iRhythm found the intrusion on June 8 and heard from the attacker the next day. The target was third-party-hosted business applications, reached through social engineering, and the take included protected health information, personal information and proprietary company data. A payment demand followed, with publication of the stolen material as the threat.
The cardiac monitoring company reports no impact to products, clinical or device systems, manufacturing or its connections to customers, and no financial account or card data in the stolen set because it does not store any.
The lesson for device makers: the breach surface includes every SaaS vendor that holds your data, and the extortion letter still arrives addressed to you.