Security Guides
AdaptHealth data breach (about 4.1 million people): health insurance and health data exposed — patients should check benefit statements and calls
AdaptHealth reported a June 2026 breach of 4,115,802 patients' health insurance and health data, without SSNs. What patients should do, and the lesson from a contractor account.
For: people in the US who have received CPAP equipment (for sleep apnea), diabetes supplies, oxygen or other home medical equipment from AdaptHealth, their families, and anyone whose organization gives contractors access to its systems.
This article is based on AdaptHealth's notice, its report to the US Securities and Exchange Commission (SEC), state and US Department of Health and Human Services (HHS) disclosures, and US government guidance. It does not cover attack techniques.
What patients should do today
Check your letter and use only the official number
The company says it notified all affected people for whom it had current contact information. For questions, its notice lists (844) 958-8963, Monday to Friday, 8:00 a.m. to 5:30 p.m. Central Time, excluding US holidays.
If you are unsure the letter is real, open the company's own website notice and the HHS breach portal (ocrportal.hhs.gov) yourself and compare. The steps are in Six US healthcare data breaches in 2026, and how to check a notice.
Enroll in the free monitoring before the deadline
The company says it is providing identity protection services, including credit monitoring, at no charge for at least 12 months. Your activation code and deadline are in the letter.
Because SSNs were not exposed, a credit freeze at the three bureaus is not essential here. If your SSN has been exposed in another breach, though, this is a good moment to place one.
Read your Explanation of Benefits for claims you do not recognize
An Explanation of Benefits (EOB) is the statement your insurer sends showing who was paid, for what care and how much. The Federal Trade Commission (FTC) lists bills for care you did not receive and calls from debt collectors about unknown medical debt as warning signs of medical identity theft.
For home medical equipment, also look for equipment or supplies you never received. Medicare advises comparing the dates and services on its statements with your own records.
Do not give insurance numbers to callers about reorders
The exposed data may include contact details and health information, such as which equipment you use. So a caller who names your device and says it is "time for a replacement" or that your "insurance needs verifying" has not proven anything.
Do not answer with your insurance or Medicare number. Hang up and call the number on your AdaptHealth bill or equipment, or your prescribing doctor. Medicare says it will never call you to sell you anything or visit your home. For the basics of spotting these contacts, see What is phishing?
If you find a strange claim, get your records and report it
The FTC advises requesting your records from the providers involved, reporting errors in writing, and building a recovery plan at IdentityTheft.gov. If you think your Medicare number is being misused, call 1-800-MEDICARE (1-800-633-4227).
What happened (from AdaptHealth's notice and SEC report)
The following is drawn from AdaptHealth's notice, its Form 8-K filed with the SEC, a state disclosure and the HHS report as covered in news reports.
June 5, 2026
According to the company, the date of the attack.June 15
The company received a communication from a threat actor claiming to have obtained data. The company says it discovered the attack on this date.June 27
The company determined the incident was material, due to the nature and potential volume of data at risk.July 2
Form 8-K filed with the SEC, describing the cause and the kinds of data taken.August 14
Notice posted on the company's website, with notification of affected people and at least 12 months of free identity protection.Around August 21
The Vermont Attorney General announced that more than 48,000 Vermonters were affected (per news reports).Early September
The HHS Office for Civil Rights breach portal listed 4,115,802 people (per news reports).
- Company
- AdaptHealth, which delivers home medical equipment and supplies such as CPAP, diabetes supplies and oxygen to patients in the US
- Exposed data
- Names, contact information, demographic information, health insurance information and health information (August 14 notice)
- Not included
- SSNs, financial account, credit or debit card, and bank account information. The company says it does not collect SSNs in the affected systems
- Cause (SEC report)
- A successful social engineering attack (tricking people into giving information or access) compromised a user session associated with a third-party contractor
- What was reached (same)
- Cloud-based business applications, including internal patient management systems and document storage platforms. A stored password file associated with insurance billing was taken, and external electronic health record portals were accessed
- Response
- Disabled the account, reset affected credentials and added access controls. Notified law enforcement and investigated with outside experts. The company says operations and patient service were not materially affected
- Contact
- (844) 958-8963, Monday to Friday, 8:00 a.m. to 5:30 p.m. Central Time, excluding US holidays
About the numbers
The figure of 4,115,802 is the count reported to the HHS Office for Civil Rights breach portal, as covered in the news. The company's August 14 notice gives no number. Claims made by the people who took the data also circulate online; this article does not use them. Not receiving a letter does not prove you are unaffected, since people with outdated contact details may not have been reached.
How far one contractor account reached
In the DentaQuest case (DentaQuest data breach), the person tricked was the company's own employee, and the lessons were about MFA and help desk identity checks. What stands out in AdaptHealth's report is different. The way in was an outside contractor, and from there the access went past the company's own cloud into systems run by others.
A user session associated with an outside contractor
Compromised through social engineering
↓
The company's cloud business applications
Patient management, document storage → patient data taken
↓
A stored password file for insurance billing
Confirmed taken
↓
External electronic health record portals
Confirmed accessed (systems outside the company)
Two general lessons follow from this sequence. Contractor accounts are not always protected as strongly as employee accounts. And shared passwords saved in a file turn one break-in into access to partners' systems.
Easy to spread
- Contractors hold standing accounts with no end date
- Contractors can reach more applications than their work needs
- Partner portal passwords are written in a shared file
- Several people share one login
Easier to contain
- Contractor access has an end date per job and stops when the job ends
- Contractors reach only the applications and data their work needs
- Shared credentials live in a password management system that logs use
- One account per person on partner portals, with MFA
For organizations that hold patient data or use contractors
List contractor accounts and what each can reach
Build a table of every contractor account that can enter your systems: company, named person, applications, data visible and expiry date. Start with accounts that have no expiry, no known owner, or more access than the work needs, and narrow or disable them.
Hold contractors to the same MFA requirements as staff. For choosing strong methods, see How to choose multi-factor authentication.
Find passwords stored in files and move them into a password manager
Search shared drives, document storage and spreadsheets for files that hold passwords to partner portals or insurance billing sites. Move them into a password management system that can separate access by person (such as a business password manager), then delete the files. The personal-use basics are in How to choose a password manager.
When a break-in is found, change partner portal passwords right away
Containing your own systems does not stop someone from using taken passwords on a partner's system. Keep a list of stored credentials in advance, and plan to change all of them the same day, along with the contacts you will use to tell each partner.
Keep watching after sign-in
The report says a user session was compromised. A session is the signed-in state that stays usable for a while after login; passing MFA at sign-in says little about what happens afterward. Shorten contractor session lifetimes, require re-authentication for large actions such as bulk downloads of patient data, and alert when one account reads far more data than usual. The overall approach is in Security baseline for organizations.
Sources (public record)
The facts in this article come from the public sources below. Claims by the people who took the data are not used.
- AdaptHealth, "AdaptHealth Notice of Cybersecurity Incident" (August 14, 2026) — adapthealth.com
- AdaptHealth Corp., Form 8-K, Item 1.05 (dated July 2, 2026; copy hosted by classaction.org) — classaction.org (PDF)
- BleepingComputer, "AdaptHealth confirms 4.1 million people exposed in July cyberattack" (September 9, 2026) — bleepingcomputer.com
- SecurityWeek, "4.1 Million Impacted by AdaptHealth Data Breach" (September 10, 2026) — securityweek.com
- HIPAA Journal, "AdaptHealth Data Breach" — hipaajournal.com
- WCAX, "Data breach at health product company impacts 48,000 Vermonters" (August 21, 2026) — wcax.com
- Federal Trade Commission, "What To Know About Medical Identity Theft" — consumer.ftc.gov / IdentityTheft.gov
- Medicare, "Reporting Medicare fraud and abuse" — medicare.gov
Update history
2026-10-03: First version, based on AdaptHealth's August 14 notice, its Form 8-K dated July 2, the HHS count and Vermont disclosure as reported in the news, and FTC and Medicare guidance.
Read next
- Checking whether a notice is real: Six US healthcare data breaches in 2026, and how to check a notice
- People tricked into giving access: DentaQuest data breach (an MFA code handed over) / Carnival Corporation data breach
- Another 2026 health data case: Aesto Health (a health data storage vendor)
- Preparing for follow-on scams: What is phishing?
- Other 2026 incidents: Data breaches and cyberattacks list (Japan and worldwide)
- For organizations: Security baseline for organizations
FAQ
QWhat was exposed in the AdaptHealth data breach?
According to AdaptHealth's August 14, 2026 notice, the information included names, contact information, demographic information, health insurance information and health information. The company says it did not include Social Security numbers, financial information including credit or debit card information, or bank account information.
QHow many people were affected?
AdaptHealth's report to the HHS Office for Civil Rights breach portal lists 4,115,802 people, according to news coverage. At the state level, the Vermont Attorney General announced that more than 48,000 Vermonters were affected.
QAm I affected?
The company says it notified all affected individuals for whom it had current contact information. If you received CPAP equipment, diabetes supplies, oxygen or other home medical equipment from AdaptHealth and got a notice, you are affected. If unsure, call the company's line at (844) 958-8963, Monday to Friday, 8:00 a.m. to 5:30 p.m. Central Time.
QIf my SSN was not exposed, do I need to do anything?
Without an SSN, the risk of someone opening new credit in your name is lower. But health insurance information can be used for medical identity theft, where someone gets care or bills for equipment in your name. Check the Explanation of Benefits statements from your insurer or Medicare for care or equipment you did not receive.
QIs free credit monitoring offered?
The company says it arranged identity protection services, including credit monitoring, at no charge to all affected individuals for at least 12 months. How to enroll and the deadline are in your notice letter.
QWhat caused the breach?
According to the company's Form 8-K dated July 2, 2026, the incident resulted from a successful social engineering attack that compromised a user session associated with a third-party contractor. The attacker reached cloud-based business applications, including internal patient management systems and document storage platforms, and took data. The company says it disabled the account, reset affected credentials, added access controls and contained the incident.
QWhat should I do if someone calls about reordering my supplies?
Do not give your insurance or Medicare number on that call. Hang up and call back using the number on your AdaptHealth bill or equipment, or your prescribing doctor, to confirm whether a reorder is really needed. Medicare says it will never call you to sell you anything.