AdaptHealth, a provider of home medical devices and services, has confirmed that a cyberattack discovered in July exposed the data of 4.1 million individuals. The company offers a range of equipment and services, including those for sleep apnea, respiratory care, oxygen therapy, hospital beds, and mobility.
The incident was initially disclosed by AdaptHealth in a U.S. Securities and Exchange Commission (SEC) filing on July 2, 2026. At that time, the company reported that attackers had accessed its systems and exfiltrated private data. The investigation confirmed that the intrusion occurred earlier and involved access to cloud-based business applications, including internal patient management systems, document storage platforms, and electronic health record system portals.
On June 15, an unidentified threat actor contacted AdaptHealth, demanding a ransom payment to prevent the leakage of the stolen data. AdaptHealth stated that the breach was a result of a successful social engineering tactic that compromised a privileged account belonging to a third-party contractor.
An update on August 14 specified that the compromise took place on June 5. The exposed data potentially includes full names, contact information, demographic details, health insurance information, and general health information.
AdaptHealth has begun sending data breach notifications to affected individuals, which include instructions for enrolling in a complimentary 12-month credit monitoring and identity protection service. The company has stated that as of its last update, there was no evidence of identity theft, fraud, or other misuse of the stolen data.
According to information on AdaptHealth's website, as of July 2024, the company served approximately 4.1 million patients across all 50 U.S. states through a network of 680 locations. A submission to the U.S. Department of Health and Human Services indicates that the breach specifically affects 4,115,802 individuals.
While the ShinyHunters threat group was previously linked to the attack based on claims of adding AdaptHealth to their list of victims, the company's entry could not be found on ShinyHunters' extortion portal, suggesting it may have been removed.
This disclosure from AdaptHealth follows similar recent reports from other health-tech firms. Aesto Health, CareCloud, and Unlimited Technology Systems have also confirmed data breaches. Additionally, McKesson and Nutex Health disclosed incidents late last month, though they have not yet determined the number of impacted individuals.






