4.1 Million Impacted by AdaptHealth Data Breach
AdaptHealth, a healthcare company serving over 680 facilities, suffered a data breach exposing the personal, health, and insurance information of 4.1 million individuals. The breach stemmed from a social engineering attack targeting a third-party contractor, and a separate, related breach at Baylor Genetics impacted an additional 2.8 million people, including employee data and financial information. The incidents highlight the increasing risk of healthcare data breaches and the need for robust security measures.
AdaptHealth, a healthcare company providing solutions and medical equipment to over 680 facilities across the United States, experienced a significant data breach. The attack, occurring in early June, granted a threat actor access to AdaptHealth’s cloud-based applications, including internal systems used for patient management and document storage. Following contact from the attacker, AdaptHealth confirmed the breach, revealing that a password file associated with insurance billing had been stolen. The company attributed the attack to social engineering, where a user session at a third-party contractor was compromised.
On August 14th, AdaptHealth announced that the hacker had exfiltrated names, contact and demographic information, as well as health and health insurance details. Importantly, the company stated that Social Security numbers and financial information were not affected. Simultaneously, the US Department of Health and Human Services (HHS) added AdaptHealth to its data breach portal.
Adding to the concerning trend, Baylor Genetics, a clinical genomics company, was also hacked in June, resulting in the theft of patients’ names, dates of birth, medical test data, health insurance information, and Social Security numbers. The incident also compromised the PII of Baylor Genetics’ employees, along with their financial information.
These two breaches, occurring within a short timeframe, underscore the vulnerability of the healthcare sector to cyberattacks and the potential for widespread exposure of sensitive patient data. The HHS continues to monitor and track these incidents as part of its ongoing efforts to protect patient information.