Health Payment Systems Data Breach Exposes Health Payment and Billing Records

Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

What Happened in the Health Payment Systems Data Breach?

Health Payment Systems, Inc. is a Wisconsin company that runs PayMedix, a platform many self-insured employers and health plans use to handle claims and billing. The company recently told federal regulators about a break-in involving one of its email systems. As a result, thousands of people connected to its client health plans could have had personal data exposed.

According to the filing made with the U.S. Department of Health and Human Services Office for Civil Rights, this was a hacking incident tied to email access. The filing was submitted in July 2026. However, the company has not shared exactly when the intrusion itself took place or when its internal team first discovered it.

Because HPS has not released a full public notice, many details remain unclear. For instance, the company hasn’t explained how the attacker got into the email account or whether it belonged to a single employee or several. This lack of detail is common in the early stages of a breach investigation, especially for a business associate handling data on behalf of many separate organizations.

What is clear is that HPS reported the event to regulators as required once it identified the scope of the incident. Investigations like this typically involve outside forensic experts who trace how an attacker gained access and determine which records, if any, were viewed or copied. Additional information may follow as that work continues.

Who was affected?

The individuals affected by this incident are connected to Health Payment Systems through its PayMedix platform. Because HPS acts as a payment processor for numerous employer health plans, many affected people may have never directly interacted with the company. They might only recognize it as the name on their benefits statement or paycheck deduction.

HPS reported that the breach affects approximately 9,380 individuals. This estimate comes from the regulatory filing and could shift as the investigation moves forward. The affected group likely spans multiple employer groups and health plans across different states, since PayMedix serves clients broadly rather than a single regional customer base.

Because health payment platforms often manage data for entire households enrolled in a benefits plan, spouses and dependents could also be included among those affected. At this stage, HPS has not specified whether minors are part of the impacted population. Anyone unsure of their status should watch for an official notification letter in the coming weeks.

What Information Was Potentially Exposed?

Health Payment Systems has not published a specific list of the data types involved in this breach. The regulatory filing only identifies the location of the compromised data as email, without detailing which fields or documents were included. Even so, given the nature of HPS’s business, certain categories of information are commonly at risk in incidents like this.

  • Full names
  • Health plan or member identification numbers
  • Billing and claims details
  • Payment account information
  • Contact information such as addresses, phone numbers, or email addresses
  • Other personal identifiers tied to health benefit accounts

Because HPS processes payment and billing records on behalf of health plans, any exposed email correspondence could include sensitive financial and health-related details. As a result, affected individuals may face a higher risk of targeted phishing attempts that reference their actual billing information, making scams harder to spot.

In addition, if payment details or account numbers were part of the exposed email traffic, victims could see attempted fraud on existing accounts. Because health billing data often includes information tied to insurance claims, there’s also a possibility of medical identity theft, where someone else’s treatment gets billed under a victim’s name.

What is the company doing?

Once Health Payment Systems identified the incident, it took steps required under federal law by reporting the breach to HHS OCR. This filing is a necessary part of the response process for any HIPAA-covered entity or business associate that experiences a breach affecting 500 or more individuals.

At this time, HPS has not publicly detailed additional remediation measures, such as email security upgrades or staff training changes. However, companies in this position typically work with cybersecurity specialists to contain the incident and prevent similar access in the future. Affected individuals should expect to receive direct written notice from HPS or PayMedix as the investigation concludes and specific records are confirmed.

Because HPS works with numerous employer health plans, notification responsibilities may also be shared with those plan sponsors. This can mean some individuals receive information indirectly through their employer’s benefits department rather than straight from HPS itself.

What Should Affected Individuals Do?

Monitor Your Health Plan and Financial Statements

Start by reviewing recent statements from your health plan and any linked payment accounts. Look closely for claims you don’t recognize or billing activity tied to services you never received.

This step matters because payment platforms like PayMedix handle both claims data and financial transactions. Catching an unfamiliar charge or claim early can help limit damage and give you a head start if you need to dispute anything with your provider or insurer.

Watch for Phishing Attempts

Be cautious of emails, texts, or phone calls referencing your health benefits, billing account, or payment history. Scammers sometimes use details from a breach to make their messages look convincing.

Avoid clicking links or providing information unless you can verify the sender independently. Instead, contact your health plan or HPS directly using a phone number you already trust, not one provided in a suspicious message.

Consider a Fraud Alert or Credit Freeze

If you’re concerned that financial information may have been exposed, consider placing a fraud alert or credit freeze with the major credit bureaus. This makes it harder for anyone to open new credit accounts using your identity.

A credit freeze is generally the stronger protection because it blocks most new credit inquiries entirely. Meanwhile, a fraud alert simply requires lenders to verify your identity before approving new credit, which still adds a helpful layer of security.

Guard Against Medical Identity Theft

Because this breach involves a healthcare payment processor, keep an eye on your medical records and insurance claim history too. Request an explanation of benefits from your insurer periodically and check that all listed services match what you actually received.

If you notice unfamiliar claims, report them to your health plan right away. Medical identity theft can be harder to untangle than financial fraud, so catching it early is especially important.

Keep Records and Consider Legal Options

Save any notification letter you receive from Health Payment Systems or PayMedix, along with records of any suspicious activity you find. This documentation can prove valuable if you decide to pursue a legal claim later.

Because companies that manage sensitive health and payment data have a legal duty to protect it, affected individuals may have options for holding HPS accountable. Speaking with a data breach attorney can help you understand whether you qualify for compensation and what steps come next.



More Information

Official data breach notification from Delaware Attorney General

Official data breach notification from Oregon Department of Justice

Related Data Breaches

View the full list of tracked data breaches →