AdaptHealth told the SEC on July 2 that attackers stole patient data from its cloud systems. The home medical equipment supplier learned of the theft on June 15, when the threat actor contacted the company claiming to hold the data. A social engineering attack had compromised a third-party contractor's user session.
The intruders reached cloud business applications, including internal patient management systems and document storage platforms. They also obtained a stored password file tied to insurance billing, plus access to external electronic health record portals. Exfiltrated records include personally identifiable information and protected health information. The company says Social Security numbers, financial account details, and payment card data are not stored in the compromised systems.
AdaptHealth determined the incident was material on June 27 and filed its Form 8-K the following week. The company disabled the compromised account, reset credentials, added access controls, brought in outside forensic teams, and notified law enforcement. It carries cybersecurity insurance that may cover part of the cost. The number of affected people has not been disclosed.
HIPAA Journal reports the ShinyHunters group claimed the theft and added AdaptHealth to its leak site, threatening publication unless the company paid. The same name surfaced in the April intrusion at Medtronic, which led to notifications for 3,834,294 people per state attorney general filings.
AdaptHealth supplies CPAP machines, continuous glucose monitors, and insulin pumps to patients at home, which makes it a dense aggregation point for device-linked health records. Suppliers of connected home devices hold clinical data at manufacturer scale without a manufacturer's security budget. A contractor session that can open a stored password file is an access design failure, and no phishing training fixes that.