AdaptHealth Confirms 4.1 Million Patients Hit in Breach Tied to ShinyHunters
The home medical supplier says a contractor's account was tricked open in June, giving intruders a path into patient records across all 50 states.

Key points
- AdaptHealth, a US home medical equipment supplier, has told regulators that a June cyberattack exposed data on 4,115,802 patients.
- The break-in on June 5, 2026 came through a third-party contractor's account, tricked open by social engineering (con-artist tactics used against staff).
- Stolen data includes names, contact details, health insurance information and medical information; the company says it has seen no evidence of fraud so far.
- The ShinyHunters extortion crew was linked to the theft, and contacted AdaptHealth demanding a ransom on June 15; the company has not said whether it paid.
- Affected patients are being offered 12 months of free credit monitoring and identity protection.
AdaptHealth, one of the largest US suppliers of home medical gear, has confirmed that hackers made off with personal and medical data belonging to 4.1 million of its patients. The company rents and sells things like sleep-apnea machines, oxygen equipment, hospital beds and mobility aids, serving customers across all 50 states through around 680 locations.
The intrusion was first disclosed in a filing with the US Securities and Exchange Commission on July 2. A follow-up notice on August 14 pinned the actual break-in to June 5, and a formal count later filed with the US Department of Health and Human Services put the number of affected people at 4,115,802.
How did the hackers get in?
They talked their way in. AdaptHealth says the attackers ran a social engineering ploy against a third-party contractor and took over that contractor's privileged account, meaning an account with high-level access.
From there they reached cloud-based business systems including internal patient management tools, document storage, and portals connected to electronic health record systems. Those are the systems that hold the everyday paperwork of a medical supplier: who the patient is, what they were prescribed, and who is paying for it.
On June 15, ten days after the intrusion, an unnamed group contacted AdaptHealth demanding money in exchange for not publishing the stolen files. The company has not confirmed whether it paid.
Who is ShinyHunters?
ShinyHunters is a long-running data-theft crew rather than a traditional ransomware gang. The group specialises in stealing large databases and squeezing companies for payment under threat of leaks, rather than encrypting files on the way out.
AdaptHealth was named as a ShinyHunters victim on the group's extortion site, according to reporting from The HIPAA Journal. BleepingComputer noted the listing has since been removed, which typically suggests either a payment, a negotiation, or a decision by the crew to pull the entry.
What data was taken?
According to AdaptHealth, the exposed information may include:
- Full names and contact details
- Demographic information
- Health insurance details
- Health information
The company says it has found no evidence yet that any of the data has been used for identity theft or fraud. Patients whose records were involved should have received a written notice by now, along with instructions to sign up for 12 months of free credit monitoring and identity protection.
What should affected patients do?
Enrol in the free monitoring, and treat unexpected calls or emails about medical bills, insurance claims or prescriptions with suspicion. Health data is prized by scammers because it makes fake insurance and billing fraud far more convincing than a stolen credit card alone.
It is also worth checking insurance statements for treatments or equipment you did not receive, and reporting anything odd to your insurer.
A rough month for health-tech
AdaptHealth's disclosure lands in a run of similar filings from health-technology firms Aesto Health, CareCloud and Unlimited Technology Systems. McKesson and Nutex Health also filed breach notices late last month, though neither has yet put a number on how many patients are affected.
The pattern is consistent: attackers are going after the cloud accounts, contractors and suppliers that sit around big healthcare providers, rather than the hospitals themselves.



