AdaptHealth Cybersecurity Incident
On June 5th, 2026, a targeted cyberattack involving data exfiltration occurred within AdeptHealth’s environment and persisted for ten days before being stopped. During this period, information for 4.1 million customers was pilfered. The claim that impacted individuals have been notified comes with the standard offer of a South Park BP parody “we’re sorry” year of identity monitoring.

Attacks will never stop, vulnerabilities will be exploited before they are identified, and defenders will consistently be underfunded as the financial cost of tooling, policy enforcement, and skilled personnel required to minimize the blast radius of such an event is greater than a token apology, a small fine, and a year of monitoring services. With a traditional retailer, options include no longer conducting business with the entity that didn’t value your information. Unfortunately, the goods purveyed by AdaptHealth and their subcontractors are placed behind medical subscriptions.
For devices such as CPAP/BiPAP machines or comparable solutions which require the guidance and medical professionals, procurement does need to be gated. The fact that accessories such as masks, filters, tubes, and replacement tanks are under the same controls is asinine. Switching to another provider can rapidly increase healthcare-related costs for a consultation, replacement subscription, and potential wholesale equipment changes. Companies such as AdaptHealth truly personify the prior meme due to the heroics required by people who want to make a change.
At a minimum, this is yet another opportunity for those who received notice to ensure that the password used for the AdaptHealth website is unique. If you’re using a password manager, this is also an opportunity to address any alerts related to compromised or weak passwords.
