AdaptHealth discloses material cybersecurity incident involving patient data
AdaptHealth Corp. disclosed a material cybersecurity incident in which an unauthorized threat actor gained access to certain cloud-based business applications, including patient management systems and document storage platforms, and exfiltrated data including passwords and personally identifiable and protected health information of patients. The company determined the incident material on June 27, 2026, after receiving a threat actor communication on June 15, 2026. The incident resulted from a social engineering attack that compromised a third-party contractor user session; the company has contained the threat and is investigating the full scope with external forensics teams, while noting it does not currently have a material operational impact but cannot yet determine total financial remediation costs.
Key facts
- Threat actor gained unauthorized access to certain cloud-based business applications including internal patient management systems and document storage platforms
- Company determined incident material on June 27, 2026
- Exfiltrated data includes passwords associated with insurance billing and certain personally identifiable information and protected health information of patients
- Incident resulted from successful social engineering attack that compromised a user session associated with a third-party contractor
- Company received communication from threat actor claiming to have obtained data on June 15, 2026
- Company does not collect Social Security numbers in affected systems and does not store individual financial account information or payment card information
- As of filing date, incident has not had material impact on Company's operations and has not affected ability to service patients
- Company maintains cybersecurity insurance that may cover certain losses associated with the incident
- Full scope of affected data sets and specific volume of data at issue not yet determined
Why it matters
As a healthcare company managing patient data, AdaptHealth faces potential regulatory, legal, and reputational consequences from the loss of protected health information and patient personally identifiable information, with financial impact—including remediation, notification, and legal costs—not yet quantifiable.
Share
Derived from 8-K filed 2026-07-02. Not investment advice. View the source filing on SEC.gov →