2026 AdaptHealth — ShinyHunters breach; contractor social-engineering; PHI exfiltrated (Jun)
Data compromised
Exfiltrated patient PII and PHI from cloud business applications including internal patient-management systems and document storage; stored password file tied to insurance billing and external EHR portal access—specific data categories and victim count under investigation; company states SSNs and payment card data are not stored in compromised systems
Technical writeup
Verified material cybersecurity incident — disclosed via SEC Form 8-K July 2026. AdaptHealth Corp., a publicly traded home medical equipment and sleep/diabetes supply provider, reported that on June 15, 2026 a threat actor contacted the company claiming stolen patient files. Forensics determined certain cloud-based business applications were accessed, including internal patient-management systems and document storage platforms, with PII and PHI exfiltrated. AdaptHealth attributed the intrusion to social engineering of a third-party contractor that yielded contractor credentials, a stored insurance-billing password file, and access to external electronic health record portals; the affected account was disabled and credentials reset. Patient services were not disrupted; victim count and full data categories remained under review at catalog time. HIPAA Journal linked the incident to ShinyHunters leak-site extortion pressure.
Root cause
Social-engineering attack against a third-party contractor whose credentials accessed AdaptHealth cloud patient-management and document-storage systems; ShinyHunters extortion listing
References
- https://databreaches.net/2026/07/04/adapthealth-says-attackers-sweet-talked-their-way-into-cloud-systems-and-stole-patient-data/
- https://www.theregister.com/2026/07/03/adapthealth-crooks-stole-our-passwords-patient-health-data/
- https://www.sec.gov/Archives/edgar/data/1725255/000110465926080297/ahco-20260627x8k.htm
- https://www.hipaajournal.com/adapthealth-data-breach/
- https://www.securityweek.com/what-the-latest-shinyhunters-breaches-reveal-about-modern-cyberattacks/