← Blog

AdaptHealth Breach: PHI Stolen via Social Engineering

Share on X

June 15, 2026: AdaptHealth Corp. (NASDAQ: AHCO), one of the largest U.S. suppliers of home medical equipment, told the SEC it is investigating a material cybersecurity incident after a threat actor claimed stolen patient files. Forensics confirmed PII and PHI were exfiltrated from cloud business applications following a social-engineering attack on a third-party contractor.

What happened

On June 15, an extortionist contacted AdaptHealth saying they had company data. Investigators found the actor had reached internal patient-management systems, document storage, a password file tied to insurance billing, and portals into external electronic health record systems — all through credentials tied to a contractor account that fell for social engineering.

AdaptHealth disabled the account, reset credentials, added access controls, and engaged law enforcement. Patient deliveries and clinical services kept running; this was a confidentiality breach, not a shutdown of CPAP or glucose-monitor supply chains.

What data was involved

The company has not finished scoping every field or patient count. AdaptHealth states it does not store Social Security numbers, payment cards, or bank accounts in the compromised cloud apps — reducing pure financial-fraud risk but not eliminating medical identity threats from PHI.

Home medical equipment patients often do not think of themselves as “healthcare breach victims” because their interaction is a mail-order CPAP mask or diabetes supplies. The stolen billing passwords and EHR portal access suggest attackers were hunting reimbursement and chart data, not warehouse inventory.

Who is at risk

Anyone who received home medical equipment, sleep therapy, or diabetes supplies through AdaptHealth or its hospital and physician partners during the access window could be in scope once notifications go out. ShinyHunters pressure appeared in trade reporting linked to the same incident timeline.

Action items

  1. Watch for AdaptHealth or insurer letters — verify through official channels before calling numbers in unsolicited email.
  2. Review Explanation of Benefits for DME charges you did not receive.
  3. Report suspicious CPAP or supply-order calls asking for Medicare or insurance IDs.
  4. Enable MFA on any patient portal your DME provider uses.

Canonical record: AdaptHealth 2026 breach on BreachHistory.