Risk Program Administrators (RPA), a California-based third-party claims administrator, discovered that an unauthorized person gained access to an employee email account between late May and mid-June 2025. The company disclosed this incident in July 2026. A Nebraska regulatory filing indicates the company reported the incident to the state Attorney General on July 23, 2026. The breach potentially exposed full names, home addresses, Social Security numbers, driver’s license numbers, dates of birth, financial account information, policy numbers, contact information, and medical and health insurance details. The medical data included treatment type, location, cost, physician information, and health plan subscriber numbers. The exact number of affected individuals has not been publicly disclosed, but Class Action U states "thousands of individuals" were affected. It remains unclear which other states beyond Nebraska were impacted. Additional details about the incident, including the full scope and any further regulatory actions, may emerge over time. Consumer notification dates may also vary by subject to change or further clarification as the situation develops.