Overview
- AdaptHealth says attackers used social engineering to compromise a privileged account at a third‑party contractor on June 5, the company first learned of an extortion demand on June 15 and disclosed the incident in a July 2 SEC filing.
- A submission to the U.S. Department of Health and Human Services lists 4,115,802 affected individuals whose stolen files may include names, contact and demographic details, health information, and health insurance data.
- The company confirmed a password file tied to insurance billing was taken, a detail that increases the risk of credential reuse or insurance‑billing fraud even though AdaptHealth reports no detected misuse so far.
- AdaptHealth has notified those impacted, offered 12 months of free credit monitoring and identity protection, and has reported the incident to HHS and the SEC as part of its response.
- Reporting has linked the attack to the ShinyHunters group but public evidence of the group's extortion listing is unclear, a development that underscores growing threats to healthcare vendors and may push tighter vendor access controls across the sector.