← Back

Wire · regulatory

MedImpact PBM breach exposes employer plan members' health data

Published

28 September 2026

Topic

regulatory

◆ Sectors

Healthtech Infrastructure

◆ Geography

United States

◆ Source

Read at insurancebusinessmag.com →

◆ Verified

Fusion42 · 28 September 2026 · Fusion42 review

A ransomware attack on MedImpact Healthcare Systems exposed health data of employer plan members, with notifications delayed over 11 months past HIPAA requirements, raising significant vendor risk concerns for self-insured employers and their fiduciary duties under ERISA.

This Wire brief sits within Fusion42's coverage of Healthtech Infrastructure.

◆ ◆ The Wire takeaway

You must tighten scrutiny on your healthcare vendors' data security now, as late breach notifications expose you to regulatory and reputational risks. The long delay in alerts shows vendor oversight gaps that can harm your business and your employees.

◆ Coverage

1 source · 28 Sep 2026

◆ Related on Wire

◆ Topics

Healthtech Infrastructureransomwarehealthcaredata-breachhipaavendor-riskpharmacy-benefit-manager