AdaptHealth data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
AdaptHealth, a U.S. home medical equipment and supplies company, said a cyberattack on June 5, 2026 gave an unauthorized party access to certain systems containing personal data. On June 15, the company received a message from a threat actor claiming to have taken data. In an SEC Form 8-K filed July 2, 2026, AdaptHealth said a social engineering attack compromised a user session belonging to a third-party contractor, and that the attacker accessed cloud-based business applications, including patient management systems, document storage, and certain external electronic health record portals.
On August 14, 2026, AdaptHealth reported the breach to the U.S. Department of Health and Human Services as affecting 4,115,802 people and began mailing notice letters. State filings include 48,090 Vermont residents. The company said it was not aware of any actual or attempted identity theft, fraud, or misuse, and it is offering free Kroll identity monitoring for at least 12 months.
AdaptHealth said it does not store Social Security numbers, financial account information, or payment card information in the affected systems. Its SEC filing did note that passwords associated with insurance billing were among the data taken.
Sources
- AdaptHealth Notice of Cybersecurity Incident, AdaptHealth
- AdaptHealth Corp. Form 8-K, July 2, 2026, U.S. Securities and Exchange Commission
- Breach Portal, U.S. Department of Health and Human Services Office for Civil Rights
- Submitted Breach Notification Sample: AdaptHealth, LLC, California Attorney General
- Security Breach Notices, Office of the Vermont Attorney General
- AdaptHealth confirms 4.1 million people exposed in July cyberattack, BleepingComputer
- 4.1 Million Impacted by AdaptHealth Data Breach, SecurityWeek
- AdaptHealth Data Breach Affects 4.1 Million Individuals, HIPAA Journal
What data was exposed
The following types of personal data were compromised:
- Names
- Contact information
- Demographic information
- Health insurance information, such as health plan name and policy number
- Health information, such as medical equipment orders and referring provider
- Passwords associated with insurance billing (per AdaptHealth's SEC filing)
Breach details
| Detail | Value |
|---|---|
| Breach name | AdaptHealth |
| Date | June 5, 2026 |
| Disclosed | July 2, 2026 (SEC Form 8-K); individual notices from August 14, 2026 |
| Accounts affected | 4,115,802 (reported to HHS) |
| Domain | adapthealth.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by AdaptHealth; it reflects a publicly reported security incident.
For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- If you received an AdaptHealth notice, enroll in the free Kroll monitoring using the instructions in your letter.
- Treat unexpected messages about CPAP or oxygen supplies, equipment orders, insurance billing, or "account updates" as possible phishing. Your name, contact details, and insurance information were exposed together.
- Verify any delivery, refund, or billing request by calling the number on your AdaptHealth paperwork or on adapthealth.com, not a number from an unexpected text or email.
- Review Explanation of Benefits statements for medical equipment or supply claims you don't recognize.
- If you have questions, call AdaptHealth's assistance line at (844) 958-8963 (weekdays, 8:00am to 5:30pm Central).
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- Got a breach email?
- First 48 hours after a data breach
- Dark web vs. data brokers
- What to do after a data breach
- Baylor Genetics breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.