AdaptHealth data breach 2026: 4.1 million patients' personal, health, and insurance data stolen in June 2026. Disclosed September 10, 2026. Affected: names, DOB, addresses, SSN, medical records, insurance info. AdaptHealth is offering free credit monitoring (SecurityWeek, 2026).
Data last verified September 2026 from SecurityWeek and AdaptHealth disclosures.
AdaptHealth data breach — what we know
| Field | Detail |
|---|---|
| Company | AdaptHealth Corp. (NASDAQ: AHCO) |
| Records affected | 4.1 million patients |
| Discovery date | June 2026 |
| Public disclosure | September 10, 2026 (via SecurityWeek) |
| Data types | Name, DOB, address, SSN, medical records, insurance info, payment info |
| Remediation | Free credit monitoring and identity theft protection |
| Reporting | HHS Office for Civil Rights (HIPAA breach reporting) |
Source: SecurityWeek, September 10, 2026.
What is AdaptHealth?
AdaptHealth Corp. (NASDAQ: AHCO) is a leading home medical equipment (HME) provider in the US, headquartered in Plano, Texas. AdaptHealth provides: (1) Sleep therapy equipment (CPAP, BiPAP) for sleep apnea, (2) Oxygen therapy for COPD and other respiratory conditions, (3) Mobility equipment (wheelchairs, walkers, scooters), (4) Diabetes management supplies (CGMs, test strips), (5) Wound care supplies, (6) Home INR testing. AdaptHealth serves over 4 million patients annually through a network of 700+ locations across the US (AdaptHealth Corp., 2026).
Healthcare data breach impact
The AdaptHealth breach is the largest healthcare data breach disclosed in 2026 to date. Healthcare data breaches are particularly damaging because medical data cannot be easily changed (unlike credit card numbers or passwords). The breach exposes patients to: (1) Identity theft, (2) Medical identity theft (where attackers use the victim's identity to receive medical care), (3) Insurance fraud, (4) Targeted phishing (attackers use medical details to make phishing emails more convincing), (5) Blackmail in cases involving sensitive medical conditions (US Department of Health and Human Services, 2026).
Why healthcare is the most-breached industry
Healthcare is the most-breached industry in the US for several reasons: (1) Valuable data — medical records fetch $250-$1,000 on the dark web, far more than credit card numbers ($5-$15), (2) Aging infrastructure — many hospitals and providers still run outdated systems, (3) Multiple access points — healthcare has many interconnected systems (EMR, billing, insurance, labs), (4) High-pressure environment — patient care takes priority over security, (5) Insufficient cybersecurity investment — the healthcare industry invests less in cybersecurity than finance or retail (Cybersecurity and Infrastructure Security Agency, 2026).
What AdaptHealth is doing in response
AdaptHealth has: (1) Activated incident response protocols, (2) Engaged leading cybersecurity firms, (3) Notified the US Department of Health and Human Services (HHS) Office for Civil Rights, (4) Notified affected patients, (5) Offered free credit monitoring and identity theft protection services for affected individuals, (6) Implemented additional security controls to prevent similar breaches, (7) Coordinated with law enforcement (AdaptHealth Corp., 2026).
What to do if you are an AdaptHealth patient
- Sign up for the free credit monitoring and identity theft protection when AdaptHealth offers it (look for an email or letter from AdaptHealth in the coming weeks).
- Monitor your medical and insurance statements for unusual activity, especially for services you did not receive.
- Request your free annual credit report at annualcreditreport.com (free weekly through 2026).
- Place a fraud alert with the three credit bureaus (Equifax, Experian, TransUnion). One bureau will notify the other two.
- Consider a credit freeze for maximum protection (free, prevents new account opening).
- Watch for phishing emails referencing AdaptHealth, medical equipment, or your medical conditions.
- Check your Explanation of Benefits (EOB) from your health insurer for services you did not receive.
- File an identity theft report at identitytheft.gov if you detect fraud.
- Contact AdaptHealth's incident response line (when announced) for the latest updates.
HIPAA breach reporting timeline
HIPAA requires healthcare entities to: (1) Notify affected individuals within 60 days of discovering the breach, (2) Notify the HHS Secretary within 60 days for breaches affecting 500+ individuals, (3) Notify prominent media outlets for breaches affecting 500+ individuals in a state or jurisdiction, (4) File a breach report with the HHS Office for Civil Rights, which publishes a public 'Wall of Shame' list at hhs.gov/hipaa. AdaptHealth is in the process of meeting these requirements (US Department of Health and Human Services, 2026).
Medical identity theft warning signs
- Medical bills for services you did not receive.
- Calls from debt collectors about medical debts you do not recognize.
- Notices from your health insurer about benefits you did not claim.
- Errors on your Explanation of Benefits (EOB) statements.
- Denied insurance claims because your benefits are exhausted.
- Notice from your medical provider about treatment you did not receive.
Resources and next steps
Visit identitytheft.gov for free identity theft recovery resources. Check your credit reports at annualcreditreport.com. The FTC provides a free identity theft recovery plan at identitytheft.gov/immediate-steps. For medical identity theft, the FTC has specific guidance at identitytheft.gov/medical. For HIPAA breach information, the HHS Office for Civil Rights publishes the breach portal at hhs.gov/hipaa. The Identity Theft Resource Center provides free victim assistance at idtheftcenter.org.






