The healthcare company, which serves patients across all 50 U.S. states through 680 locations, first detected the intrusion in early July. An investigation later revealed that attackers accessed its systems on June 5, 2026, and exfiltrated data from patient management systems, document storage platforms, and electronic health record portals.
On June 15, an unnamed threat actor contacted AdaptHealth demanding a ransom payment in exchange for not leaking the stolen information. According to a subsequent update on August 14, the compromised data includes full names, contact information, demographic details, health insurance information, and medical health information.
AdaptHealth has stated it found no evidence of identity theft, fraud, or other misuse of the stolen data. Impacted individuals have received breach notifications with instructions to enroll in free 12-month credit monitoring and identity protection services.
The cyberattack has been attributed to ShinyHunters, a known threat group, according to a report by the HIPAA Journal. However, BleepingComputer could not confirm an entry for AdaptHealth on ShinyHunters' extortion portal, suggesting the listing may have been removed.
In a submission to the U.S. Department of Health and Human Services, AdaptHealth reported the breach affects 4,115,802 individuals. The incident follows similar large-scale data breaches at other health-tech firms, including Aesto Health and CareCloud.