AdaptHealth confirms data of 4.1 million patients stolen in July breach
AdaptHealth told the SEC on July 2 that a social‑engineering compromise of a third‑party session led to exfiltration of PII, PHI and billing password files; a DHHS filing lists 4,115,802 affected individuals.
AdaptHealth disclosed in a Form 8‑K filed July 2, 2026, that an unauthorized actor accessed multiple cloud‑based business applications after a social‑engineering attack compromised a third‑party contractor’s authenticated session. The company said the attacker exfiltrated patient data, including certain PII, PHI and stored password files related to insurance billing and external EHR portals. In a separate submission to the U.S. Department of Health and Human Services, AdaptHealth listed the incident as affecting 4,115,802 individuals.
Why it matters
- Large healthcare data sets with PHI and billing credentials heighten risks of identity theft, fraud, and downstream attacks on providers and insurers.
- Attackers exploiting third‑party contractor access underscore the need for stronger vendor session security and monitoring across cloud‑based health systems.
Sources
Check the original material below. How we use sources