Risk Program Administrators Data Breach Investigation
Risk Program Administrators LLC reported an email-account security incident that may have exposed personal, financial, and health information belonging to certain individuals. The company said it was not aware of actual or attempted identity fraud related to the event when it issued its notice. Strauss Borrelli PLLC is investigating the Risk Program Administrators data incident and the rights of people who may be affected. If you received a notice, you may fill out the secure contact form on this page to ask whether you may qualify to pursue a claim.
Key Facts at a Glance
- Entity Involved: Risk Program Administrators LLC (Healthcare)
- Incident Type: Hacking/IT incident involving unauthorized access to an employee email account
- Date of Incident: May 27, 2025, to June 16, 2025
- Discovery Date: Not disclosed in the available notice
- Official Notice Date: July 22, 2026
- Exposed Information: Names, addresses, Social Security numbers, driver’s license numbers, dates of birth, financial account information, medical information, and health insurance information
- Affected Population: 8,309 individuals, according to the supplied regulatory filing information
What Happened?
According to Risk Program Administrators LLC’s official consumer notice, the organization identified suspicious activity involving an employee email account and took steps to secure the account. RPA said it then engaged external cybersecurity specialists to investigate the nature and scope of the event. The investigation reportedly determined that an unknown unauthorized person accessed certain emails from May 27, 2025, through June 16, 2025. RPA subsequently reviewed the affected email content to determine whose information may have been accessible.
The company’s notice, dated July 22, 2026, states that information relating to certain individuals could have been accessed. RPA said it had no evidence that information was misused and was unaware of actual or attempted identity fraud associated with the incident when the notice was issued. The company also reported that it was mailing letters to individuals whose protected information was contained in the files at issue and for whom it had valid mailing addresses. The supplied regulatory information categorizes the event as a hacking/IT incident involving email.
What Information Was Exposed?
Risk Program Administrators reported that the information potentially affected varies by individual. The data may include full names, addresses, Social Security numbers, driver’s license numbers, dates of birth, financial account information, medical information, and health insurance information. The health-related information may include treatment type, treatment location, treatment cost, physician information, mental or physical conditions, subscriber or member numbers, and admission dates.
This combination of identifying, financial, and healthcare data may create risks beyond ordinary phishing. Potentially affected individuals should watch for fraudulent patient bills, insurance-verification scams, false prescription inquiries, medical identity theft, and communications impersonating a healthcare provider or insurer. The notice did not state that every listed data element was involved for every person.
What Should You Do Next?
- Review the notice carefully: Confirm whether Risk Program Administrators identified the particular information associated with you. Keep the letter, envelope, and related communications in a secure place.
- Monitor financial and credit records: Review bank and financial account statements for unfamiliar activity. Obtain your credit reports through AnnualCreditReport.com and consider placing a free fraud alert or credit freeze with the major credit bureaus.
- Check healthcare records: Examine explanations of benefits, patient portals, medical bills, prescription records, and insurance statements for services or claims you do not recognize. Report discrepancies promptly to the provider or insurer.
- Be alert for targeted scams: Treat unexpected calls, emails, or texts requesting insurance numbers, account details, payments, or identity verification with caution. Contact the healthcare provider, insurer, or financial institution through a verified phone number rather than using links in unsolicited messages.
- Document suspicious activity: Save relevant messages, screenshots, bills, account statements, and records of time spent responding. If identity theft or fraud occurs, consider reporting it to the affected institution, the Federal Trade Commission, and appropriate law enforcement.
Your Legal Rights
People whose personal or health information may have been involved could have rights under federal or state privacy, consumer-protection, data-breach notification, or other laws. The rights available depend on factors such as where the person lives, what information was involved, whether misuse occurred, and whether the person experienced losses or other legally recognized harm.
Potential remedies may include reimbursement for documented out-of-pocket losses, compensation for certain harms where permitted, or measures intended to improve data security. Receiving a notice does not automatically establish a legal claim, and the company’s notice does not establish that information was actually misused. Affected individuals should preserve notices and supporting records because legal deadlines may apply. This general information is not individualized legal advice.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC investigates cybersecurity and privacy incidents involving sensitive personal, financial, medical, and insurance information. The firm can evaluate the available notices and circumstances, explain potential legal options, and assess whether an affected individual may qualify to pursue a claim. A consultation can also help consumers understand which documents may be useful to preserve. No outcome is guaranteed, and any evaluation depends on the facts and applicable law.
If you believe you may have been affected by the Risk Program Administrators breach:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










