AdaptHealth disclosed a data breach after attackers used social engineering to gain access to its cloud environment through a third‑party contractor.
AdaptHealth disclosed a data breach after attackers used social engineering to gain access to its cloud environment through a third‑party contractor. The company, which provides home medical equipment and serves more than 4.2 million patients nationwide, reported the incident to the Securities and Exchange Commission on Thursday. Investigators determined that the attackers accessed internal patient management systems, document storage platforms, and external electronic health record portals. They obtained a password file associated with insurance billing and other personally identifiable information and protected health information. Social Security numbers and payment details were not believed to be compromised. AdaptHealth disabled the contractor’s user account, reset affected credentials, and implemented additional access controls. The company said the breach is now contained and it has taken steps intended to mitigate the risk of data dissemination. No extortion demand was reported and no cybercrime group has claimed responsibility. AdaptHealth continues to investigate the full scope of the breach and will provide further updates as the investigation proceeds.
- Publisher
- theregister
- Reliability
- high
- Published
- 7/4/2026, 10:00:21 AM
- Retrieved
- 7/4/2026, 10:00:21 AM
- Relevance
- 80%
- Confidence
- 85%

