FEDERALItem 1.05 · mandatorySocial EngineeringPhishingStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainSupply Chain (3P Vendor)CREDENTIALSPIIPHILowContained
AdaptHealth Corp.
bd_bdea54b1108c7028 · schema v1 · pii pii-v1
Full breach record for AdaptHealth Corp. →AdaptHealth Corp. filed an 8-K on June 27, 2026, disclosing a material cybersecurity incident. A threat actor gained unauthorized access to cloud-based business applications, including patient management systems, via a social engineering attack compromising a third-party contractor's session. The actor exfiltrated data including insurance billing passwords, PII, and PHI. The incident has been contained, law enforcement was notified, and the scope of affected individuals remains undetermined.
SEC clockMateriality determined Jun 27, 2026 → Filed Jul 2, 20265d ✓ SEC 4-day OK17 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1725255/000110465926080297/ahco-20260627x8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 2, 2026
- Raw hash
- 797f9e5c05b647d09b90e35f12d5cf7a59cf5eba4d38958716663683c581f9ea
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- AdaptHealth Corp.norm: adapthealth
- SEC CIK
- 0001725255
Victim entity
- Name
- AdaptHealth Corp.norm: adapthealth
- SEC CIK
- 0001725255
Incident
- Discovered
- Jun 15, 2026
- Materiality determined
- Jun 27, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPIIPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 5d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 27, 2026→ Filed: Jul 2, 20265d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.