Home medical equipment provider AdaptHealth disclosed that a June cyberattack exposed personal and health information belonging to more than 4.1 million patients, according to a filing with the HHS Office for Civil Rights.
The company said the breach stemmed from a social engineering attack that compromised a third-party contractor’s user session, giving a threat actor access to AdaptHealth’s cloud-based patient management and document storage systems. AdaptHealth first disclosed the intrusion in a July 2 SEC filing after the attacker contacted the company June 15 claiming to have stolen data.
In an Aug. 14 notice, AdaptHealth said the threat actor exfiltrated names, contact information, demographic data, health insurance information and health information, along with a password file tied to insurance billing. Social Security numbers, financial account information and payment card data were not affected, the company said.
AdaptHealth recently reported the number of affected individuals to HHS and said it notified all impacted patients for whom it had current contact information. The company is offering credit monitoring and identity protection services at no charge for at least 12 months.
The breach ranks among the largest healthcare data incidents reported to federal regulators this year, underscoring the exposure home health and durable medical equipment vendors face when third-party contractor access is compromised.