
Healthcare company AdaptHealth has confirmed that a cyberattack discovered in July that was attributed to the threat group ShinyHunters exposed data on 4.1 million people.
The Company provides medical devices, supplies and related services for home use, including sleep apnea and ventilators, oxygen therapy, hospital beds and mobility products.
AdaptHealth first announced the incident in a submission on July 2, 2026 with the US Securities and Exchange Commission (SEC) and said that attackers had accessed their systems and exfiltrated private data.
At the time, AdaptHealth’s investigation confirmed that the breach had occurred earlier and involved access to cloud-based business applications, including certain internal patient management systems, document storage platforms and electronic health record portals.
On June 15, an unnamed threat actor contacted AdaptHealth and demanded a ransom payment in exchange for not sharing the stolen data.
AdaptHealth added that the breach occurred through a successful social engineering trick that compromised a third-party privileged account.
In one update On August 14, AdaptHealth said the compromise occurred on June 5 and may have exposed the following data:
- Full names
- Contact information
- Demographic information
- Health insurance information
- Health Information
Affected individuals should have already received a data breach notification with instructions on how to sign up for a free 12-month credit monitoring and identity protection service.
AdaptHealth said at the time that it found no evidence of identity theft, fraud or other misuse of the data stolen in the attack.
According to information on the company’s website, AdaptHealth served approximately 4.1 million patients in all 50 US states through a network of 680 locations (as of July 2024).
A submission to the US Department of Health and Human Services states: AdaptHealth data breach affects 4,115,802 people Individuals.
The HIPAA Journal previously reported that ShinyHunters was responsible for the attack based on the fact that the threat actor added the company to the victim list.
However, BleepingComputer was unable to find an AdaptHealth entry on ShinyHunter’s extortion portal, an indication that the threat actor has removed the company.
AdaptHealth’s confirmation of data breach impact follows similar recent disclosures from health technology companies Aesto Health, CareCloud and Unlimited Technology Systems.
McKesson and Nutex Health also disclosed data breach incidents late last month, but neither has yet determined the number of people affected.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

