breach
AdaptHealth Breach: Contractor Talked Into Handing Over Keys
2026-07-03

AdaptHealth, a Pennsylvania medical equipment company looking after more than 4.2 million patients across the US, has told the SEC that attackers wandered into its cloud environment by way of a third-party contractor and left with patient data on the way out.
The intruders reached internal patient management systems, document storage, and external electronic health record portals. What they took included a password file tied to insurance billing, along with personally identifiable information and protected health information for an unspecified number of patients. Social Security numbers and payment details appear to have been left alone.
How the company found out
AdaptHealth says it only learned of the theft when the attacker made contact on 15 June. By 27 June, having taken stock of the volume and sensitivity of what was gone, the company decided the incident was material enough to disclose to regulators. It has not said whether an extortion demand was made or paid, and no ransomware group has publicly claimed the job.
The contractor account has been disabled. Credentials have been reset. Extra access controls are now in place. AdaptHealth believes the incident is contained and says it has taken steps to reduce the risk of the stolen data being spread further, though it has been quiet on what exactly those steps involve.
The entry point is the story
There was no zero-day here. No exotic malware. No clever chain of exploits.
Someone with legitimate access to a healthcare company's cloud was convinced to hand over the keys. That is the whole plot. A contractor, presumably going about their day, was talked into doing something that ended with 4.2 million patients sitting inside the blast radius of that conversation.
This is not a novel technique. Social engineering has been the reliable workhorse of breach reports for years now, precisely because it keeps working. Attackers know that finding a bug in a well-patched cloud tenancy is hard. Finding a person who is tired, busy, or trusting is not.
The contractor problem
Healthcare organisations, like most large operations, run on a sprawling network of third parties. Billing providers, equipment suppliers, IT contractors, portal integrators. Each one is another set of credentials, another human with access, another potential conversation an attacker can start.
AdaptHealth has not named the contractor or explained how the social engineering played out. There's no public detail on whether it was a phishing email, a phone call, an MFA fatigue attack, or a well-crafted impersonation. What is clear is that the person on the other end of that interaction had enough access to matter, and enough trust to be believed when they used it.
- The stolen material includes a password file linked to insurance billing.
- Attackers reached patient management systems, document storage, and EHR portals.
- Social Security numbers and payment details were not affected, per AdaptHealth.
- The contractor account is now disabled and credentials reset.
The disclosure follows the SEC's four-day materiality rule with a bit of room to spare. What it doesn't answer is the question every affected patient will eventually ask: what conversation happened, and could it have gone differently?