U.S. healthcare company AdaptHealth confirmed that a cyberattack resulted in the exposure of data belonging to 4,115,802 people, or approximately 4.1 million individuals. The company provides home medical equipment, supplies, and services, including equipment for treating sleep apnea, ventilatory support devices, oxygen therapy, hospital beds, and mobility products.
AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) dated July 2, 2026, explaining that attackers had gained access to its systems and extracted private data. A subsequent investigation showed that the breach began earlier and involved access to cloud-based business applications, internal patient-management systems, document-storage platforms, and portals for electronic health record systems.
What data was exposed?
In an update issued on August 14, the company said the breach occurred on June 5 and that the affected data may include:
- Full names and contact information.
- Demographic information.
- Health insurance information.
- Health information.
AdaptHealth explained that a threat actor contacted it on June 15 to demand a ransom in exchange for not publishing the stolen data. The company said the entry point was a social engineering campaign that successfully compromised a highly privileged account belonging to an external contractor.
According to the company’s website, AdaptHealth served approximately 4.1 million patients in all 50 U.S. states through a network of 680 locations, according to July 2024 data. The company also submitted a notification to the U.S. Department of Health and Human Services, which identified the number of affected individuals as 4,115,802.
ShinyHunters’ connection to the attack
A previous report by HIPAA Journal said that the ShinyHunters group was behind the attack, based on the group adding AdaptHealth’s name to its victim list. However, BleepingComputer did not find the company’s name on ShinyHunters’ extortion portal, suggesting that the group may have removed the listing later. Therefore, attribution of the attack to the group remains based on this indication, not on direct confirmation from AdaptHealth in the available information.
Why does this news matter?
The significance of the incident extends beyond the number of people affected, as the systems accessed by the attackers combine identifying, financial, and health data—categories that can increase the sensitivity of the impact of any leak on patients. The incident also demonstrates that compromising a highly privileged account belonging to an external contractor can provide a path to cloud applications and systems connected to patient management, even without indicating the exploitation of a specific software vulnerability.
AdaptHealth said it had found no evidence of identity theft, fraud, or misuse of the stolen data as of the time of its disclosure. It also stated that affected individuals were expected to have received notifications containing instructions for enrolling free of charge for 12 months in credit-monitoring and identity-theft protection services.
The confirmation of the incident’s scale comes after similar disclosures from healthcare and medical technology companies Aesto Health, CareCloud, and Unlimited Technology Systems. McKesson and Nutex Health also announced breach incidents late the previous month, without specifying the number of affected individuals by the time the report was published.