AdaptHealth disclosed in a Form 8‑K filed July 2, 2026, that an unauthorized actor accessed multiple cloud‑based business applications after a social‑engineering attack compromised a third‑party contractor’s authenticated session. The company said the attacker exfiltrated patient data, including certain PII, PHI and stored password files related to insurance billing and external EHR portals. In a separate submission to the U.S. Department of Health and Human Services, AdaptHealth listed the incident as affecting 4,115,802 individuals.

Why it matters

  • Large healthcare data sets with PHI and billing credentials heighten risks of identity theft, fraud, and downstream attacks on providers and insurers.
  • Attackers exploiting third‑party contractor access underscore the need for stronger vendor session security and monitoring across cloud‑based health systems.