AdaptHealth confirmed on September 9 that a June cyberattack exposed the health data of 4,115,802 patients. That makes it one of the largest healthcare breaches disclosed this year. The Pennsylvania-based home medical equipment provider reported the number to the Department of Health and Human Services’ Office for Civil Rights, closing out a breach that the extortion group ShinyHunters claimed credit for back in June, then quietly walked away from.
What AdaptHealth Confirmed
AdaptHealth supplies sleep-apnea machines, oxygen equipment, hospital beds, and mobility devices through roughly 680 locations in all 50 states. Its own account of what happened, filed with the SEC on July 2, is fairly narrow: a threat actor compromised the authenticated session of a third-party contractor through social engineering around June 5, then used that access to reach AdaptHealth’s cloud-based business applications, including internal patient management systems and document storage.
The Leak Site Listing That Vanished
The attacker got in touch on June 15 to demand a ransom in exchange for silence. ShinyHunters added AdaptHealth to its dark web leak site around June 24 or 25. AdaptHealth decided the incident was material on June 27 and filed the 8-K five days later. Notification letters went out in mid-August. This month, the company gave federal regulators the final number: 4,115,802 people, with names, contact details, demographic information, health insurance information, and clinical health information exposed, plus passwords tied to insurance billing. No Social Security numbers, AdaptHealth says, because it doesn’t collect them in the affected systems. No financial account or payment card data either. And so far, no evidence the stolen data has been used against anyone.
One thing didn’t make it into any of AdaptHealth’s own statements. BleepingComputer reported this week that it could no longer find an AdaptHealth entry on ShinyHunters’ extortion site, which is usually a sign the group took the listing down itself. Neither side has said why, or whether money changed hands.
The Pattern Behind It
A Six-Company Warning From July
AdaptHealth isn’t an isolated case. Health-ISAC, the healthcare sector’s information-sharing group, warned members on July 31 that ShinyHunters was running a vishing campaign against healthcare and health-adjacent companies. It named six: Medtronic, iRhythm, OneMedical, DentaQuest, AdaptHealth, and Hims & Hers. The method hasn’t changed much since: call an employee, talk them into resetting a password or enrolling a new device, use that foothold to get into a single sign-on platform like Okta or Microsoft Entra, then pull data out of whatever cloud apps sit behind the login.
A Contractor’s Login, Not an Employee’s
AdaptHealth’s version of that attack has one wrinkle. The compromised session belonged to a contractor, not an AdaptHealth employee. Vishing aimed at a company’s own staff can at least be countered with training, phishing-resistant multi-factor authentication, and help-desk verification the company controls end to end. A contractor’s session sits partly outside that. The organization that owns the patient data usually can’t see how the vendor manages its own credentials, and has even less say in how fast that vendor notices something is wrong.
It’s also the fourth ShinyHunters-linked breach in recent weeks to follow this shape: a vishing or social-engineering foothold, an SSO or cloud-app compromise, bulk exfiltration, then a ransom sized to the target. ReliaQuest, Apollo Global Management, and McKesson all fit that pattern earlier this year. AdaptHealth is the first of the six Health-ISAC-named healthcare targets to put a real, federally filed number behind the claim, which makes it a decent benchmark for how big this particular campaign has gotten.
The Open Question
The disappearing leak-site listing deserves more scrutiny than it’s getting. The FBI and CISA have both discouraged ransom payments for years, and most large companies say, on the record, that they don’t pay. But leak-site listings don’t usually vanish on their own, and “no evidence of misuse” is a different claim than “the data is gone.” Until AdaptHealth or ShinyHunters says more, nobody outside that negotiation knows what happened, and that gap between the public non-payment position and the private outcome is exactly what keeps this kind of extortion profitable.
The Vendor Access Problem
The contractor problem is the lesson likely to outlast this specific breach. Healthcare providers have spent years hardening their own employees against social engineering while treating vendor and contractor accounts almost as an afterthought, often leaving them with standing access instead of scoped, time-limited credentials tied to one task. ShinyHunters has now shown, across six named targets, that it doesn’t need to breach a hospital or a medical supplier directly. It just needs to find the login nobody’s watching.
Expect the next few healthcare breach disclosures to trace back to a vendor’s compromised session rather than a provider’s own network. Procurement and security teams should start asking, out loud, who else holds a key to their patients’ data besides the people treating them.

