AdaptHealth (Nasdaq: AHCO), the US home medical equipment provider, has reported to the HHS Office for Civil Rights that a June 2026 cyberattack exposed personal and health information belonging to 4,115,802 people. Every source reviewed gives that same HHS figure, so the victim count is not in dispute. The attacker got in by socially engineering a third-party contractor, then used that access to reach AdaptHealth's cloud-based patient management and document storage systems. BleepingComputer attributes the intrusion to the ShinyHunters data-extortion group. AdaptHealth has not publicly named the actor. The company says Social Security numbers, payment card data and financial account information were not in the affected systems.
What Happened
The sources agree on this sequence of events:
- June 5, 2026: The intrusion began. AdaptHealth gave this date in its August 14 update (BleepingComputer), and TechJournal says it is also the "first known breach date" in the company's California consumer notice.
- June 15, 2026: A threat actor contacted AdaptHealth and said it had stolen files containing patient data. HIPAA Journal, citing the Form 8-K, describes this as a claim that data had been obtained. BleepingComputer describes it as a ransom demand in exchange for not leaking the data. Hexnode treats June 15 as the date AdaptHealth discovered the activity.
- June 27, 2026: AdaptHealth decided the incident was material because of "the nature and potential volume of data at risk" (Edelson Lechtzin, TechJournal).
- July 2, 2026: AdaptHealth disclosed the incident in an SEC Form 8-K. At that point it did not yet know which data types were involved or how many people were affected (HIPAA Journal).
- August 14, 2026: AdaptHealth published an update listing the exfiltrated data categories. SecurityWeek reports that the company notified HHS of the 4,115,802 figure at the same time. HHS listed the breach on its portal in the week of September 7.
Some accounts differ on the dates. BleepingComputer's headline calls it a "July cyberattack", but the body of its article, AdaptHealth's own filings and every other source place both the intrusion and the extortion contact in June. July is when the company disclosed it. GBlock says AdaptHealth notified HHS "in September". SecurityWeek says the notification was filed August 14 and only published on the portal in September. We give more weight to SecurityWeek's account.
AdaptHealth said it disabled the affected account, reset credentials, added access controls and brought in outside incident responders and law enforcement. It also said patient services were not disrupted (HIPAA Journal).
What Was Taken
In its August 14 notice, AdaptHealth said the attacker exfiltrated:
- Full names
- Contact information
- Demographic information
- Health insurance information
- Health information
- A stored password file tied to insurance billing
The company says Social Security numbers, financial account information and payment card data were not affected. HIPAA Journal adds that AdaptHealth says it does not collect patients' SSNs at all.
The 4.1 million figure should be read against the size of AdaptHealth's business. BleepingComputer notes that the company's website said it served about 4.1 million patients across all 50 states through 680 locations as of July 2024. That suggests the breach may cover most or all of its active patient base. AdaptHealth has not described it that way.
At the August update, AdaptHealth said it had found no evidence of identity theft or fraud (BleepingComputer). Edelson Lechtzin and GBlock report that ShinyHunters listed AdaptHealth on its leak site and threatened to publish the data. GBlock also reports that the listing was later removed and reads that as a sign of negotiation. These claims come only from OTHER-tier sources and remain unconfirmed. AdaptHealth has not said whether it paid or negotiated.
Why It Matters
- The data reveals diagnoses. GBlock makes the point that a durable medical equipment provider's customer list is effectively a list of conditions. A CPAP order points to sleep apnea, and an oxygen concentrator order points to respiratory disease. Combined with insurance details, that data can be used for highly convincing medical and insurance fraud and for targeted phishing, even without SSNs.
- The password file is a second-order risk. The stolen file relates to insurance billing. HIPAA Journal reports that the attacker also got access to external EHR portals. Any credentials in that file could let an attacker move into payer and partner systems beyond AdaptHealth's own environment.
- It fits a ShinyHunters pattern. If BleepingComputer's attribution holds, this is another case of the group using social engineering to get into cloud business applications and then extorting the victim, rather than deploying ransomware.
- It is one of the largest healthcare breaches of 2026. Becker's ranks it among the largest reported to HHS this year. SecurityWeek notes it went onto the HHS portal alongside Baylor Genetics (2.8M affected), which was also breached in June.
The Attack Technique
The sources agree on the broad outline: a social engineering attack against a third-party contractor, followed by use of that contractor's legitimate access to AdaptHealth's cloud applications. No malware or software exploit has been reported.
They describe the initial compromise differently:
- Becker's, SecurityWeek and Hexnode say a contractor's user session was compromised. That wording fits session hijacking or token theft, for example through a help-desk or MFA-fatigue lure.
- HIPAA Journal (citing the 8-K) says the contractor's credentials were obtained.
- BleepingComputer says a privileged account belonging to the contractor was compromised.
Session theft versus credential theft matters for defenders, because MFA alone does not stop session-token replay. AdaptHealth has not published technical detail that settles the question.
Once inside, the attacker reached internal patient management systems, document storage platforms and external EHR portals, and took the insurance billing password file (HIPAA Journal, Hexnode). GBlock claims that the stored billing password is what unlocked the external EHR portals. The primary-derived reporting lists the password file and the portal access as separate items and does not say one led to the other.
What Organizations Should Do
- Treat contractor identities as privileged by default. Put third-party accounts under the same conditional access, device compliance and MFA rules as employees. Scope them to the minimum set of applications, and set expiry dates on their access.
- Defend against session hijacking as well as password theft. Use phishing-resistant MFA (FIDO2), bind tokens to devices where the platform supports it, keep session lifetimes short, and alert on the same session appearing from a new IP address, ASN or device.
- Remove stored credential files. Move shared billing and portal passwords out of files and document stores into a secrets vault with access logging, and rotate everything that sat in reachable storage.
- Harden help-desk and identity recovery workflows. Require out-of-band identity verification before password or MFA resets, particularly for contractor and privileged accounts. This is the step ShinyHunters-style voice phishing targets.
- Monitor cloud applications for bulk data access. Set baselines for normal document and patient-record access, and alert on large exports, API-driven bulk downloads or access at unusual hours. Here the attacker had about 10 days before announcing itself.
- Plan for extortion-only incidents. Keep a playbook for data-theft extortion without encryption that covers legal, regulatory (HIPAA and SEC 8-K timing) and negotiation decisions, so they are not being made for the first time mid-incident.
Sources: AdaptHealth cyberattack exposes data of 4.1 million patients - Beck... | AdaptHealth confirms 4.1 million people exposed in July ... | AdaptHealth Data Breach Affects 4.1 Million Individuals | 4.1 Million Impacted by AdaptHealth Data Breach - SecurityWeek | AdaptHealth Data Breach: Cloud IAM Lessons | AdaptHealth Data Breach Affects 4.1 Million People | AdaptHealth Corp. Data Breach: Edelson Lechtzin LLP | AdaptHealth Breach Exposes 4.1M Patients' Health Data