AdaptHealth Discloses Data Breach Affecting 4.1 Million Patients

AdaptHealth Data Breach Exposes Personal and Health Info of 4.1M

HIGH
September 10, 2026
4m read
Data BreachSupply Chain AttackCloud Security

Impact Scope

People Affected

4,115,802

Industries Affected

Healthcare

Geographic Impact

United States (national)

Related Entities

Organizations

U.S. Department of Health and Human Services (HHS)

Full Report

Executive Summary

AdaptHealth, a major United States network of medical equipment companies, has officially reported a massive data breach impacting 4,115,802 individuals. According to a notification filed with the U.S. Department of Health and Human Services (HHS), an unauthorized third party gained access to the company's cloud-based applications in June 2026. The initial access vector was a social engineering attack that compromised a user session at one of AdaptHealth's third-party contractors. The threat actor successfully exfiltrated a wide range of patient data, including protected health information (PHI), though the company states that Social Security numbers and financial details were not exposed in this incident.


Threat Overview

The breach was initiated through a social engineering attack targeting an external contractor, highlighting the significant risks posed by supply chain partners. After gaining a foothold, the threat actor accessed internal, cloud-based platforms used for patient management and document storage. The attacker exfiltrated a large volume of sensitive data before contacting AdaptHealth, prompting an internal investigation that confirmed the breach. The stolen data included a password file related to insurance billing, which likely facilitated further access to patient records. The incident underscores how a single compromised third-party account can lead to a large-scale data breach.

MITRE ATT&CK Techniques


Impact Assessment

The breach affects over 4.1 million patients, exposing their sensitive personal and health information. While AdaptHealth asserts that SSNs and financial data were not compromised, the stolen data is highly valuable on the dark web and can be used for sophisticated phishing campaigns, insurance fraud, and identity theft. The exposed data includes:

  • Full Names
  • Contact Information (address, phone number, email)
  • Demographic Information
  • Health Data (related to medical equipment and conditions)
  • Health Insurance Information

The incident poses significant reputational damage to AdaptHealth and will likely result in regulatory scrutiny under HIPAA, potentially leading to substantial fines. Affected individuals are at an increased risk of being targeted by follow-on fraud schemes that leverage their detailed personal and medical information.


IOCs — Directly from Articles

No specific technical Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.


Detection & Response

  • Cloud Security Monitoring: Organizations should implement robust monitoring for their cloud environments. This includes enabling and analyzing audit logs from cloud providers (e.g., AWS CloudTrail, Azure Monitor) to detect anomalous access patterns, such as logins from unusual geographic locations or impossible travel scenarios.
  • Third-Party Access Control: Access for third-party contractors should be strictly controlled and monitored. Enforce Multi-Factor Authentication (MFA) on all accounts, especially those belonging to external partners. Regularly review and recertify third-party access rights.
  • Data Loss Prevention (DLP): Implement DLP solutions to monitor and block the unauthorized exfiltration of large volumes of sensitive data, such as PHI. Configure alerts for unusual data access or download patterns.

Mitigation

  1. Vendor Risk Management: Establish a comprehensive third-party risk management program. This should include security assessments of all contractors and vendors before granting them access to sensitive systems and data.
  2. Enforce MFA: Mandate the use of phishing-resistant MFA for all employees and contractors to access internal and cloud-based applications. This is one of the most effective controls against credential theft and social engineering.
  3. Principle of Least Privilege: Ensure that all users, especially third-party contractors, are granted only the minimum level of access necessary to perform their job functions. Access to sensitive patient data should be tightly restricted and logged.
  4. User and Contractor Training: Conduct regular security awareness training for all employees and contractors, with a specific focus on identifying and reporting social engineering and phishing attempts.

Timeline of Events

1
June 1, 2026
Threat actor gains unauthorized access to AdaptHealth's cloud applications.
2
August 14, 2026
AdaptHealth files its official breach notification with the Department of Health and Human Services.
3
September 8, 2026
The HHS adds the incident to its public data breach portal.
4
September 10, 2026
This article was published

MITRE ATT&CK Mitigations

Enforcing MFA on all cloud accounts, especially for third-party contractors, would have likely prevented this breach.

Training contractors and employees to recognize and report social engineering attempts is a critical preventative measure.

Implement strict network and application access controls for third parties, limiting them to only the resources they absolutely need.

Audit

M1047enterprise

Continuously audit cloud access logs to detect anomalous behavior from third-party accounts.

Timeline of Events

1
June 1, 2026

Threat actor gains unauthorized access to AdaptHealth's cloud applications.

2
August 14, 2026

AdaptHealth files its official breach notification with the Department of Health and Human Services.

3
September 8, 2026

The HHS adds the incident to its public data breach portal.

Sources & References

4.1 Million Impacted by AdaptHealth Data Breach
SecurityWeek (securityweek.com) September 10, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachHealthcareAdaptHealthSocial EngineeringSupply ChainCloud SecurityPHI

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.