Summary
AdaptHealth, a home medical equipment company operating over 680 facilities across the United States, has confirmed that a cyberattack first disclosed in July 2026 exposed the personal, health, and insurance information of 4,115,802 individuals. The attack was attributed to the ShinyHunters threat group and gained entry through social engineering of a third-party contractor's user session, giving the attacker access to AdaptHealth's cloud-based patient management systems, document storage, and electronic health record portals. The breach was formally reported to the U.S. Department of Health and Human Services, which added the incident to its public data breach portal this week. Social Security numbers and financial information were not affected.
Timeline
| Date | Event |
|---|---|
| June 5, 2026 | Attacker compromises a third-party contractor's privileged account via social engineering and accesses AdaptHealth's cloud environment |
| June 27, 2026 | AdaptHealth files disclosure with the SEC; confirms theft of patient records and insurance billing passwords |
| July 4, 2026 | AdaptHealth publicly discloses the cyberattack |
| Aug 14, 2026 | AdaptHealth notifies HHS, reporting 4,115,802 affected individuals; offers 12-month free credit monitoring |
| Sep 10, 2026 | HHS adds AdaptHealth to its public data breach portal; breach confirmed at scale |
What Happened
The attacker used social engineering to trick a third-party contractor into surrendering login credentials, then used those credentials to enter AdaptHealth's cloud-based infrastructure. From there, the attacker accessed internal patient management systems and document storage platforms, exfiltrating names, contact and demographic information, health information, and health insurance details, as well as a password file associated with insurance billing. No Social Security numbers or financial account data were confirmed stolen.
AdaptHealth has notified all 4,115,802 affected individuals and enrolled them in a 12-month credit monitoring and identity protection service. The company reports no evidence the stolen data has been used for identity theft or fraud as of this publication. The incident follows a pattern consistent with other ShinyHunters campaigns that use contractor access as an entry point — a supply-chain access pattern also seen in the ShinyHunters Florida DAVID breach documented in TTO-2026-0908-111.
Domain Intelligence
adapthealth.com — 60.15
Score sits in the low-trust range. AdaptHealth is the breached organization. The score reflects adapthealth.com's domain trust posture as assessed prior to and independently of this incident.
The Trust Observatory · thetrustobservatory.com · September 10, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026