AdaptHealth Blames Social Engineering After Patient Data Walks Out the Door
Home medical equipment provider AdaptHealth has told the SEC that attackers used social engineering to compromise its cloud systems and make off with sensitive patient data, including what the company describes as a password file tied to insurance billing.
The Pennsylvania-based firm, which supplies respiratory, sleep, and diabetes equipment to over 4.2 million patients across the US, filed its disclosure on Thursday. According to the filing, the attackers didn't go after AdaptHealth directly. Instead, they targeted a third-party contractor, sweet-talked their way in, and used that foothold to reach the company's cloud environment and the business applications sitting inside it.
The breach surfaced on June 15 when the attacker apparently contacted the company and announced the theft themselves. Whether that contact came with a ransom demand attached, AdaptHealth isn't saying. No cybercrime group has publicly claimed responsibility either.
Once the company realised what had happened, it killed the contractor's account, reset credentials, and bolted on additional access controls. It believes the breach is now contained, which is exactly what every breached company says.
Beyond the billing-related password file, personally identifiable information and protected health information belonging to an unspecified number of patients were also taken. The company says Social Security numbers and payment card details don't appear to have been caught up in it, which is something at least.
By June 27, AdaptHealth had concluded the incident was material given the nature and potential volume of the data involved, triggering the SEC disclosure obligation. The exact scale of the breach remains unclear, with investigations still ongoing to determine how many patients are affected.
The company added, in suitably vague corporate terms, that it has taken steps to reduce the risk of the stolen data being spread or misused. What those steps actually look like is anyone's guess.
This is the kind of attack that should make any organisation rethink how much access it hands to third-party contractors and how carefully it monitors that access. Social engineering works precisely because humans are the weakest link, and no amount of perimeter security fixes that.