The Pennsylvania-based home medical equipment provider says a threat actor accessed internal systems through a compromised third-party contractor, stealing files containing patient information.

AdaptHealth, a publicly traded company that supplies home medical equipment, diabetes supplies and sleep therapy products, is investigating a material cybersecurity incident involving unauthorized access to patient data. In a Form 8-K filing with the U.S. Securities and Exchange Commission, the company said a threat actor contacted it on June 15, 2026, claiming to possess files containing patient information.
AdaptHealth launched an investigation following the contact, retaining third-party cybersecurity specialists and alerting law enforcement. The company has determined that the threat actor accessed certain cloud-based business applications, including internal patient management systems and document storage platforms, and exfiltrated files containing patients’ personally identifiable information and protected health information.
The breach traces back to a social engineering attack against a third-party contractor, which allowed the threat actor to obtain the contractor’s credentials. Using that access, the attacker retrieved a stored password file connected to insurance billing and reached external electronic health record portals.
AdaptHealth disabled the compromised account, reset credentials and added further access controls in response. The company said the incident has not disrupted its operations or patient services and considers the intrusion contained, though a review is ongoing to determine the full scope of the data theft. The specific categories of data involved and the number of affected individuals have not yet been determined. AdaptHealth said it does not collect patients’ Social Security numbers, and that financial account information and payment card data are not stored within the affected systems.
On June 27, AdaptHealth concluded that the nature and potential volume of the data at risk made the incident material, triggering the SEC disclosure requirement. The company said it has since taken steps intended to reduce the risk that the stolen data will be further disseminated.
The financial impact of the breach remains under assessment. AdaptHealth said it may face costs tied to forensic investigation, breach notifications, legal and regulatory response, and remediation efforts, and noted that it holds a cybersecurity insurance policy that may offset some of those losses.
The company has not named the party responsible for the attack. The intrusion appears to have been a data theft and extortion attempt by the ShinyHunters threat group, which added AdaptHealth to its data leak site and has threatened to release the stolen information if a ransom is not paid. AdaptHealth has not specified whether an extortion demand was made or whether any payment occurred, and no group had formally claimed responsibility at the time of reporting.
Founded in 2012 and headquartered in Pennsylvania, AdaptHealth specializes in respiratory, sleep and diabetes therapies. According to a 2024 annual report, the company serves more than 4.2 million patients across all 50 states.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543