
Medical device manufacturer CPAP Medical Supplies and Services said the data security incident it suffered last year compromised the sensitive personal data of over 90,000 individuals.
Headquartered in Jacksonville, Florida, CPAP Medical Supplies and Services offers essential equipment and support for Continuous Positive Airway Pressure (CPAP) therapy, a widely used treatment for sleep apnea, serving military personnel and their families.
In a data security incident notice filed with the Office of Maine Attorney General, CPAP said that on June 27, it identified unauthorised access within its internal network. The medical device manufacturer immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected network and notified relevant law enforcement authorities about the incident.
“After an extensive forensic investigation and complex manual document review, we discovered on June 27, 2025, that the impacted systems, which were accessed between December 13, 2024, and December 21, 2024, contained some of your personal information and/or protected health information,” CPAP said.
The compromised data included names and other personal identifiers including Social Security numbers. The filing with the Maine state regulator also states that CPAP has identified at least 90,133 individuals impacted by the incident.
While CPAP found no evidence of the compromise data being misused, it has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered two years of complimentary identity protection and credit monitoring services through IDX to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on CPAP. The medical device manufacturer also did not share details on who was behind the attack, how much data was compromised, or whether it has received a ransom demand.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543