Home / The Long Read / Research
Long Read

AdaptHealth breach reached patient data through a third-party contractor's stolen credentials

AdaptHealth told the SEC that attackers reached patient data through a third-party contractor's stolen credentials, obtained by social engineering. The number of affected individuals is not yet confirmed. For third-party risk teams, contractor and vendor accounts are part of the attack surface.

AdaptHealth breach reached patient data through a third-party contractor's stolen credentials
TL;DR

AdaptHealth told the SEC that attackers reached patient data through a third-party contractor's stolen credentials, obtained by social engineering. The number of affected individuals is not yet confirmed. For third-party risk teams, contractor and vendor accounts are part of the attack surface.

AdaptHealth, a US home medical equipment provider, has told the Securities and Exchange Commission (SEC) that attackers reached its patient data through a third-party contractor. The company says a social engineering attack (manipulating a person, not exploiting software) let the intruder obtain the contractor's login credentials, then use them to enter cloud-based business applications holding patient information. AdaptHealth determined the incident to be material on 27 June 2026 and disclosed it in a Form 8-K. The lesson for other organisations: your contractors' and vendors' accounts are part of your attack surface, and one borrowed identity can reach the systems where regulated data lives.

AdaptHealth breach (June 2026): the entry point was a borrowed identity No system was broken into. A third-party contractor's stolen credentials reached the apps where patient data lives. Threat actor social engineering (people, not code) ShinyHunters (claimed, unverified) Third-party contractor credentials stolen AdaptHealth cloud business apps patient management systems document storage platforms external EHR portals Data exfiltrated Personally identifiable info (PII) Protected health info (PHI) Insurance-billing password file Affected individuals: not yet confirmed Not affected, per AdaptHealth: Social Security numbers (not collected), payment card and financial account data, operations and patient services Third-party risk, in one line: Attackers did not break a system. They borrowed a contractor's identity, and it reached the apps where patient data lives. Sources: AdaptHealth Form 8-K (SEC), The HIPAA Journal, The Register. Draft diagram for Breach Wire, Supplier Shield.

What happened

According to AdaptHealth's Form 8-K, a threat actor contacted the company on 15 June 2026, claiming to hold files with patient data. AdaptHealth's investigation found that the unauthorised access followed a social engineering attack on a third-party contractor, which allowed the contractor's credentials to be obtained. Using that access, the intruder reached cloud-based business applications, including internal patient management systems and document storage platforms, and external electronic health record portals. Files containing personally identifiable information (PII) and protected health information (PHI, health data protected under US law) were taken. A stored password file tied to insurance billing was also obtained. AdaptHealth says it does not collect Social Security numbers, and that payment card and financial account data are not stored in the affected systems. The number of affected individuals is not yet confirmed, and the review is ongoing. The ShinyHunters extortion group has claimed the attack and added AdaptHealth to its leak site. AdaptHealth has not named or confirmed the actor, so that claim is unverified.

Why it matters for third-party risk

The entry point was not AdaptHealth's own staff or software. It was a contractor's identity. This is the supplier-as-weak-link pattern in a pure form: the attackers did not break into a system, they borrowed a trusted account and walked in. Contractor and vendor credentials often carry standing access to core applications, yet they frequently sit outside the identity controls a company applies to its own employees. When a company measures its attack surface only by its own systems, that gap is invisible until it is used.

What teams should take from it

Treat third-party and contractor accounts as first-class identities. Enforce phishing-resistant multi-factor authentication on them, scope their access to the minimum each role needs, and monitor those sessions for unusual activity. Then map which vendor and contractor accounts can reach systems holding regulated data, because that inventory, not the org chart, is where breach impact is actually decided. To see how continuous vendor monitoring works, Acuna's supplier-risk resource sets out the practice.

FAQ

Was this a breach of AdaptHealth's own systems?

No. AdaptHealth says the access came through a third-party contractor's stolen credentials, obtained via social engineering, which then reached its cloud-based business applications.

What data was affected?

Files with PII and PHI, plus a stored password file tied to insurance billing. AdaptHealth says it does not collect Social Security numbers, and that payment card and financial account data were not held in the affected systems.

How many people are affected?

AdaptHealth has not confirmed a number. The company says the investigation is ongoing and the extent of data theft is still being determined.

What to do next

Want this applied to your supplier ecosystem? See the platform in action and map your top vendor risks live in one walkthrough.

Read next

ChainDrop npm worm hits 400-plus packages: one stolen login becomes a self-spreading supply-chain attack

ChainDrop npm worm hits 400-plus packages: one stolen login becomes a self-spreading supply-chain attack

A self-propagating worm named ChainDrop infected more than 400 npm packages, including keyv, flat-cache and cache-manager, Microsoft reported on 4 August 2026. The malware steals developer and cloud credentials, then uses stolen publishing tokens to poison further packages on its own. For third-party risk teams, it is a fourth-party exposure most vendor registers never capture.

Read article
Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen told the US SEC that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from its own network. The company concluded the incident was material on 29 July 2026. It says medicine supply was not affected. The lesson: data placed in a supplier's cloud is still the owner's breach to disclose.

Read article
Xsolis breach reached hospital patients through one shared healthcare AI vendor

Xsolis breach reached hospital patients through one shared healthcare AI vendor

A phishing attack at Xsolis, a US healthcare vendor that many hospitals and insurers use to review whether care is covered, exposed the data of about 1.4 million people. Patients at Mayo Clinic, UW Medicine and VHC Health were among those affected, because one vendor held records from many providers at once.

Read article
AdaptHealth breach: contractor credentials opened the door | Breach Wire | Supplier Shield