AdaptHealth has confirmed that 4.1 million people had their information exposed in a cyberattack that the company discovered in July. The healthcare provider, which supplies home medical equipment and related services, said the intrusion involved a third-party contractor's privileged account that was compromised through a social engineering scheme. The ShinyHunters threat group has been linked to the attack.

According to a filing AdaptHealth submitted to the U.S. Securities and Exchange Commission on July 2, 2026, attackers gained access to its systems and took private data. The company's investigation determined the breach happened earlier and touched cloud-based business applications, among them certain internal patient management systems, document storage platforms, and electronic health record system portals. AdaptHealth provides sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products.

AdaptHealth said an unnamed threat actor reached out on June 15 to demand a ransom in return for keeping the stolen data from being leaked. In an August 14 update, the company reported that the compromise took place on June 5. Notifications were sent to affected individuals with instructions for signing up for a free 12-month credit monitoring and identity protection service, and AdaptHealth said it had uncovered no signs of identity theft, fraud, or other misuse of the stolen data.

A submission to the U.S. Department of Health and Human Services lists 4,115,802 individuals as affected by the AdaptHealth breach. Information on the company's website states that it served roughly 4.1 million patients across all 50 U.S. states through a network of 680 locations as of July 2024. The HIPAA Journal had earlier reported that ShinyHunters carried out the attack after the group added AdaptHealth to its list of victims, though BleepingComputer could not locate an AdaptHealth entry on the group's extortion portal, suggesting it had been removed.

The confirmation from AdaptHealth comes after a string of similar disclosures from other health-tech firms, including Aesto Health, CareCloud, and Unlimited Technology Systems. McKesson and Nutex Health also reported data breach incidents late last month, but neither has established how many individuals were impacted.

More cybersecurity news from TechManNews.