
AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
The US home medical equipment provider told federal health regulators that 4,115,802 people had data exfiltrated after an attacker socially engineered access through a third-party contractor.
01 / What happened
AdaptHealth, a US provider of home medical equipment and supplies such as sleep-apnea and respiratory devices, oxygen therapy and mobility products, has reported to the US Department of Health and Human Services (HHS) that a cyberattack affected 4,115,802 individuals, according to BleepingComputer and HIPAA Journal, which reported the filing on 9 and 10 September 2026.
The company first disclosed the incident in a Form 8-K under Item 1.05 (material cybersecurity incidents), signed on 2 July 2026. In that filing, AdaptHealth said it received a communication on 15 June from a threat actor claiming to hold company data, and determined on 27 June that the incident was material given the nature and potential volume of data at risk. A later notice on the company's website, dated 14 August, places the attack itself on 5 June 2026.
According to the 8-K, the attacker used a successful social engineering attack to compromise a user session associated with a third-party contractor, then reached cloud-based business applications, including internal patient management systems, document storage platforms and portals to external electronic health record systems. The company said it disabled the account, reset credentials, added access controls and considers the incident contained.
02 / Why it matters
The incident fits a pattern of intrusions that bypass technical controls by targeting people with privileged access, particularly at suppliers and contractors whose accounts reach into cloud applications. For a healthcare provider, that route led directly to protected health information at scale.
A single contractor session was enough to reach systems holding data on millions of patients.
AdaptHealth said in the 8-K that the incident had not materially affected operations or its ability to serve patients, and that the financial impact had not yet been determined.
03 / Who is exposed
The company's 14 August notice says the exfiltrated files contained:
- Names and contact information
- Demographic information
- Health insurance information
- Health information
The 8-K also cites passwords associated with insurance billing. AdaptHealth says Social Security numbers, financial account data and payment card data were not involved, as it does not keep them in the affected systems. BleepingComputer notes that the total is close to the company's entire reported patient base.
04 / Confirmed vs. claimed
Confirmed (company filings and notice): attack on 5 June 2026; extortion contact on 15 June; materiality determined 27 June; entry via social engineering of a third-party contractor's session; data categories listed above; 4,115,802 individuals reported to HHS; 12 months of free credit monitoring and identity protection offered; law enforcement notified.
Claimed / unconfirmed: HIPAA Journal attributes the attack to the ShinyHunters extortion group, which it reported had listed AdaptHealth on its leak site. BleepingComputer said it could not find the entry on the group's portal, suggesting it had been removed. AdaptHealth has not publicly named the attacker. The company says it has found no evidence of misuse of the data.
05 / What to do now
- Patients who receive a notification letter should enrol in the offered credit monitoring and identity protection service and use the company's dedicated support line listed in its notice.
- Watch for phishing that references AdaptHealth, insurance claims or medical equipment orders; stolen contact and insurance details make such lures more convincing.
- Review explanation-of-benefits statements from insurers for services you did not receive.
- Organisations should review how contractor and vendor accounts authenticate to cloud applications, require phishing-resistant multi-factor authentication for privileged sessions, and train help-desk staff to verify identity before resetting credentials.
Source log / 2026-0909-AH
- AdaptHealth Corp. — Form 8-K, Item 1.05 Material Cybersecurity Incidents (2 July 2026) Primary
- AdaptHealth — Notice of Cybersecurity Incident (14 August 2026) Primary
- BleepingComputer — AdaptHealth confirms 4.1 million people exposed in July cyberattack (9 September 2026) Secondary
- HIPAA Journal — AdaptHealth Data Breach Affects 4.1 Million Individuals (10 September 2026) Secondary