← AdaptHealth

2026 AdaptHealth — ShinyHunters breach; contractor social-engineering; PHI exfiltrated (Jun)

2026 Unknown records affected Share on X

Data compromised

Exfiltrated patient PII and PHI from cloud business applications including internal patient-management systems and document storage; stored password file tied to insurance billing and external EHR portal access—specific data categories and victim count under investigation; company states SSNs and payment card data are not stored in compromised systems

Technical writeup

Verified material cybersecurity incident — disclosed via SEC Form 8-K July 2026. AdaptHealth Corp., a publicly traded home medical equipment and sleep/diabetes supply provider, reported that on June 15, 2026 a threat actor contacted the company claiming stolen patient files. Forensics determined certain cloud-based business applications were accessed, including internal patient-management systems and document storage platforms, with PII and PHI exfiltrated. AdaptHealth attributed the intrusion to social engineering of a third-party contractor that yielded contractor credentials, a stored insurance-billing password file, and access to external electronic health record portals; the affected account was disabled and credentials reset. Patient services were not disrupted; victim count and full data categories remained under review at catalog time. HIPAA Journal linked the incident to ShinyHunters leak-site extortion pressure.

Root cause

Social-engineering attack against a third-party contractor whose credentials accessed AdaptHealth cloud patient-management and document-storage systems; ShinyHunters extortion listing

References