PDCM Insurance Data Breach Class Action Lawsuit Investigation

Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the PDCM Insurance data breach, which reportedly affected about 39,759 individuals and may have exposed names, dates of birth, Social Security numbers, driver’s license and state identification numbers, taxpayer identification numbers, and financial account information. It also identifies treatment information, diagnoses, treating or referring physicians, prescription and medication information, health insurance subscriber and policy numbers, and medical record numbers.


JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against PDCM Insurance, please submit your information to be considered:

You may also open the form here: PDCM Insurance Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.

PDCM Insurance Data Breach: Key Facts

Company: PDCM Insurance
Location: Waterloo, Iowa
Incident Type: Data Breach
Number Affected: APPROXIMATELY 39,759
Data Involved: names, dates of birth, Social Security numbers, driver’s license and state identification numbers, taxpayer identification numbers, and financial account information. It also identifies treatment information, diagnoses, treating or referring physicians, prescription and medication information, health insurance subscriber and policy numbers, and medical record numbers
Date Began: April 27, 2025
Date Discovered: April 28, 2025
Date Ended: April 28, 2025
Notice Date: August 3, 2026
Credit Monitoring: 12 Months of Kroll
Status: Class Action Lawsuit Investigation


What happened in the PDCM Insurance data breach?

PDCM Insurance has reported a data breach affecting 39,759 people, including 1,046 Texas residents, according to the reporting data underlying the Texas Attorney General’s breach disclosure website. The incident involved unauthorized access to files and folders on PDCM’s computer network in April 2025. Although the Texas disclosure was published on September 29, 2026, the incident had already been reported to Iowa regulators in August 2026.

PDCM Insurance, based in Waterloo, Iowa, is a division of Patriot Growth Insurance Services, LLC. According to its public notice, PDCM detected suspicious activity involving certain computer systems on April 28, 2025. Its investigation subsequently established that unauthorized access occurred between April 27 and April 28, 2025. The company has not publicly identified the method used to enter its network, the vulnerability involved, or the party responsible. The official notices reviewed do not establish whether the incident involved ransomware, phishing, or another intrusion method

The affected systems contained personal, financial, medical, and insurance information. PDCM’s public notice lists names, dates of birth, Social Security numbers, driver’s license and state identification numbers, taxpayer identification numbers, and financial account information. It also identifies treatment information, diagnoses, treating or referring physicians, prescription and medication information, health insurance subscriber and policy numbers, and medical record numbers. These categories describe information found across the involved systems; an individual’s notification letter identifies the information associated with that person.

After discovering the activity, PDCM says it secured its network, contacted law enforcement, and investigated the incident. It then reviewed the affected systems to identify sensitive information and the individuals involved. In its August 3, 2026 submission to the Iowa Attorney General, PDCM stated that this review had recently concluded. The filing does not provide an exact completion date or a detailed explanation for the interval between discovery and the August notifications.

The Iowa filing states that PDCM provided written notices to 4,734 Iowa residents on or about August 3, 2026, while notifications to relevant clients and individuals continued. That figure represents Iowa residents notified at that stage, rather than the total affected population. PDCM also reported offering 12 months of complimentary Kroll credit monitoring to individuals whose Social Security numbers or similar identifiers were potentially affected, along with additional safeguards and employee training.

PDCM states that it had no indication of identity theft or fraud resulting from the incident when it issued its notice. It encourages potentially affected individuals to review financial statements, credit reports, and insurance explanations of benefits for unfamiliar activity. The company lists 844-958-8900 as its dedicated assistance number for questions about the breach.


How did the PDCM Insurance data breach occur?

The PDCM Insurance data breach occurred when an unauthorized party accessed files and folders on the company’s computer network. The initial method of entry has not been publicly disclosed. PDCM’s official notices do not identify a compromised password, phishing email, software vulnerability, or other entry point. They also do not confirm ransomware, encryption, or the downloading of affected files.


When did the PDCM Insurance data breach occur?

The PDCM Insurance data breach occurred between April 27 and April 28, 2025, when an unauthorized party accessed files and folders on its network. PDCM discovered suspicious activity on April 28, 2025.


How many people were affected by the PDCM Insurance data breach?

Approximately 39,759 individuals were affected by the PDCM Insurance data breach.


What information was exposed in the PDCM Insurance data breach?

  • Breached data reportedly may include, but is not necessarily limited to:
    • names
    • dates of birth
    • Social Security number
    • driver’s license and state identification numbers
    • taxpayer identification numbers
    • financial account information
    • treatment information
    • diagnoses
    • treating or referring physicians
    • prescription and medication information
    • health insurance subscriber and policy numbers
    • medical record numbers

Has PDCM Insurance offered free credit monitoring and/or identity theft protection services?

Yes. PDCM Insurance’s August 3, 2026 filing with the Iowa Attorney General states that it is offering 12 months of free credit monitoring through Kroll to individuals whose Social Security numbers or similar identifiers were potentially affected. The accompanying sample notice lists credit monitoring, fraud consultation, and identity theft restoration among the available services.


PDCM Insurance Data Breach Timeline

Date Event
April 27–28, 2025 An unauthorized party accessed files and folders within PDCM Insurance’s computer network.
April 28, 2025 PDCM detected suspicious network activity. The company says it took steps to secure its network, notified law enforcement, and began investigating.
On or about August 3, 2026 PDCM provided written notifications to 4,734 Iowa residents. Notifications to relevant clients and individuals remained ongoing.

Who is PDCM Insurance?

PDCM Insurance is an insurance agency based in Waterloo, Iowa, and a division of Patriot Growth Insurance Services, LLC. It provides business insurance, personal insurance, employee benefits services, and consulting for employers, individuals, and families. Its offerings include home and auto coverage, employee benefit planning and administration, and guidance on human resources, workplace safety, and wellness programs. PDCM works with multiple insurance carriers to arrange coverage for its clients.


What should you do if you received a PDCM Insurance data breach letter?

If you received a PDCM Insurance data breach letter, review the information listed as affected and consider taking these steps:

    • Enroll in the free Kroll services offered in your letter. PDCM reported offering 12 months of credit monitoring to eligible individuals, with fraud consultation and identity theft restoration also listed in its sample notice. Follow your letter’s enrollment instructions and activation deadline.
    • Review your financial accounts and credit reports. Check for unfamiliar transactions, accounts, or credit inquiries. PDCM directs recipients to AnnualCreditReport.com for free credit reports.
    • Consider a credit freeze or fraud alert. PDCM’s notice explains these options for limiting unauthorized credit activity. Credit freezes are free and must be placed separately with Equifax, Experian, and TransUnion.
    • Check medical bills and insurance statements if health information was affected. Look for unfamiliar treatment, prescriptions, or claims, and report discrepancies to your insurer or healthcare provider. PDCM specifically recommends reviewing explanations of benefits.
    • Keep the letter and document suspicious activity. Save related correspondence, expenses, and records of any suspected misuse. If identity theft occurs, visit IdentityTheft.gov and contact the affected financial institution or insurer.

For questions about the notice or available assistance, PDCM lists 844-958-8900, Monday through Friday, 9:00 a.m.–6:30 p.m. Eastern, excluding U.S. holidays. Receiving a letter means your information was potentially affected; it does not establish that identity theft has occurred.


PDCM Insurance Data Breach Notice

The notice describes the PDCM Insurance data breach, including the type of information that may have been involved and the steps offered to affected individuals.

Open the PDCM Insurance Data Breach Notice in a New Tab


Sources & Additional Information About the PDCM Insurance Data Breach


Class Action FAQ

A class action lawsuit is a case brought on behalf of a group of people who were harmed in a similar way by the same company or organization.

A class representative, sometimes called a named plaintiff or lead plaintiff, is a person who volunteers to bring the lawsuit on behalf of the larger group. They help represent the interests of everyone in the class. There may be more than one class representative in a class action.

A person who was harmed may start a class action if many other people were harmed in a similar way.

Usually, no. In many class action cases, the lawyers are paid only if the case is successful.

Sometimes you do not need to do anything. Other times, you may need to submit a claim form by a deadline to receive money or benefits.


Infographic summarizing the PDCM Insurance data breach, including the number of affected individuals, the categories of information involved, and the publicly confirmed reporting timeline.
PDCM Insurance data breach infographic summarizing the number of people affected, the types of information involved, and the publicly confirmed timeline. Information current as of September 29, 2026.


About This Data Breach Resource

This page was created to give affected individuals and researchers a clear, comprehensive explanation of the PDCM Insurance data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.

This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.

This page is especially relevant for readers searching for information about the PDCM Insurance data breach, PDCM Insurance data breach notice, PDCM Insurance class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.

Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.

The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.

For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?

This website is not associated with nor authorized by PDCM Insurance or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.