AdaptHealth Confirms 4.1 Million Patients Exposed in Cyberattack That Began With a Contractor Account

AdaptHealth Confirms 4.1 Million Patients Exposed in Cyberattack That Began With a Contractor Account

AdaptHealth Confirms 4.1 Million Patients Exposed in Cyberattack That Began With a Contractor Account

Home medical equipment provider AdaptHealth has confirmed that the personal and health data of 4,115,802 people was exposed in a cyberattack first disclosed in July. In a filing to the U.S. Department of Health and Human Services, the company put a precise number on a breach that highlights a risk most organizations still underestimate: the privileged accounts of third-party contractors.

The Timeline

AdaptHealth, which supplies sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products through roughly 680 locations across all 50 U.S. states, first disclosed the incident to the SEC on July 2, 2026. The company's investigation later established that the compromise occurred on June 5. On June 15, an unnamed threat actor contacted AdaptHealth demanding ransom in exchange for not leaking the stolen data.

According to the company, the breach began with a social engineering attack that compromised the privileged account of a third-party contractor. From there, the attackers reached cloud-based business applications — including internal patient management systems, document storage platforms, and electronic health record portals — and exfiltrated full names, contact information, demographic details, health insurance information, and health information. AdaptHealth says it has found no evidence of identity theft or fraud using the stolen data so far, and is offering impacted individuals 12 months of free credit monitoring and identity protection.

Part of a Larger Healthcare Wave

The confirmation lands amid a wave of healthcare-sector breaches: Aesto Health recently reported more than 95 million patients affected, CareCloud 37 million, and Unlimited Technology Systems 38 million, while McKesson and Nutex Health disclosed incidents affecting still-undetermined numbers. HIPAA Journal previously reported that the ShinyHunters group listed AdaptHealth as a victim, although the entry no longer appears on the group's extortion portal.

What Should You Do?

  1. Treat contractor accounts as part of your attack surface. A privileged third-party account is indistinguishable from your own privileged account to the systems it can reach — apply the same multi-factor authentication, conditional access, and session monitoring to it.
  2. Verify identity out-of-band before privileged actions. Social engineering defeated the human layer here; a mandatory callback or independent verification workflow for credential resets and sensitive requests stops many of these campaigns cold.
  3. Monitor cloud application behavior, not just logins. Bulk data movement through patient management and document storage platforms is the signature of this breach — set volume and anomaly alerts on data exports.
  4. Prepare the compliance path now. HIPAA notification duties, SEC disclosure timelines, and affected-individual counts go more smoothly when incident response plans already include legal and regulatory steps.

The WAF Angle

Nothing in this breach involved an exploit a WAF would block — a valid privileged account, gained through social engineering, walked through the front door of cloud applications. That is exactly why perimeter controls need behavioral reinforcement at the API layer: per-tenant rate limits, impossible-travel checks, and anomalous data-volume detection on document and EHR portals shrink what a stolen credential can accomplish. When your attack surface includes contractors, your defense-in-depth model has to assume some of those doors will open — and engineer the blast radius down accordingly.

Sources