PDCM Insurance data breach (2025): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
PDCM Insurance says it discovered suspicious network activity on April 28, 2025. Its investigation identified unauthorized access to files and folders between April 27 and April 28, 2025. The company has since notified affected clients and individuals.
What data may have been involved
PDCM’s notice lists names, birth dates, Social Security and tax identifiers, driver’s license or state ID numbers, financial account information, medical treatment and diagnosis information, prescriptions, and health-insurance or medical-record information. The combination varies by person. A notice naming one category is not proof that all of those categories applied to you.
An August 3, 2026 filing to the Iowa Attorney General reports 4,734 Iowa residents notified. That is a state count, not a national total. Vermont’s September 29 register separately lists one affected Vermont resident and Social Security information.
PDCM’s assistance line is 844-958-8900. Check your own letter for monitoring eligibility and its enrollment deadline; do not assume one person’s offer applies to everyone.
Sources
What to do now
- Keep your notice. It identifies the data categories that applied to you and any enrollment deadline.
- Verify the notice through the organization’s official website or a contact number you already trust. Do not use an unexpected message’s links or share passwords or one-time codes.
- If Social Security or other identity information was involved, consider a free credit freeze with each of the three major U.S. bureaus. A freeze helps restrict new credit; it does not stop transactions on existing accounts.
- Review bank and card statements. Contact the institution about unfamiliar transactions. If health information was involved, also check insurance statements for unfamiliar claims.
- Use IdentityTheft.gov if someone is using your identity. Enroll in any monitoring offer through the verified notice’s instructions.
For help interpreting a letter, see a company emailed me about a breach.
What a Delist scan can tell you
A free Delist scan checks personal-data exposure on the sources we cover. It does not inspect this organization’s systems, establish whether your record was involved in this incident, or erase breach dumps. Paid listing-removal work requires separate authorization.
This summary is compiled from public notices and reporting available when this page was last updated. Figures may change as investigations continue. Confirm your own exposure and any assistance offer with the organization named in your notice.
Inclusion is a record of a publicly reported incident, not an allegation of wrongdoing or negligence.
Are the Iowa and Vermont figures national totals?
No. The Iowa filing reports 4,734 Iowa residents notified, and Vermont separately lists one affected resident. Neither is a nationwide total. The company notice places unauthorized access on April 27–28, 2025.
Frequently asked questions
Why does the title say 2025 when the filings are from 2026?
The company dates the unauthorized access to April 2025. The later state filings describe notification in 2026; notification and access dates are different.
Does every listed medical or financial field apply to me?
No. PDCM says the information varies by individual. Your letter identifies your own categories and any monitoring eligibility or enrollment deadline.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- Farmers Insurance data breach (2025)
- AssuranceAmerica data breach (2026)
- DentaQuest data breach (2026)
- Conduent data breach (2025)
- Allianz Life data breach (2025)
- AdaptHealth data breach (2026)
- First 48 hours after a data breach
- How to freeze your credit
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.