MedImpact breach notice (PDF).
For more class actions keep scrolling below.
Status
Complaint Filed — No Class Certified
Case Title
Sockwell v. MedImpact Healthcare Systems, Inc.
Case Number
3:26-cv-05693
Court
U.S. District Court, Southern District of California
Date Filed
October 5, 2026
Breach Identified
October 18, 2025