Almeida Law Group is investigating a data breach at AdaptHealth, LLC. The breach occurred on June 5th–15th, 2026 and was discovered on June 15th, 2026. If you were affected, contact Almeida Law Group.
About AdaptHealth, LLC
AdaptHealth, LLC (NASDAQ: AHCO) is a publicly traded, full-service home medical equipment company headquartered in Conshohocken, Pennsylvania. It provides healthcare-at-home solutions including home medical equipment, diabetes supplies, sleep therapy products such as CPAP machines, respiratory therapy, mobility products, wound care, non-invasive ventilation, and nutritional support. The company operates approximately 668 locations across 48 states and serves roughly 4.8 million patients annually, partnering with hospitals, physician practices, and insurance companies. Because the company handles patient records, medical information, and health insurance data, a breach of its systems carries significant risk of harm to the patients it serves.
What Happened?
AdaptHealth, LLC was listed in a Texas Attorney General data security breach report (record ID BR-0005258, published August 14th, 2026). The breach involved unauthorized access to cloud-based business applications containing patient names, addresses, dates of birth, medical information, health insurance information, and other data. A total of 4,115,802 individuals were affected nationally. AdaptHealth notified consumers by U.S. mail, publication in print media, and posting to its website.
According to AdaptHealth’s SEC Form 8-K filed July 2nd, 2026, a threat actor contacted the company on June 15th, 2026, claiming to possess company data. The breach was caused by a social engineering attack that compromised a third-party contractor’s user session, granting the attacker access to cloud-based business applications, including internal patient management systems, document storage platforms, and external electronic health record system portals. AdaptHealth confirmed that stored password files associated with insurance billing, as well as personally identifiable information and protected health information, were exfiltrated. Importantly, the company stated that the compromised systems did not contain Social Security numbers, individual financial account information, or payment card data. Patient services were not materially disrupted. The extortion group ShinyHunters listed AdaptHealth on its data leak site around June 24th–25th, 2026, claiming responsibility for the attack, but AdaptHealth has not confirmed this attribution and it remains an unconfirmed attacker-side claim. A putative class action lawsuit was filed against AdaptHealth in the U.S. District Court for the Eastern District of Pennsylvania by July 10th, 2026, with multiple additional law firm investigations announced. A separate securities-law investigation has also been announced by Holzer & Holzer, LLC.
Key Facts at a Glance
- Company or Organization: AdaptHealth, LLC
- Industry: Healthcare – Home Medical Equipment Provider
- Location: Conshohocken, Pennsylvania
- Incident type: Social engineering attack; unauthorized access to cloud-based systems; data exfiltration
- Date of breach: June 5th, 2026 – June 15th, 2026
- Date breach discovered: June 15th, 2026
- Date of consumer notification: July 2nd, 2026 (SEC Form 8-K); consumer notices by mail and publication followed
- Total persons affected: 4,115,802
- Litigation status: Putative class action filed July 10th, 2026, in the U.S. District Court for the Eastern District of Pennsylvania; multiple additional law firm investigations announced; separate securities-law investigation by Holzer & Holzer, LLC
- Source: Texas Attorney General data security breach report (BR-0005258); TechTarget; HIPAA Journal; Law360
What Should You Do?
If you received a notice from AdaptHealth, act promptly to protect yourself. Review any Explanation of Benefits statements from your health insurer and check your medical records for services you did not receive, as medical information and health insurance information were among the data types confirmed as compromised. Place a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion—to make it harder for anyone to open accounts in your name. Monitor your existing accounts closely for unusual activity and request your free annual credit reports at AnnualCreditReport.com. If you believe your information has already been misused, visit IdentityTheft.gov for step-by-step guidance on reporting and recovery. Because the company confirmed that Social Security numbers and financial account or payment card data were not in the affected systems, your immediate fraud-prevention focus should center on health insurance and medical identity fraud.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.