Wire · regulatory
MedImpact PBM breach exposes employer plan members' health data
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 28 September 2026 · Fusion42 review
A ransomware attack on MedImpact Healthcare Systems exposed health data of employer plan members, with notifications delayed over 11 months past HIPAA requirements, raising significant vendor risk concerns for self-insured employers and their fiduciary duties under ERISA.
This Wire brief sits within Fusion42's coverage of Healthtech Infrastructure.
◆ ◆ The Wire takeaway
You must tighten scrutiny on your healthcare vendors' data security now, as late breach notifications expose you to regulatory and reputational risks. The long delay in alerts shows vendor oversight gaps that can harm your business and your employees.
◆ Coverage
1 source · 28 Sep 2026
◆ Related on Wire
◆ Topics