AdaptHealth Corp.
bd_bdea54b1108c7028 · schema v1 · pii pii-v1
Full breach record for AdaptHealth Corp. →AdaptHealth Corp. filed an 8-K on June 27, 2026, disclosing a material cybersecurity incident. A threat actor gained unauthorized access to cloud-based business applications, including patient management systems, via a social engineering attack compromising a third-party contractor's session. The actor exfiltrated data including insurance billing passwords, PII, and PHI. The incident has been contained, law enforcement was notified, and the scope of affected individuals remains undetermined.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 15, 2026
Discovered
Jun 27, 2026
Scope determined
Jul 2, 2026
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Washington State AGbd_2a63e7918c132c152026-08-14 · +42dVerified
- California State AGbd_4e721acad23217052026-08-14 · +42dVerified
- HHS OCRbd_dc9d666fdb7b14f22026-08-14 · +42dVerified
- Texas State AGbd_dca8d9fe3c84e6e72026-08-14 · +42dVerified
Show 1 more filing ↓Show fewer ↑up to 42d gap
- Vermont State AGbd_e8b8399c6e13ad642026-08-14 · +42dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Jul 2, last Aug 14 (VT) — a 42-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.