Skip to main content
Emerging ThreatsData Breaches

AdaptHealth Breach Exposes 4.1 Million Patients' Data

Hospital corridor with staff, patient rooms, and a blurred laptop screen on a nurse's station counter.

4.1 million people had personal data exposed after a June compromise of AdaptHealth systems, the company confirmed following an attack it first disclosed in a July SEC filing.

ShinyHunters and the extortion timeline

AdaptHealth said attackers accessed and exfiltrated private data and first reported the intrusion in a filing with the U.S. Securities and Exchange Commission on July 2, 2026. In an August 14 update the company said the compromise occurred on June 5, and that an unnamed threat actor contacted AdaptHealth on June 15 to demand a ransom in exchange for not leaking the stolen data. The HIPAA Journal reported that the ShinyHunters threat group was responsible based on that group adding AdaptHealth to its list of victims. BleepingComputer, however, later could not find an AdaptHealth entry on ShinyHunters’ extortion portal, an absence the outlet noted as an indication the threat actor removed the company from the portal.

How the attackers got in: social engineering of a third‑party privileged account

AdaptHealth attributed the breach to a successful social engineering ploy that compromised the privileged account of a third‑party contractor. The company’s investigation found the intrusion involved access to cloud‑based business applications, including certain internal patient management systems, document storage platforms, and electronic health record system portals.

Types of data exposed and notifications to affected people

In its August 14 update AdaptHealth said the breach may have exposed full names; contact information; demographic information; health insurance information; and health information. Impacted individuals should have already received a data breach notification with instructions on how to enroll in a free‑of‑charge 12‑month credit monitoring and identity protection service. AdaptHealth also stated that it had found no evidence of identity theft, fraud, or other misuse of data stolen in the attack.

Scale of impact and formal reporting

AdaptHealth’s own public materials note the company served about 4.1 million patients across all 50 U.S. states through a network of 680 locations as of July 2024. In a submission to the U.S. Department of Health and Human Services, AdaptHealth reported the data breach affects 4,115,802 individuals.

Related disclosures among health‑tech firms and defensive context

The confirmation of AdaptHealth’s breach followed similar recent disclosures from health‑tech firms Aesto Health, CareCloud, and Unlimited Technology Systems. McKesson and Nutex Health also disclosed data breach incidents late last month, though those companies had not determined the number of impacted individuals at the time of their disclosures. Separately, the Blue Report 2026 — cited in the same reporting — highlights a defensive challenge: “Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.” The Blue Report measures defenses technique‑by‑technique across 338 million simulations run in customer production environments, a statistic cited to illustrate how credential misuse changes the defensive calculus.

What this means for security teams, regulators, and affected patients

  • Security teams: The incident centers on social engineering against a third‑party privileged account and access to cloud‑based business applications and EHR portals—elements teams will watch in post‑incident reviews and supply‑chain risk assessments, especially given the Blue Report’s finding about credential‑based access.
  • Regulators and HHS: AdaptHealth has submitted a breach report to the U.S. Department of Health and Human Services documenting 4,115,802 affected individuals; that record is now part of regulators’ oversight of healthcare data security and breach notification compliance.
  • Affected patients: Impacted individuals should already have received notification and instructions to enroll in the free 12‑month credit monitoring and identity protection service AdaptHealth is offering; the company has reported no evidence to date of identity theft, fraud, or other misuse of the stolen data.

AdaptHealth’s disclosures establish a clear timeline—compromise on June 5, ransom contact on June 15, public SEC notification on July 2, and an August 14 update of exposed data—and a scope: roughly 4.1 million people and core healthcare and contact information. The company reports no confirmed misuse so far; independent reporting notes the listing and subsequent apparent removal from a threat actor portal. Whether that removal reflects a resolved extortion attempt, a change in the threat actor’s behavior, or simply the ebb and flow of criminal forums is a question the public record accompanying the breach does not answer.

Original story