iRhythm Technologies Inc. Data Breach Investigation

Data Breach Blog

Data Breach

iRhythm Technologies Inc. Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

October 6, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at iRhythm Technologies Inc. The breach occurred on June 3rd–8th, 2026 and was discovered on August 7th, 2026. If you were affected, contact Almeida Law Group.

About iRhythm Technologies Inc.

iRhythm Technologies Inc. (now operating as iRhythm Holdings, Inc., NASDAQ: IRTC) is a publicly traded digital healthcare company headquartered in San Francisco, California. The company specializes in remote cardiac monitoring and arrhythmia detection, with its flagship product being the Zio wearable ECG monitor — a biosensor patch that continuously records heart rhythm for up to several weeks. iRhythm combines wearable technology with cloud-based analytics and AI-assisted analysis to help clinicians diagnose cardiac arrhythmias, and its service has been used to analyze more than two billion hours of heartbeat data from over twelve million patients. Because the company’s core business involves collecting and processing patients’ cardiac health data, the type of personal and medical information it holds is especially sensitive.

What Happened?

iRhythm Technologies Inc. was listed in a Texas Attorney General data security breach report filed on October 6th, 2026. According to that report and iRhythm’s own disclosures, attackers gained unauthorized access to third-party-hosted business applications used by the company through a social engineering attack. The breach occurred between June 3rd, 2026 and June 8th, 2026. On June 9th, 2026, a threat actor contacted the company claiming to possess stolen data and demanded a ransom payment to prevent its public disclosure. iRhythm confirmed that data was exfiltrated and declared the incident material in an SEC Form 8-K filed June 10th, 2026. The company completed its forensic investigation and began notifying affected individuals on October 2nd, 2026 — nearly four months after discovery. The total number of individuals affected is 8,179,772. No ransomware group has publicly claimed responsibility, and it is unknown whether iRhythm paid the ransom demand.

The compromised data includes patient names, addresses, email addresses, phone numbers, iRhythm patient account numbers, iRhythm device serial numbers, patient insurance numbers, dates of service, and dates of birth. The Texas Attorney General filing additionally lists medical information and health insurance information as affected data categories. iRhythm confirmed that no payment card or financial account data was involved, and that its clinical and medical device systems were not affected. As of October 6th, 2026, at least two law firms — Shamis & Gentile P.A. and attorneys working with ClassAction.org — have announced investigations into potential class action lawsuits on behalf of affected individuals. Separately, iRhythm’s 2020 SEC filing acknowledged that the company had in the past been subject to cyber-attacks and data breaches, though no prior large-scale breach was publicly documented.

Key Facts at a Glance

  • Company or Organization: iRhythm Technologies Inc.
  • Industry: Digital Healthcare / Medical Devices – Remote Cardiac Monitoring
  • Location: San Francisco, California
  • Incident type: Unauthorized access via social engineering; data exfiltration; ransom demand
  • Date of breach: June 3rd, 2026 – June 8th, 2026
  • Date breach discovered: August 7th, 2026
  • Date of consumer notification: October 2nd, 2026
  • Total persons affected: 8,179,772
  • Prior breach: iRhythm acknowledged past cyber-attacks and data breaches in a 2020 SEC filing without providing specifics
  • Litigation status: At least two law firms announced class action investigations as of October 6th, 2026; no complaint filed as of that date
  • Source: Texas Attorney General data security breach report; GlobeNewswire press release; BleepingComputer; SecurityWeek; HIPAA Journal; ClassAction.org

What Should You Do?

If you received a notification letter from iRhythm, review it carefully to confirm which of your data was involved. Because medical information and health insurance information were among the exposed data types, you should review any Explanation of Benefits statements you receive from your insurer and check your medical records for services you did not receive, which can be a sign of medical identity theft. Place a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — and request your free annual credit reports at AnnualCreditReport.com to watch for unfamiliar accounts or inquiries. Monitor your existing financial and insurance accounts for suspicious activity. If you believe your identity has already been misused, visit IdentityTheft.gov to create a personalized recovery plan.

Your Legal Rights

If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.