AdaptHealth discloses June cyberattack resulting in patient data exposure
AdaptHealth disclosed in a July 2 SEC Form 8-K that a June 15 cyberattack led to data exfiltration from its cloud applications. The company said patient data and PHI, including stored password files tied to insurance billing, were exposed, but no Social Security numbers or payment card/account data were compromised. It attributed the breach to social engineering of a contractor session and says the incident is contained while investigations continue.
How this was made
The 30-second read
Why it matters
The disclosure frames the incident as material by 27 June, confirms containment actions (account disablement, credential resets, added access controls), and notes ongoing investigation with dataset scope still being determined.
Market read
Traders can reassess ADAP’s breach-related risk premium immediately based on the new primary disclosure and the stated (limited) exclusions of SSNs and payment card data.
What to watch
The breach involved stored password files tied to insurance billing mandates and PHI; the eventual cost driver may be remediation, customer/partner notifications, and any downstream claims/regulatory findings rather than the initial data categories alone.
Background
AdaptHealth filed an SEC Form 8-K disclosing a June cyberattack involving cloud-based applications and a social-engineering compromise of a third-party contractor user session.
Market effects
Reinforces heightened cyber risk across home medical device and healthcare services, potentially increasing compliance/remediation scrutiny for peers.
US healthcare providers may see broader investor focus on HIPAA/PHI handling and third-party contractor access controls.
Limited direct global read-through, but contributes to the ongoing cross-industry pattern of healthcare-targeted cyber incidents.
Counterpoint
Because the company asserts no SSNs or payment card/account data were exposed, the market may over-discount the event relative to actual financial/legal exposure.
Key entities
- companyAdaptHealth
Home-based medical device provider that disclosed a June cyberattack with patient data exposure via an SEC 8-K.
- regulatory_filingSEC Form 8-K
Primary-source disclosure mechanism used to report the material cybersecurity incident and its asserted data impact.

