4.1 M Individuals Affected by AdaptHealth Data Breach

by | Sep 14, 2026 | Healthcare Industry News

AdaptHealth has reported that a June 2026 cybersecurity incident compromised the electronic protected health information (ePHI) of 4,115,802 individuals.

Scope of the Data Breach

The incident involved unauthorized access to certain cloud-based business applications used by AdaptHealth, including internal patient management systems and document storage platforms. The company reporte

d that files containing personally identifiable information and protected health information were exfiltrated.

AdaptHealth initially notified the U.S. Securities and Exchange Commission that it was investigating a cybersecurity incident that involve unauthorized access to patient records. At that time, the company had not determined the number of individuals affected or the types of patient data involved.

The HHS Office for Civil Rights has since been informed that ePHI belonging to 4,115,802 individuals was compromised.

Date and Nature of the Cybersecurity Incident

AdaptHealth’s forensic investigation determined that the attack occurred on June 5, 2026. The investigation found that the threat actor exfiltrated files containing names, contact information, demographic information, health insurance information, and health information.

AdaptHealth reported that the cause of the unauthorized access was a social engineering attack by a third-party vendor. The attack allowed the threat actor to get the contractor’s credentials. The threat actor also got the information to access insurance billing and electronic health record portals.

AdaptHealth deactivated the affected account, changed credentials, and applied extra access controls. Despite the incident, the company’s operations or patient services were not affected.

Patient Information Involved

The compromised files contained names, contact information, demographic information, health insurance information, and health information.

AdaptHealth stated that it does not collect patients’ Social Security numbers. The company also stated that financial account information and payment card information were not stored in the compromised systems.

The company reported that it was unaware of any actual or attempted misuse of the compromised information.

Investigation and Response

AdaptHealth launched an investigation after the attacker contacted the company on June 15, 2026, claiming to have obtained files with patient records. The company hired cybersecurity experts and sent breach notification to law enforcement.

The investigation initially remained ongoing while AdaptHealth worked to determine the extent of the data theft. The company later reported the affected population to the HHS Office for Civil Rights as 4,115,802 individuals.

AdaptHealth has offered affected individuals complimentary credit monitoring and identity theft protection services for 12 months as a precaution.

The company also reported that the financial impact of the incident remained under assessment. Potential costs identified by AdaptHealth included forensic investigation, breach notification, legal and regulatory responses, and remediation measures.

Threat Actor Information

AdaptHealth did not name the threat actor responsible for the incident.

The HIPAA Journal reported that the incident appeared to involve ShinyHunters and described the activity as a data theft and extortion attempt. The report stated that ShinyHunters had added AdaptHealth to its data leak site and threatened to release the stolen information if a ransom was not paid.

The HIPAA Journal later reported that there was no current listing for AdaptHealth on the ShinyHunters data leak site and stated that the entry appeared to have been removed.

Regulatory Reporting

AdaptHealth’s initial disclosure to the U.S. Securities and Exchange Commission occurred before the company had determined the number of individuals affected. The subsequent report to the HHS Office for Civil Rights identified 4,115,802 individuals whose electronic protected health information was compromised.

The reported information includes patient names, contact information, demographic information, health insurance information, and health information.

The incident involved unauthorized access to cloud-based business applications, exfiltration of patient information, and compromised credentials associated with a third-party contractor.

AdaptHealth reported that affected accounts were disabled, credentials were reset, and additional access controls were implemented following the incident.

Stay Informed

Subscribe To Our Newsletter To Receive Healthcare Industry News Via Email

View our privacy policy

Categories