AdaptHealth, a Pennsylvania healthcare company, was linked to a reported hacking/IT incident in June 2026. The company stated the incident was discovered on June 27, 2026, and was material due to the nature and potential volume of data involved. The breach originated via a social engineering attack compromising a user session of a third-party contractor. AdaptHealth filed a Form 8-K on July 2, 2026, reporting the material cybersecurity event to regulators.
The available incident data indicates that names, health records, and health insurance information, along with passwords associated with insurance billing, Personally Identifiable Information (PII) and Protected Health Information (PHI) may have been involved. Social Security Numbers (SSN), individual financial account information, and payment card information were not exposed. The exact number of affected individuals is not yet determined and is still under investigation by external forensic teams. The company has not yet issued a final, detailed official breach notification letter to patients as the full scope of data exfiltrated is still under investigation.
Details on specific state health privacy notifications are not yet public, and the number of individuals notified is currently unknown. Information regarding the full financial impact of the breach, including remediation, legal, regulatory, and notification costs, is pending.