Home Medical Equipment Provider Confirms Major Breach
AdaptHealth, a major U.S. provider of home-based medical equipment, has confirmed that a cyberattack discovered in July exposed the personal and health information of 4,115,802 people. The intrusion is linked to the ShinyHunters extortion group, part of a broader wave of social-engineering-driven attacks hitting healthcare organizations in 2026.
How the Attackers Got In
According to the breach timeline, the intrusion began on June 5 when attackers used a social engineering scheme against a third-party contractor's account to gain a foothold, rather than exploiting a technical vulnerability. From there, the threat actor moved into AdaptHealth's cloud environment and reached several cloud-based business applications, including:
- Internal patient management systems
- Document storage platforms
- Certain external electronic health record (EHR) portals
AdaptHealth disclosed the incident in a Form 8-K filed with the SEC on July 2, describing it as a material cybersecurity incident.
What Was Exposed
The exposed data may include patients' names, contact details, insurance information, and health information. AdaptHealth has not publicly named the threat actor, but ShinyHunters added the company to its data leak site and threatened to publish the stolen data if a ransom wasn't paid. The company was later removed from ShinyHunters' extortion portal listing, which may indicate a resolution behind the scenes — though AdaptHealth has not confirmed payment.
Company Response
AdaptHealth says it has:
- Notified affected individuals and offered free credit monitoring
- Found no evidence of identity theft or fraud stemming from the incident so far
- Taken steps to reduce the risk of further dissemination of the stolen data
- Confirmed the incident has not disrupted patient care operations
The company is still assessing the full financial impact, including incident response, legal and regulatory obligations, and notification costs — though it noted cybersecurity insurance may offset some of that exposure. Multiple U.S. law firms have opened investigations into potential class-action litigation, though none have yet been certified.
Part of a Larger Healthcare Targeting Wave
This breach adds to a growing pattern of identity-based social engineering attacks against healthcare organizations in 2026. ShinyHunters has also been linked to a far larger intrusion at healthcare distributor McKesson, where the group claims to have exfiltrated roughly 1 TB of data — around 284 million records, though not necessarily unique patients. Both incidents underscore how attackers are increasingly bypassing technical defenses entirely by targeting contractors and third-party accounts with access to cloud environments.
Recommendations
- Healthcare organizations should extend phishing-resistant MFA and access reviews to third-party contractor accounts, not just employees
- Audit cloud application access logs for anomalous activity tied to vendor or contractor credentials
- AdaptHealth patients should monitor for phishing attempts referencing this breach and enroll in the offered credit monitoring
- Treat unsolicited calls or emails referencing "AdaptHealth" or "account verification" with suspicion — verify through official channels only