Breach taxonomy
Summary
AdaptHealth is investigating a security incident in which a threat actor gained unauthorized access to cloud-based business applications, including internal patient management systems and document storage platforms, and exfiltrated data including a stored password file associated with insurance billing; external electronic health record portals were also accessed. The company received a communication from the threat actor on June 15, 2026 claiming to have obtained data, and determined the incident material on June 27, 2026 due to the nature and potential volume of data at risk.
Tagging rationale
ThreatUnknown
Filing refers only to 'a threat actor' with no attribution -> UNKNOWN.
MethodsData Exfil
Filing confirms 'certain data was exfiltrated from its systems including a stored password file associated with insurance billing' -> DATA-EXFIL.
AssetsPersonal DataConfidential Biz
Access to 'internal patient management systems and document storage platforms' and external EHR portals puts patient data at risk -> PERSONAL-DATA; exfiltrated password file for insurance billing -> CONFIDENTIAL-BIZ.
EffectsInfo Privacy Loss
Material data compromise with no disclosed operational disruption -> INFO-PRIVACY-LOSS.
Impact
Company determined the incident material due to nature and potential volume of patient data at risk; no operational disruption disclosed -> score 3.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 1.05 Material Cybersecurity Incidents. AdaptHealth Corp. (the "Company") is investigating a security incident whereby a threat actor gained unauthorized access to Company systems and exfiltrated certain data therefrom. Upon learning of the incident, the Company promptly activated its incident response procedures, launched the investigation with the support of external advisors and cybersecurity experts to assess and contain the threat and notified law enforcement. While the investigation is ongoing, the Company has been able to confirm certain facts about the incident, and on June 27, 2026, the Company determined that the incident is material, due to the nature and potential volume of the data that is at risk. Specifically, based on information obtained to date, the Company believes that a threat actor gained unauthorized access to certain of the Company's cloud-based business applications, including certain internal patient management systems and document storage platforms. On June 15, 2026, the Company received a communication from a threat actor claiming to have obtained certain data from the Company's systems. The Company has confirmed that certain data was exfiltrated from its systems including a stored password file associated with insurance billing; the Company also has confirmed that certain external electronic health record system portals were accessed by the threat actor.