Risk Program Administrators LLC Reports Data Breach Affecting 8,309 Individuals
Risk Program Administrators LLC, a U.S.-based insurance program administration firm serving public entities, private organizations, faith-based groups, and nonprofits, disclosed a data breach impacting 8,309 individuals. The incident, classified as a "data privacy event," exposed both personally identifiable information (PII) and protected health information (PHI).
Unauthorized activity was detected within the company’s systems between May 27 and June 16, 2025, though the breach was only reported to the U.S. Department of Health and Human Services (HHS) on July 23, 2026 over three years later. A public notice was posted on the company’s website on July 22, 2026.
Compromised Data:
- PII: Full names, Social Security numbers, home addresses, dates of birth, driver’s license numbers, financial account details, and payment information.
- PHI: Admission dates, health insurance data, medical conditions, physician details, treatment records, subscriber/member numbers, treatment costs, and locations.
Risk Program Administrators has begun notifying affected individuals and directing them to the company’s notice page for updates on protective measures. The delayed reporting raises concerns about compliance and response timelines in data security incidents.
Source: https://www.claimdepot.com/data-breach/risk-program-administrators-2026
Risk Program Administrators cybersecurity rating report: https://www.rankiteo.com/company/risk-program-administrators
"id": "RIS1787434090",
"linkid": "risk-program-administrators",
"type": "Breach",
"date": "5/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '8309',
'industry': 'Insurance',
'location': 'U.S.',
'name': 'Risk Program Administrators LLC',
'type': 'Insurance Program Administration Firm'}],
'customer_advisories': 'Direct notifications to affected individuals with '
'protective measures guidance',
'data_breach': {'number_of_records_exposed': '8309',
'personally_identifiable_information': ['Full names',
'Social Security '
'numbers',
'Home addresses',
'Dates of birth',
'Driver’s license '
'numbers',
'Financial account '
'details',
'Payment information',
'Admission dates',
'Health insurance '
'data',
'Medical conditions',
'Physician details',
'Treatment records',
'Subscriber/member '
'numbers',
'Treatment costs',
'Locations'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Protected Health Information '
'(PHI)']},
'date_detected': '2025-05-27',
'date_publicly_disclosed': '2026-07-22',
'description': 'Risk Program Administrators LLC, a U.S.-based insurance '
'program administration firm, disclosed a data breach '
'impacting 8,309 individuals. The incident exposed personally '
'identifiable information (PII) and protected health '
'information (PHI).',
'impact': {'data_compromised': 'PII and PHI',
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'references': [{'source': 'Risk Program Administrators LLC Notice',
'url': 'https://www.riskprogramadministrators.com/notice'}],
'regulatory_compliance': {'regulations_violated': ['HIPAA (potential)'],
'regulatory_notifications': ['Reported to U.S. '
'Department of Health '
'and Human Services '
'(HHS) on 2026-07-23']},
'response': {'communication_strategy': 'Public notice on company website and '
'direct notifications to affected '
'individuals'},
'title': 'Risk Program Administrators LLC Data Breach',
'type': 'Data Breach'}