AdaptHealth Discloses Cyberattack Leading to Patient Data Breach
AdaptHealth disclosed last week that a recent cyberattack led to the theft of patient data. The attacker gained unauthorized access to company systems through social engineering tactics and stole data including personally identifiable information, protected health information, and password files related to insurance billing. The company stated that it has contained the incident, but the full scope of the affected data has not yet been determined.

AdaptHealth disclosed last week that a recent cyberattack led to the theft of patient data. According to the company's filing with the U.S. Securities and Exchange Commission (SEC) on July 2,the filingattackers gained unauthorized access to the company's systems through a social engineering attack and stole data including certain personally identifiable information, patients' protected health information, and stored password files related to insurance billing.
Based on information obtained to date, AdaptHealth believes that attackers gained unauthorized access to certain cloud-based business applications, including internal patient management systems and document storage platforms. The company also confirmed that certain external electronic health record system portals were also accessed.
Although AdaptHealth did not specify the content of the stolen data, the company stated that the affected systems do not collect Social Security numbers, nor do they store financial account information or payment card information.
AdaptHealth stated that the full scope of the affected data sets has not yet been determined, and specific information about the volume of stolen data is not yet available. According to the filing, the incident has been contained, and the company is continuing to investigate the attack with external forensic teams.
"The company has since taken steps aimed at reducing the risk of dissemination of the stolen data," AdaptHealth said.
AdaptHealth supplies medical equipment such as CPAP machines and other devices for sleep apnea, continuous glucose monitors, and insulin pumps, with a focus on home health products.
As of the date of the filing, the incident has not had a material impact on AdaptHealth's operations or its ability to serve patients.
"At this time, the company cannot determine the full financial impact of the incident, including remediation and response costs, legal, regulatory, and notification matters, as well as potential impacts on patients, counterparties, and the company's reputation," the company said, adding that it holds cybersecurity insurance that may cover some losses related to the attack.
On June 27, the company determined the incident was material due to "the nature and potential volume of data at risk."
According to the filing, the cyber incident was the result of a social engineering attack that compromised a user session associated with a third-party contractor. After detecting the attack, the company implemented containment measures, including disabling compromised user accounts, resetting affected credentials, and implementing additional access controls.
The attackers notified the company on June 15 that they had taken data from its systems.
AdaptHealth's incident is the latest in a series of cyberattacks in the medical technology sector.Stryker、Intuitive Surgical、Medtronic and iRhythm have all disclosed attacks in recent months. The attack on Stryker caused manufacturing and shipping disruptions for weeks andsignificantly impactedits first-quarter earnings.