[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcyTxb7FQilplsEyGesaRbeLkjut8MBAbIiKL_Q2cmBA":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":22,"source":23,"isVerified":4,"isSpamList":24,"isSensitive":4,"severity":25,"processingStatus":26,"logoUrl":27,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a668fc405863014b5b881e2","AdaptHealth2026","AdaptHealth 2026 Data Breach","adapthealth-2026","adapthealth.com",{"name":12,"sector":13,"country":14,"website":10},"AdaptHealth Corp.","Healthcare","United States","2026-06-15T00:00:00.000Z","2026-07-26T22:52:52.210Z",0,[19,20,21],"Personally identifiable information","Protected health information","Insurance billing password files","\u003Cp>\u003Cstrong>The AdaptHealth 2026 data breach\u003C\u002Fstrong> is an incident in which the home-health equipment provider reported to the U.S. Securities and Exchange Commission that patient data was exfiltrated after unauthorized access to cloud-based business applications. AdaptHealth confirmed that the stolen material included certain personally identifiable information, protected health information belonging to patients, and stored password files associated with insurance billing. No affected-person or record count has been published, so LeakData records the total as unknown.\u003C\u002Fp>\n\u003Cp>The Form 8-K filed on July 2, 2026 is the primary official source. MedTech Dive reviewed the filing and corroborated that social engineering compromised a session belonging to a third-party contractor and provided access to patient-management and document-storage applications. Because the investigation was incomplete, the company did not enumerate every personal field or quantify the exfiltrated volume. This record lists only the principal categories confirmed in the filing.\u003C\u002Fp>\n\u003Ch2>Confirmed Types of Data\u003C\u002Fh2>\n\u003Cp>The three main categories confirmed by AdaptHealth are personally identifiable information, protected health information, and stored password files connected to insurance billing. PII and PHI are broad classifications; the company has not yet said which underlying fields, such as names, dates of birth, addresses, diagnoses, prescriptions, or insurance numbers, were present. LeakData therefore does not infer specific fields that were not disclosed.\u003C\u002Fp>\n\u003Cp>The company specifically said it does not collect Social Security numbers in the affected system and does not store bank-account or payment-card information in the relevant systems. SSNs, credit cards, bank accounts, and payment data are not listed as compromised classes. Although the password files were confirmed to relate to insurance billing, AdaptHealth did not disclose their format, encryption status, freshness, or the number of accounts represented.\u003C\u002Fp>\n\u003Ch2>Attack Method and Accessed Systems\u003C\u002Fh2>\n\u003Cp>According to the SEC filing, the attack began with social engineering that compromised a user session associated with a third-party contractor. That description does not establish exploitation of a software vulnerability or compromise of the entire AdaptHealth network. The unauthorized party reached certain cloud-based business applications, while the company did not say whether email, telephone, a fake login page, or another social-engineering method produced the initial access.\u003C\u002Fp>\n\u003Cp>The accessed environment included internal patient-management systems, document-storage platforms, and certain external electronic-health-record portals. That list does not prove that every record in each platform was exfiltrated. AdaptHealth said it was still determining the scope of affected datasets. LeakData records the systems as context but does not convert the company's overall patient or customer population into an incident count.\u003C\u002Fp>\n\u003Ch2>Incident Timeline\u003C\u002Fh2>\n\u003Cp>The threat actor notified AdaptHealth on June 15, 2026 that data had been taken from its systems. On June 27 the company determined the event was material because of the nature and potential volume of data at risk, and it filed the Form 8-K on July 2. The exact initial-access date and duration of the compromised session were not disclosed. The June 15 date in LeakData represents the verified day on which the theft was reported to the company.\u003C\u002Fp>\n\u003Cp>The materiality assessment suggests that the possible volume could be substantial, but the filing provides no person, file, or record count. “Potential volume” is not a settled total and cannot support a pwnCount. If later patient notices or healthcare-regulator records publish a reliable figure, the count can be updated; at this stage an unknown value is the most accurate and conservative representation.\u003C\u002Fp>\n\u003Ch2>AdaptHealth's Response\u003C\u002Fh2>\n\u003Cp>After detecting the attack, AdaptHealth disabled the compromised user account, reset affected credentials, and implemented additional access controls. It said the incident had been contained, external forensic teams were assisting the continuing investigation, and steps were taken to reduce the risk that exfiltrated data would be disseminated. These are the concrete measures disclosed by the company; undocumented technical changes are not added to the record.\u003C\u002Fp>\n\u003Cp>As of the filing date, the event had not materially affected AdaptHealth's operations or interrupted its ability to serve patients. The company nevertheless said it could not yet determine all response, legal, regulatory, notification, patient, reputational, and financial effects. Cybersecurity insurance may cover certain losses, but insurance does not eliminate the privacy and account-security consequences of stolen information.\u003C\u002Fp>\n\u003Ch2>Patient and Account Security Risks\u003C\u002Fh2>\n\u003Cp>Protected health information is sensitive because it can reveal a person's healthcare relationship or medical context. Password files associated with insurance billing could create account-access or fraud risk if their contents are current and recoverable. Because detailed fields were not disclosed, readers should not assume every patient lost the same information. Risk should be evaluated from the specific data listed in each person's eventual notice.\u003C\u002Fp>\n\u003Cp>Notified patients should independently verify unexpected invoices, portal-login links, password resets, or requests to confirm health information sent in AdaptHealth's or an insurer's name. Reused or similar passwords should be changed on other accounts, and multifactor authentication should be enabled where available. The absence of SSNs and payment-card data from the affected systems does not remove phishing and medical-privacy risks.\u003C\u002Fp>\n\u003Ch2>How to Interpret This LeakData Record\u003C\u002Fh2>\n\u003Cp>The zero-person value does not mean no patients were affected; it means the company has not yet published a verified total. AdaptHealth's overall patient population, equipment sales, and partner customer bases are not the breach scope. The data classes indicate the broad categories confirmed as exfiltrated in the SEC filing, not that every field was present in every record.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that social engineering compromised a third-party contractor session and enabled theft of PII, PHI, and insurance-billing password files from certain AdaptHealth cloud applications and electronic-health-record portals. The incident was contained and no material service disruption was reported, while the affected count and detailed fields remain open during the investigation. LeakData documents the real breach within those evidentiary limits.\u003C\u002Fp>","Social engineering",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fadapthealth_com.png"]