AdaptHealth Confirms Cybersecurity Attack
PLYMOUTH MEETING, Pennsylvania—AdaptHealth, a provider of home-based medical devices including CPAP machines, has revealed it was hit by a cyberattack resulting in data exfiltration last month, yet stressed that vital customer data such as payment card information was not compromised by the breach.
In a Form 8-K filed with the U.S. Securities and Exchange Commission, AdaptHealth said what they identified as a “threat actor” reached out, claiming to have obtained certain data from AdaptHealth’s systems.
The company said the attacker accessed certain cloud-based business applications, including internal patient management systems and document storage platforms. It then received a communication from the “threat actor” on June 15, claiming to have obtained data from its systems, and later confirmed that certain data had been exfiltrated. The affected data includes passwords associated with insurance billing, as well as certain personally identifiable information and protected health information of patients.
The company said it does not collect Social Security numbers in the affected systems and does not store individual financial account or payment card information.
AdaptHealth said that the incident stemmed from a social engineering attack that compromised a user session linked to a third-party contractor. The company said it has contained the incident by disabling the compromised account, resetting affected credentials and adding access controls, while continuing to assess the scope with external forensic teams.
AdaptHealth said it cannot yet determine the full financial impact, including remediation, legal, regulatory and notification costs, as well as possible reputational effects. The company said it maintains cybersecurity insurance that may cover certain losses.
Post navigation
OUR DIGITAL PARTNERS


