Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.
The incident, which iRhythm detected on June 8, involved unauthorized access to third-party-hosted business applications. An investigation revealed that the attackers maintained access to company systems between June 3 and June 8, gaining entry through a social engineering attack.
According to iRhythm's filings, 298,647 individuals in Texas and 69,526 in South Carolina had their information compromised. The company also filed notices in California, though a spokesperson declined to provide the total number of affected individuals globally.
The exfiltrated data includes names, addresses, phone numbers, iRhythm patient account numbers, iRhythm device serial numbers, patient insurance numbers, dates of service, and dates of birth. While the company confirmed that data was downloaded, it stated there is "no evidence that any personal information has been or will be used to commit identity theft."
iRhythm clarified that the cyberattack did not impact its clinical systems, medical devices, manufacturing processes, or distribution operations, nor did it result in any loss of service or disruption to its business operations or finances.
In a June 8-K filing with the Securities and Exchange Commission (SEC), iRhythm disclosed that it "received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information." The threat actor demanded payment in exchange for not publicly disclosing this information, and iRhythm has since confirmed that certain data was exfiltrated from the affected applications. No hacking group has publicly claimed responsibility for the attack.
The incident highlights a continuing trend of cyberattacks targeting medical device companies. Over the past two years, numerous firms in the sector, including Medtronic, Boston Scientific, Stryker, UFP, Masimo, Surmodics, Artivion, and Zoll, have experienced cybersecurity incidents, leading to the exposure of sensitive medical data and, in some cases, supply chain disruptions.






