Particle.news
Download on the App Store

AdaptHealth Breach Exposes Data of 4.1 Million Patients

The intrusion exploited a third‑party privileged account, highlighting vendor access weaknesses.

Overview

  • AdaptHealth says attackers used social engineering to compromise a privileged account at a third‑party contractor on June 5, the company first learned of an extortion demand on June 15 and disclosed the incident in a July 2 SEC filing.
  • A submission to the U.S. Department of Health and Human Services lists 4,115,802 affected individuals whose stolen files may include names, contact and demographic details, health information, and health insurance data.
  • The company confirmed a password file tied to insurance billing was taken, a detail that increases the risk of credential reuse or insurance‑billing fraud even though AdaptHealth reports no detected misuse so far.
  • AdaptHealth has notified those impacted, offered 12 months of free credit monitoring and identity protection, and has reported the incident to HHS and the SEC as part of its response.
  • Reporting has linked the attack to the ShinyHunters group but public evidence of the group's extortion listing is unclear, a development that underscores growing threats to healthcare vendors and may push tighter vendor access controls across the sector.