AdaptHealth confirms 4.1 million people exposed in July cyberattack

Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group.
The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products.
AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data.
At the time, AdaptHealth’s investigation confirmed the intrusion occurred earlier and involved access to cloud-based business applications, including certain internal patient management systems, document storage platforms, and electronic health record system portals.
On June 15, an unnamed threat actor contacted AdaptHealth to demand a ransom payment in exchange for not leaking the stolen data.
AdaptHealth added that the breach occurred through a successful social engineering ploy that compromised the privileged account of a third-party contractor.
In an update on August 14, AdaptHealth informed that the compromise had occurred on June 5 and may have exposed the following data:
- Full names
- Contact information
- Demographic information
- Health insurance information
- Health information
Impacted individuals should have already received a data breach notification with instructions on how to enroll in a free-of-charge 12-month credit monitoring and identity protection service.
AdaptHealth stated at the time that it had found no evidence of identity theft, fraud, or other misuse of data stolen in the attack.
According to information on the company’s website, AdaptHealth served about 4.1 million patients across all 50 U.S. states through a network of 680 locations as of July 2024.
In a submission to the U.S. Department of Health and Human Services, the AdaptHealth data breach affects 4,115,802 individuals.
The HIPAA Journal previously reported that ShinyHunters was responsible for the attack, based on the threat actor adding the company to the list of victims.
However, BleepingComputer coould not find an AdaptHealth entry on ShinyHunter's extortion portal, an indication that the threat actor removed the company.
AdaptHealth's confirmation of the data breach impact follows similar recent disclosures from health-tech firms Aesto Health, CareCloud, and Unlimited Technology Systems.
McKesson and Nutex Health also disclosed data breach incidents late last month, but neither has determined the number of impacted individuals yet.
References in this story
- adapthealth.com
- adapthealth.com
- U.S. Department of Health & Human Services - Office for Civil Rights ocrportal.hhs.gov
- AdaptHealth Reports Material Cybersecurity Incident and Theft of Patient Data www.hipaajournal.com AdaptHealth, a publicly traded healthcare company that provides home medical equipment, diabetes supplies, and sleep therapy products, has informed theThe medical equipment provider AdaptHealth has announced a material…
- Aesto Health says data breach affects over 9.5 million patients www.bleepingcomputer.com Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals.
- Healthtech firm CareCloud data breach impacts 3.7 million patients www.bleepingcomputer.com U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals.
- Unlimited Technology Systems breach impacts 3.8 million people www.bleepingcomputer.com Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.
- McKesson discloses breach after ShinyHunters claims patient data theft www.bleepingcomputer.com Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming…
- Hospital operator Nutex Health says data stolen in cyberattack www.bleepingcomputer.com Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers.



