Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems
Notification letters are being mailed to individuals affected by data breaches at the pharmacy benefit management service provider MedImpact Healthcare Systems and the healthcare software company Rosch Visionary Systems.
MedImpact Healthcare Systems
MedImpact Healthcare Systems, a provider of pharmacy benefit management services to health plans, government entities, and self-insured employers, identified unauthorized activity within its computer network in October 2025. Immediate action was taken to secure its computer systems and prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident.
The investigation was finalized on July 17, 2026, and the affected clients were informed about the data breach on August 13, 2026. Notification letters started to be sent to the affected individuals by MedImpact Healthcare on behalf of its affected clients on September 23, 2026. Data compromised in the incident included names in combination with some or all of the following: address, date of birth, subscriber number, Social Security numbers, health insurance information, health-related information such as prescription information, treatment information, dates of service, service locations, and provider names. The affected clients and number of affected individuals have not been publicly disclosed.
Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services. At the time of issuing notification letters, no misuse of the affected data had been identified. The Qilin ransomware group claimed responsibility for the data breach and added MedImpact Healthcare to its dark web data leak site in October 2025. Qilin claimed to have exfiltrated sensitive data in the incident and threatened to leak the data if the ransom was not paid.
Rosch Visionary Systems
Rosch Visionary Systems, a Pennsylvania-based software company that provides allergy and immunotherapy management software for medical practices, has experienced a cybersecurity incident that compromised part of its computer network. The breach notifications sent to state attorneys general do not state when the breach occurred, when it was detected, or the nature of the unauthorized activity. Healthcare providers that use its software have been notified, and individual notification letters are being mailed to the affected individuals. Complimentary credit monitoring and identity theft protection services have been offered for 24 months.
The scale of the data breach and specific types of information involved are unclear. Healthcare provider clients known to have been affected include Allergy, Asthma and Food Allergy Centers and Texas Regional Asthma, Allergy & Immunology Center. This appears to have been a ransomware attack or data theft and extortion incident. A threat group called Lynx claimed responsibility for the cyberattack and alleged that sensitive data was stolen from Rosch Visionary Systems. The company is no longer listed on the Lynx data leak site, which suggests that a ransom payment was negotiated.



