The CPAP Medical 2024 data breach was a cybersecurity incident in which an unauthorized actor accessed the sleep-apnea equipment provider's network environment between December 13 and December 21, 2024. The official notice from CPAP Medical Supplies and Services confirms that affected systems contained identifiable personal information and protected health information.
The public record maintained by the U.S. Department of Health and Human Services Office for Civil Rights lists the organization as a Healthcare Provider, the event as a Hacking/IT Incident, and the information location as Network Server; 90,133 people were affected. LeakData imported no patient or customer rows, importedRecordCount is zero, and this entry contains verified incident metadata only.
How Was the CPAP Medical Breach Confirmed?
The primary source is the Notice of Data Security Incident issued by CPAP Medical Supplies and Services. It directly describes unauthorized network access, the forensic and document review, the access window, the start of notifications, credit monitoring offered to people whose Social security numbers were present, and protective recommendations.
The second source is the HHS OCR breach portal, which confirms the 90,133-person scope and incident classifications. The third is HIPAA Journal's August 20, 2025 report, which independently describes the dates and data categories based on the notice filed with the Maine Attorney General. The organization, scope, network access, and review dates align across the sources.
What Happened Between December 13 and 21, 2024?
An unauthorized actor entered CPAP Medical's network environment on December 13 and retained access through December 21. When the organization learned of the incident, it said it contained the threat, secured its internal environment, and began a thorough investigation with outside cybersecurity professionals to determine whether personal or sensitive data had been affected.
After a forensic investigation and complex manual document review, CPAP Medical determined on June 27, 2025 that the affected systems contained identifiable health and personal information. Notifications began on August 15 where contact information was available. The breachDate field uses December 13, the confirmed start of access, rather than the review or mailing date.
What Information Was Affected?
According to HIPAA Journal's report based on the regulatory filing, the files could contain full names, dates of birth, Social security numbers, financial and banking information, medical information, and health-insurance information. The official online notice also confirms identifiable personal and protected health information and says Social security numbers were present in some affected files.
The organization did not say that every field applied to all 90,133 people. This entry therefore does not add data categories to create subgroup totals and does not include undisclosed email addresses, passwords, or payment-card details. While files may have been viewed or exfiltrated, the sources do not establish that they were publicly released or sold to a named threat group.
What Does the 90,133-Person Scope Mean?
The pwnCount and totalRecords fields use the 90,133 affected-person count in the current HHS OCR public record. The same total appears in reporting based on the Maine Attorney General filing. It counts people in the notification population, not files, prescriptions, equipment orders, insurance claims, or individual data elements.
Jacksonville-based CPAP Medical provides sleep-therapy products and CPAP equipment, particularly to military families and active-duty or retired service members. Because the distribution by patient, customer, military status, or family relationship was not disclosed, this entry does not create separate totals for those groups.
What Measures Did the Organization Take?
CPAP Medical said it contained the threat, secured its systems, conducted a forensic investigation with outside professionals, and completed a document review. The organization also said it continually evaluates and modifies its practices and internal controls to improve the security and privacy of personal information.
No evidence of misuse resulting from the incident had been found at notification. Even so, people whose Social security numbers were involved received complimentary credit monitoring, and recipients were advised to review financial accounts, credit reports, and health-insurance explanation-of-benefits statements. The absence of known misuse does not remove future risk.
What Should Affected People Do?
Notice recipients should activate the offered monitoring within the stated enrollment period and review credit reports, bank activity, and health-insurance records for unfamiliar accounts, transactions, or services. A suspicious entry should be reported through a previously known official channel for the financial institution, insurer, or healthcare provider.
The connection to military communities combined with health information can make targeted phishing more convincing. Links in unexpected messages claiming to be from CPAP Medical, a military-benefit program, bank, or insurer should not be opened directly; contact should begin through an official site or verified number. LeakData does not host, distribute, or provide search access to stolen personal information.