NEWS

iRhythm Breach Notifications Reveal At Least 360,000 Patients Affected

iRhythm has begun formally notifying states about its June 2026 breach, confirming at least 360,000 patients affected in Texas and South Carolina alone.

Dylan H.

News Desk

October 10, 2026
7 min read
iRhythm Breach Notifications Reveal At Least 360,000 Patients Affected

iRhythm's Summer Breach Gets a Number — And It's Hundreds of Thousands

Cardiac-monitoring wearable maker iRhythm Technologies has begun formally notifying state attorneys general about the scope of the data breach it first disclosed back in June 2026, and the filings put hard numbers behind what had previously been an open question: at least 360,000 patients had their information stolen, with 298,647 affected in Texas alone and another 69,526 in South Carolina, according to breach notification filings reported by The Record. CosmicBytez Labs covered the original disclosure in June (see "iRhythm Confirms Patient Data Stolen in Ransomware Attack" and "iRhythm Discloses Data Breach, Hackers Stole Patient Information"); this is the follow-up with the figures regulators and affected patients had been waiting on for nearly four months.


Incident Details

AttributeValue
CompanyiRhythm Technologies (maker of the Zio cardiac monitoring patch)
Unauthorized access windowJune 3 – June 8, 2026
Breach discoveredJune 8, 2026
Threat actor ransom contactJune 9, 2026
Declared material (SEC Form 8-K)June 10, 2026
Attack vectorSocial engineering targeting third-party-hosted business applications
Forensic investigation completed / notifications beganOctober 2, 2026
State filings became publicOctober 6 – 9, 2026
Confirmed affected — Texas298,647 residents
Confirmed affected — South Carolina69,526 residents
Combined confirmed minimumMore than 360,000 individuals
States/offices that received notice filingsCalifornia, Texas, South Carolina, and additional states per filing trackers

What Happened — A Recap

As CosmicBytez Labs reported in June, iRhythm detected unauthorized access to its systems on June 8, 2026. The access window was later pinned down to June 3–8, 2026. The following day, a threat actor contacted the company claiming to possess stolen data and demanding a ransom payment to prevent its public disclosure — a classic double-extortion play. iRhythm confirmed data had been exfiltrated and declared the incident material in an SEC Form 8-K filed June 10, 2026.

Critically, the intrusion did not touch iRhythm's own core network. The company has consistently described the entry point as third-party-hosted business applications, reached via a social engineering attack rather than a direct compromise of iRhythm's clinical or device infrastructure. iRhythm has reiterated that its clinical systems, medical devices, and patient-facing services were not affected and that operations continued without disruption.

What's New: The Notification Filings

What changed this week is scale. iRhythm completed its forensic investigation and began sending notification letters to affected individuals on October 2, 2026 — nearly four months after the breach was first discovered. As part of that process, the company filed the regulatory paperwork that U.S. breach-notification laws require once more than a set threshold of residents in a given state is affected, and those filings are now public.

A filing with the Texas Attorney General's office, published October 6, 2026, lists 298,647 Texans as affected. A separate filing adds 69,526 affected individuals in South Carolina. iRhythm also filed a notice with the California Department of Justice, dated October 6, 2026, listing the same June 3 – June 8, 2026 breach window. Taken together, the confirmed state-by-state totals already exceed 360,000 people — and that figure only reflects the states whose individual filings have been reported publicly so far, not a company-confirmed nationwide total.

Some breach-tracking aggregators have floated a much larger figure, in the millions, extrapolated from iRhythm's broader patient base of roughly 8 million users across the U.S. and Europe. CosmicBytez Labs is treating that larger number with caution: it has not been confirmed by iRhythm or verified in a specific regulatory filing, and a company spokesperson told Recorded Future News it would not confirm a full victim count, saying only that iRhythm "responded promptly after detecting the unauthorized access and, once the scope was verified, notified affected individuals and applicable regulators." The verified, documented figure remains the combined state total of more than 360,000.

Data Exposed

The Texas filing lists the following categories of compromised information:

  • Names
  • Addresses
  • Dates of birth
  • Medical information
  • Health insurance information

Broader reporting on the notification letters adds additional data elements consistent across the filings, including phone numbers, iRhythm patient account numbers, iRhythm device serial numbers, patient insurance numbers, and dates of service. iRhythm's original June disclosure also referenced Social Security numbers for a subset of affected individuals, though the state filings reviewed for this update emphasize the healthcare- and device-specific data categories above rather than confirming SSN exposure in every jurisdiction. The company has repeatedly stated that no payment card or financial account data was involved, and that its clinical and medical-device systems were not affected.

Why the Four-Month Gap

The roughly four-month span between the SEC's June 10 materiality disclosure and the October 2 start of individual notifications is longer than some healthcare breach timelines, though it is not unusual for incidents requiring a full forensic scoping effort before notification. Under HIPAA, covered entities and their business associates must notify affected individuals within 60 days of determining a breach has occurred — a clock that starts once the investigation establishes the scope, not at initial discovery. iRhythm's public statements indicate the delay reflects the time needed to verify exactly which records were affected across the compromised third-party applications before notification letters could be finalized.

California's breach-notification statute adds a further wrinkle relevant to this case: under amendments effective January 1, 2026, companies notifying more than 500 California residents must also submit a sample notice to the California Attorney General within 15 days of notifying those residents — which lines up with iRhythm's filings landing in the same window as its October notification mailing.


Why This Matters

  1. Healthcare breach scope is routinely learned in pieces. As with other 2026 healthcare incidents (including the Oracle Health/Cerner breach, whose scope climbed from state-level estimates to nearly 20 million people), individual state AG filings only report residents of that state — meaning the true national total for iRhythm is likely higher than the 360,000+ currently confirmed, and may not be fully known for some time.
  2. Third-party SaaS applications remain a primary healthcare attack surface. iRhythm's own clinical systems and devices were not touched; the exposure came entirely through externally hosted business applications reached via social engineering — a reminder that vendor and SaaS risk management deserves the same scrutiny as core infrastructure.
  3. Social engineering, not a technical exploit, started this breach. Staff training on recognizing pretexting and credential-harvesting attempts against third-party application access remains one of the highest-leverage controls against this entry vector.
  4. Affected patients should watch for medical identity theft, not just financial fraud. With medical information, insurance details, device serial numbers, and dates of birth confirmed in the exposed data, patients should review insurance explanation-of-benefits statements for unfamiliar claims and treat unsolicited contact referencing their iRhythm or Zio device history with suspicion.
  5. Regulatory timelines are tightening. California's new 15-day AG-notification rule (effective January 1, 2026) and similar state-level pressure are shrinking the window companies have to formalize breach paperwork once consumer notifications go out — expect more companies to file state notices in quick succession with their notification mailings going forward, as iRhythm did here.
  6. Expect litigation to follow the numbers. At least two law firms had already announced investigations into potential class-action claims against iRhythm as of early October 2026; firmer, state-confirmed victim counts typically accelerate those filings.

Sources