2026 AdaptHealth — contractor social-engineering; HHS OCR 4,115,802 patients (ShinyHunters)
Data compromised
Full names, contact information, demographic information, health insurance information, and health information (Aug 14 company notice). Company previously stated SSNs and payment cards are not stored in the compromised systems. HHS OCR census: 4,115,802 individuals.
Technical writeup
Verified AdaptHealth / HHS OCR update — BleepingComputer September 9, 2026. AdaptHealth disclosed the June 2026 cloud intrusion via SEC 8-K (July) and patient notices (Aug 14): compromise dated June 5 via social-engineered contractor credentials; ransom demand June 15; ShinyHunters attributed in trade press. Data types: names, contact/demographic info, health insurance and health information; 12 months monitoring offered. HHS OCR breach portal lists 4,115,802 individuals. Catalog recordsAffected updated from 0 to 4115802; companyConfirmed true.
Root cause
Social-engineering of a third-party contractor; privileged credentials used to access AdaptHealth cloud patient-management, document storage, and EHR portal systems (ShinyHunters attributed)
References
- https://databreaches.net/2026/07/04/adapthealth-says-attackers-sweet-talked-their-way-into-cloud-systems-and-stole-patient-data/
- https://www.theregister.com/2026/07/03/adapthealth-crooks-stole-our-passwords-patient-health-data/
- https://www.sec.gov/Archives/edgar/data/1725255/000110465926080297/ahco-20260627x8k.htm
- https://www.hipaajournal.com/adapthealth-data-breach/
- https://www.securityweek.com/what-the-latest-shinyhunters-breaches-reveal-about-modern-cyberattacks/
- https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/
- https://adapthealth.com/blogs/notices/adapthealth-notice-of-cybersecurity-incident-1
- https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf