4.1 Million Affected by AdaptHealth Data Breach
4.1 million individuals’ personal, health, and insurance data were compromised in a cybersecurity incident involving healthcare provider AdaptHealth. The organization, which operates 680 facilities nationwide, serves as a network of medical equipment companies offering healthcare solutions and equipment. A breach was detected in early June when a malicious actor infiltrated cloud-based applications, including internal systems for patient management and document storage. The attacker reportedly contacted the company following unauthorized access, leading to confirmation of the breach. AdaptHealth disclosed that a password file linked to insurance billing was stolen. The intrusion method involved social engineering tactics targeting a user session within a third-party contractor’s environment. On August 14, the company revealed that exfiltrated data included names, contact details, demographic information, and health and insurance records. However, it emphasized that Social Security numbers and financial data remained unaffected. The incident was reported to the U.S. Department of Health and Human Services (HHS), which documented 4,115,802 affected individuals. The breach was recently added to the HHS data breach portal. A separate incident at clinical genomics firm Baylor Genetics, also reported to HHS on August 14, impacted 2,810,878 individuals. This breach, traced to a June compromise, involved the theft of patient names, dates of birth, medical test results, health insurance details, and Social Security numbers. Employee information, including financial data, was also exposed. The breaches highlight ongoing vulnerabilities in healthcare infrastructure, with threat actors leveraging social engineering and third-party access to exploit cloud-based systems. Both incidents underscore the need for stringent access controls and continuous monitoring of vendor relationships to mitigate risks associated with data exposure.
