The AdaptHealth breach: 4.1 million patients, and what the letter means

AdaptHealth delivers CPAP supplies, oxygen and diabetes equipment to homes across the US. In September 2026 it put a number on the June break-in: 4,115,802 people, with their insurance and health details taken. Here is what was exposed, why you cannot check it online, and what to do while the letters go out.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

AdaptHealth, a large US home medical equipment supplier, reported to federal regulators that 4,115,802 people were affected by a break-in on 5 June 2026 that came through a contractor’s account. Names, contact details, demographic, insurance and health information were taken; Social Security numbers and bank details reportedly were not. Affected patients are getting letters with 12 months of free credit monitoring. No online tool can check this breach. Enrol in the monitoring, read your insurance statements for equipment you never got, and call back on a number you looked up before acting on any call about your supplies.

What AdaptHealth has said vs what has been reported

The left column comes from AdaptHealth’s own filings and notice. The right column is press reporting, kept separate so you can see which facts the company stands behind.

QuestionWhat AdaptHealth saidWhat has been reported
When it happenedAn intruder got in on 5 June 2026. AdaptHealth says a threat actor contacted it on 15 June claiming to hold patient files, and it disclosed the incident to the SEC in a Form 8-K dated 2 July.HIPAA Journal, BleepingComputer and SecurityWeek covered the 8-K and each later update.
How the intruder got inSocial engineering against a third-party contractor. The attacker took over the contractor’s session and reached cloud applications AdaptHealth uses for patient management and document storage.The attack was attributed to the ShinyHunters extortion group. The company’s entry was later removed from the group’s leak site.
How many people4,115,802, the figure AdaptHealth reported to the US Department of Health and Human Services.BleepingComputer published the count on 9 September 2026; SecurityWeek followed on 10 September.
What was takenNames, contact details, demographic information, health insurance information and health information, according to the notice posted on 14 August.Reporting on the HHS filing says Social Security numbers, payment card numbers and bank account details were not involved.
Misuse so farAdaptHealth says it is not aware of any actual or attempted misuse of the data.We have not found credible reporting that the files were published.
Letters and credit monitoringAffected people are being notified and offered 12 months of free credit monitoring and identity protection, with enrolment instructions in the letter.Not applicable.
LawsuitsNot addressed.Law firms announced investigations in July. We have not seen a certified class, and there is no settlement to claim.

Sources: AdaptHealth Form 8-K, 2 July 2026; AdaptHealth notice of 14 August 2026; the HHS Office for Civil Rights breach report; reporting by HIPAA Journal, BleepingComputer (9 September 2026), SecurityWeek and Security Magazine (10 September 2026). Status as of 23 September 2026.

1. What happened, in order

On 5 June 2026 an attacker got into AdaptHealth’s cloud systems through a contractor’s account. On 15 June the attacker contacted the company claiming to hold patient files. AdaptHealth reported a material cybersecurity incident to the SEC in a Form 8-K dated 2 July. On 14 August it posted a notice listing the data involved, and in early September it reported the breach to the Department of Health and Human Services: 4,115,802 people. BleepingComputer published the number on 9 September, SecurityWeek and Security Magazine on 10 September.

2. Who is in it

AdaptHealth’s patients: people who get CPAP supplies, home oxygen, diabetes supplies and other equipment delivered to the house. Many of them are older adults, and many rely on the equipment every day. That matters for what comes next, because the stolen files tell a caller who uses which equipment and which plan pays for it. If you look after a parent who has a CPAP machine or oxygen at home, read this page with them in mind.

3. What was taken, and what was not

Names, contact details, demographic information, health insurance information and health information. Reporting on the federal filing says Social Security numbers, card numbers and bank details were not part of it. That rules out the fastest kind of fraud, opening credit in your name with a stolen SSN, but leaves two others: medical identity theft, where someone uses your insurance, and phone scams built on real details about your equipment and coverage. Our medical data breach guide covers the first in depth.

4. The honest answer to “am I affected”

Only AdaptHealth can tell you, and it does so by letter. The files have not surfaced in the breach databases that email checkers search, so no online tool can confirm this one, and any site that claims to is guessing. What you can do is work out whether you are a patient: check the name on your equipment deliveries, supply invoices or insurance statements. If AdaptHealth is on them, treat yourself as possibly affected until a letter says otherwise.

5. What is worth doing now

Enrol in the free credit monitoring when the letter comes. Read the explanation-of-benefits statements from your insurer, or the Medicare Summary Notice, for equipment, supplies or visits you never received, and report anything wrong to the insurer. Consider a free credit freeze at Equifax, Experian and TransUnion; with no SSN in these files it is less urgent than after an SSN breach, but it costs nothing and blocks new accounts whatever else has leaked about you. If something has already been opened in your name, start at identitytheft.gov. Our step-by-step breach checklist puts these in order.

6. The calls and letters that will follow

The scam to expect is a call from “your equipment supplier” or “Medicare” about a CPAP recall, a replacement sensor or a lapse in coverage, asking you to confirm a Medicare number or pay a small fee to keep supplies coming. Hang up and call back on the number printed on your paperwork. The same goes for fake breach notices by email or text that ask you to verify your identity through a link. Our guide to reading a breach notice shows what a genuine letter contains.

7. If the letter is addressed to your parent

Older patients are the people this data describes best, and the people most often targeted by callers who already know a few true details. Talk through the rule of calling back on a looked-up number, offer to go over their insurance statements with them, and make sure they know a real supplier will not ask for a payment by gift card or wire. Their name, address and phone number are also listed on people-search sites, which is how a scammer turns a stolen patient file into a phone call. Our guide on protecting elderly parents from scams goes further.

The letter covers AdaptHealth. Check what else is out there.

Our free scan looks up your email in known breach databases (this one is not among them yet) and shows the home address, phone number and relatives listed about you on 499 broker and people-search sites, the details a scam caller needs to sound real. PersProtect files the removals and keeps checking.

Check my exposure — free →
Common questions

The AdaptHealth breach, answered

What is AdaptHealth, and why would it have my information?

AdaptHealth is one of the largest US suppliers of home medical equipment: CPAP machines and supplies for sleep apnoea, home oxygen, diabetes supplies such as continuous glucose monitors, and similar equipment. It operates in all 50 states. Most customers are referred by a doctor or come through their insurance plan, so people often do not know the company by name. If you or a parent received equipment or supplies delivered to your home in the last few years, AdaptHealth or one of the companies it bought may well be the supplier.

How do I find out whether I am one of the 4.1 million?

The letter is the answer. AdaptHealth is notifying the people involved by post, and the notice says what was taken and how to enrol in the free credit monitoring. The stolen files have not turned up in the breach databases that online checkers use, so no website, ours included, can look you up in this one. If you are an AdaptHealth patient and nothing arrives in the coming weeks, contact AdaptHealth using the number on your equipment paperwork or its own website.

No Social Security numbers were taken. Should I still worry?

Less than after an SSN breach, but yes. The files hold your insurance details and what equipment you use, which says a lot about your health. That is exactly the material for a convincing call: someone who knows your name, your plan and that you use a CPAP can pose as your supplier or your insurer and ask you to “confirm” a Medicare number or card to keep a shipment coming. Medical identity theft, where someone bills treatment to your insurance, starts from the same data.

Is the AdaptHealth breach letter I got real?

A genuine notice names the incident, lists the categories of data and gives an enrolment code for the credit monitoring along with a phone number. It will not ask you to pay anything, confirm your Social Security or Medicare number, or log in through a link. Check the phone number against AdaptHealth’s own website before you call, and type any address yourself. Fake breach notices appear within weeks of every large disclosure and copy the real wording closely.

Should I take the free credit monitoring?

Yes, it costs nothing. Just know its limits: monitoring reports new accounts after they are opened. It does not stop them, and it does not watch your medical claims. A credit freeze at the three bureaus stops new credit outright, and the explanation-of-benefits statements from your insurer are where medical misuse shows up first.

My parent is the patient. What should I do?

Open the post with them over the next few weeks and read the notice together, because a letter about a “data incident” is easy to put aside. Then do two things. Agree that any call about their equipment, supplies or insurance gets a callback on a number you looked up, never the one the caller gives. And look at their Medicare Summary Notices or insurer statements for equipment or services they never received.

Can I join a class action?

Firms are collecting names and signing up costs nothing, but there is no certified class and no settlement yet, and any payout is a long way off. Ignore messages saying compensation is waiting and asking for bank details or an SSN to release it; that scam follows every large healthcare breach. When a settlement opens it will appear on our list of open data breach settlements with the official claim site.

A scam call starts with your address and phone

Those are published on people-search sites regardless of any breach. See which sites list you right now — free, in about a minute.

Run my free exposure scan →