ADAPTHEALTH disclosed a data breach in June 2026 after a threat actor gained access to its cloud-based applications, including internal patient-management and document-storage systems. The attacker reportedly used social engineering to compromise a user session at a third-party contractor, enabling reconnaissance and subsequent exfiltration from AdaptHealth’s environment.
In August, the company confirmed that names, contact and demographic information, and health and health-insurance data had been stolen, while Social Security numbers and financial information were not affected.
The incident affected a substantial number of individuals. AdaptHealth informed the US Department of Health and Human Services (HHS) that 4,115,802 people were impacted, and HHS subsequently added AdaptHealth to its breach portal. The breach also involved the theft of a password file linked to insurance billing.
By contrast, Baylor Genetics reported its own June breach with 2,810,878 individuals’ electronic protected health information compromised, including patient identifiers and health data, and, in some cases, employees’ data. The article notes these figures and timelines to illustrate the scale, focusing on the affected populations and the types of data involved, without detailing any confirmed exploitation beyond the disclosed exfiltration events. Practical responses are limited to the company’s public disclosures and the HHS breach portal listing.