Health care company AdaptHealth has confirmed that the data of 4.1 million people was exposed in a cyberattack discovered in July attributed to the ShinyHunters threat group. The company provides home medical devices, supplies and related services, including sleep apnea and respiratory equipment, oxygen therapy, hospital beds and mobility products. AdaptHealth first reported the incident in a document filed with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, saying that attackers gained access to its systems and stole private data. At the time, AdaptHealth’s investigation confirmed that the intrusion occurred previously and involved access to cloud-based business applications, including some internal patient management systems, document storage platforms and electronic health record system portals. On June 15, an unnamed attacker contacted AdaptHealth and demanded a ransom in exchange for non-disclosure of stolen data. AdaptHealth added that the breach was the result of a successful social engineering ploy that compromised a privileged account of a third-party contractor. In an August 14 update, AdaptHealth said the compromise occurred on June 5 and may have exposed the following data: Full names Contact information Demographic Information Health Insurance Information Health information Affected individuals should have already received a notification about the data breach with instructions on how to sign up for the free 12-month credit monitoring and identity protection service. At the time, AdaptHealth said it found no evidence of identity theft, fraud or other misuse of data stolen in the attack. As of July 2024, AdaptHealth served approximately 4.1 million patients in all 50 U.S. states through a network of 680 facilities, according to the company’s website. According to the US Department of Health and Human Services, the AdaptHealth data breach affected 4,115,802 people. The HIPAA Journal previously reported that ShinyHunters was responsible for the attack, based on the attacker adding the company to its list of victims. However, BleepingComputer was unable to find an entry for AdaptHealth on the ShinyHunter ransomware portal, indicating that the attacker had deleted the company. AdaptHealth’s confirmation of the impact of the data breach follows similar recent reports from health technology companies Aesto Health, CareCloud and Unlimited Technology Systems. McKesson and Nutex Health also reported data breach incidents late last month, but neither has yet identified the number of victims. General prevention scores may obscure what happens after initial access. Once attackers use valid credentials, prevention effectiveness drops dramatically. The Blue Report 2026 measures security technique by technique based on 338 million simulations run in customer production environments. Get report Post navigation Apple shares details about restrictions and terms of use of Apple Intelligence Cisco confirms that CVE-2026-20079 Secure FMC vulnerability was used in attacks