4,115,802
AdaptHealth, a major United States network of medical equipment companies, has officially reported a massive data breach impacting 4,115,802 individuals. According to a notification filed with the U.S. Department of Health and Human Services (HHS), an unauthorized third party gained access to the company's cloud-based applications in June 2026. The initial access vector was a social engineering attack that compromised a user session at one of AdaptHealth's third-party contractors. The threat actor successfully exfiltrated a wide range of patient data, including protected health information (PHI), though the company states that Social Security numbers and financial details were not exposed in this incident.
The breach was initiated through a social engineering attack targeting an external contractor, highlighting the significant risks posed by supply chain partners. After gaining a foothold, the threat actor accessed internal, cloud-based platforms used for patient management and document storage. The attacker exfiltrated a large volume of sensitive data before contacting AdaptHealth, prompting an internal investigation that confirmed the breach. The stolen data included a password file related to insurance billing, which likely facilitated further access to patient records. The incident underscores how a single compromised third-party account can lead to a large-scale data breach.
T1566 - Phishing: The likely method used in the social engineering attack against the contractor.T1078 - Valid Accounts: The attacker used legitimate, albeit stolen, credentials to access cloud applications.T1530 - Data from Cloud Storage Object: The attacker accessed and exfiltrated data stored in cloud-based systems.T1567 - Exfiltration Over Web Service: Data was likely exfiltrated over standard web protocols from the cloud environment.The breach affects over 4.1 million patients, exposing their sensitive personal and health information. While AdaptHealth asserts that SSNs and financial data were not compromised, the stolen data is highly valuable on the dark web and can be used for sophisticated phishing campaigns, insurance fraud, and identity theft. The exposed data includes:
The incident poses significant reputational damage to AdaptHealth and will likely result in regulatory scrutiny under HIPAA, potentially leading to substantial fines. Affected individuals are at an increased risk of being targeted by follow-on fraud schemes that leverage their detailed personal and medical information.
No specific technical Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.
Enforcing MFA on all cloud accounts, especially for third-party contractors, would have likely prevented this breach.
Training contractors and employees to recognize and report social engineering attempts is a critical preventative measure.
Implement strict network and application access controls for third parties, limiting them to only the resources they absolutely need.
Threat actor gains unauthorized access to AdaptHealth's cloud applications.
AdaptHealth files its official breach notification with the Department of Health and Human Services.
The HHS adds the incident to its public data breach portal.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.