← BACK TO FEED
healthcare data breachsocial engineeringSEC disclosurethird-party riskcloud security

AdaptHealth Blames Social Engineering After Patient Data Walks Out the Door

Medical equipment provider AdaptHealth suffered a cyberattack in which criminals used social engineering to compromise a third-party contractor and gain access to the company's cloud systems. Attackers stole sensitive patient data, including personally identifiable information, protected health information, and a password file linked to insurance billing, though Social Security numbers and payment details are believed to be unaffected. AdaptHealth disclosed the breach to the SEC on June 27, deeming it material due to the potential volume of data at risk, while investigations into the full scope of the incident are ongoing.

Home medical equipment provider AdaptHealth has told the SEC that attackers used social engineering to compromise its cloud systems and make off with sensitive patient data, including what the company describes as a password file tied to insurance billing.

The Pennsylvania-based firm, which supplies respiratory, sleep, and diabetes equipment to over 4.2 million patients across the US, filed its disclosure on Thursday. According to the filing, the attackers didn't go after AdaptHealth directly. Instead, they targeted a third-party contractor, sweet-talked their way in, and used that foothold to reach the company's cloud environment and the business applications sitting inside it.

The breach surfaced on June 15 when the attacker apparently contacted the company and announced the theft themselves. Whether that contact came with a ransom demand attached, AdaptHealth isn't saying. No cybercrime group has publicly claimed responsibility either.

Once the company realised what had happened, it killed the contractor's account, reset credentials, and bolted on additional access controls. It believes the breach is now contained, which is exactly what every breached company says.

Beyond the billing-related password file, personally identifiable information and protected health information belonging to an unspecified number of patients were also taken. The company says Social Security numbers and payment card details don't appear to have been caught up in it, which is something at least.

By June 27, AdaptHealth had concluded the incident was material given the nature and potential volume of the data involved, triggering the SEC disclosure obligation. The exact scale of the breach remains unclear, with investigations still ongoing to determine how many patients are affected.

The company added, in suitably vague corporate terms, that it has taken steps to reduce the risk of the stolen data being spread or misused. What those steps actually look like is anyone's guess.

This is the kind of attack that should make any organisation rethink how much access it hands to third-party contractors and how carefully it monitors that access. Social engineering works precisely because humans are the weakest link, and no amount of perimeter security fixes that.

READ NEXT
This Cybersecurity Index Tracks Real Breaches and Refuses to Invent a Grand TotalNadMesh Botnet Is Raiding Exposed AI Services for Cloud Keys, and the Numbers Don't Add UpRansomware Knocks Out Fairlife Milk Production Across the US