AdaptHealth data breach exposes 4.1 million patients' health information
US home medical equipment provider AdaptHealth confirmed that a June cyberattack exposed the personal, health, and insurance data of over 4.1 million individuals. The breach, attributed to the ShinyHunters group per The HIPAA Journal, occurred via a social engineering attack on a third-party contractor. No financial data or Social Security numbers were compromised, the company said.
Bottom line — The breach affects 4,115,802 individuals across all 50 US states, per AdaptHealth's filing with HHS.
Go deeper (7)
- The attacker gained access on June 5 and exfiltrated names, contact and demographic info, health insurance details, and health information, per AdaptHealth's notice.
- AdaptHealth said the breach resulted from a successful social engineering attack that compromised a user session at a third-party contractor, per BleepingComputer.
- The threat actor contacted AdaptHealth on June 15 demanding a ransom, per the company's SEC filing.
- The HIPAA Journal reported that ShinyHunters added AdaptHealth to its data leak site but later removed the listing, suggesting a ransom may have been paid.
- AdaptHealth operates over 680 facilities across the US and served about 4.1 million patients as of July 2024, per BleepingComputer.
- Affected individuals are being offered 12 months of free credit monitoring and identity protection services through Kroll, per Claim Depot.
- The breach is one of several recent healthcare incidents; Aesto Health reported 9.5 million affected and CareCloud 3.7 million, per BleepingComputer.