AdaptHealth breach impacts over 4 million patients, data stolen via contractor account

Healthcare provider AdaptHealth has confirmed that a cyberattack discovered in July exposed the personal and health information of 4.1 million individuals. The breach, attributed to the ShinyHunters group, originated from a social engineering attack that compromised a third-party contractor's privileged account. The company has found no evidence of identity theft so far and is offering credit monitoring to affected patients.
The attack timeline shows the initial unauthorized access occurred on June 5, with a ransom demand following ten days later. AdaptHealth formally notified regulators in early July, and the final count of affected individuals was reported to the Department of Health and Human Services as 4,115,802. The compromised data spans personal identifiers, demographic details, and medical insurance records.
Although the ShinyHunters group was linked to the intrusion, their extortion portal no longer lists the company. This incident aligns with a broader trend of recent healthcare data breaches, including those at Aesto Health, CareCloud, and McKesson, highlighting the persistent threat to medical providers.
The exposure of health insurance and medical details for over four million patients could lead to targeted fraud, such as fraudulent insurance claims or prescription scams, even if identity theft has not yet surfaced. Affected individuals may face long-term risks to their financial and medical privacy. This incident may also heighten scrutiny of third-party access controls across the healthcare sector, prompting providers to reassess their vendor security protocols to mitigate future contractor-related vulnerabilities.