4.1 Million Impacted by AdaptHealth Data Breach
In June 2026, AdaptHealth, a US-based healthcare company operating over 680 facilities, suffered a data breach impacting over 4.1 million individuals. Hackers accessed cloud-based applications, including internal patient management and document storage systems, via social engineering targeting a third-party contractor. The stolen data includes personal, health, and insurance information, but excludes Social Security numbers and financial information. The breach was confirmed by AdaptHealth and reported to the US Department of Health and Human Services (HHS).
AI Analysis
Technical Summary
In June 2026, a threat actor gained unauthorized access to AdaptHealth's cloud-based systems through social engineering of a third-party contractor's user session. The attacker exfiltrated personal, health, and insurance data of approximately 4.1 million individuals. The breach involved internal patient management and document storage applications. Social Security numbers and financial data were not compromised. AdaptHealth publicly confirmed the breach and notified the HHS, which added the incident to its data breach portal.
Potential Impact
The breach exposed sensitive personal, health, and insurance information of over 4.1 million individuals, potentially risking privacy and enabling identity-related threats. However, Social Security numbers and financial information were not affected, which limits some categories of risk. The compromise of internal patient management and document storage systems may have operational and reputational impacts on AdaptHealth.
Mitigation Recommendations
No specific patch or remediation is applicable as this breach resulted from social engineering and unauthorized access rather than a software vulnerability. Organizations should review third-party access controls and user session security. AdaptHealth has confirmed the breach and notified regulatory authorities. No further immediate action is indicated from the vendor advisory.
4.1 Million Impacted by AdaptHealth Data Breach
Description
In June 2026, AdaptHealth, a US-based healthcare company operating over 680 facilities, suffered a data breach impacting over 4.1 million individuals. Hackers accessed cloud-based applications, including internal patient management and document storage systems, via social engineering targeting a third-party contractor. The stolen data includes personal, health, and insurance information, but excludes Social Security numbers and financial information. The breach was confirmed by AdaptHealth and reported to the US Department of Health and Human Services (HHS).
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In June 2026, a threat actor gained unauthorized access to AdaptHealth's cloud-based systems through social engineering of a third-party contractor's user session. The attacker exfiltrated personal, health, and insurance data of approximately 4.1 million individuals. The breach involved internal patient management and document storage applications. Social Security numbers and financial data were not compromised. AdaptHealth publicly confirmed the breach and notified the HHS, which added the incident to its data breach portal.
Potential Impact
The breach exposed sensitive personal, health, and insurance information of over 4.1 million individuals, potentially risking privacy and enabling identity-related threats. However, Social Security numbers and financial information were not affected, which limits some categories of risk. The compromise of internal patient management and document storage systems may have operational and reputational impacts on AdaptHealth.
Defensive Guidance
No specific patch or remediation is applicable as this breach resulted from social engineering and unauthorized access rather than a software vulnerability. Organizations should review third-party access controls and user session security. AdaptHealth has confirmed the breach and notified regulatory authorities. No further immediate action is indicated from the vendor advisory.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/4-1-million-impacted-by-adapthealth-data-breach/","fetched":true,"fetchedAt":"2026-09-10T11:22:14.515Z","wordCount":944}
Threat ID: 6aa292e6acd9273b4907e555
Added to database: 09/10/2026, 11:22:14 UTC
Last enriched: 09/10/2026, 11:22:21 UTC
Last updated: 09/10/2026, 15:00:50 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.