 |
Patient Protect |
|
HIPAA Pulse |
|
HIPAA PULSE
September 16, 2026 · Bi-Weekly Briefing
|
|
A 4.1 Million-Person Breach, a Vanished Leak Listing, and 2.8 Million More at a Genetics Lab
|
An attacker compromised a third-party contractor's authenticated session, then reached a medical equipment supplier's own systems. 4.1 million people. ShinyHunters — the group that claimed the DentaQuest breach — was also reported to have listed AdaptHealth.
AdaptHealth says the initial foothold was a socially engineered contractor session, which the attacker then used to reach AdaptHealth's own cloud applications. ShinyHunters was reported to have listed the company on its extortion site; that listing has since disappeared. We found no confirmed public release of the data. AdaptHealth has not confirmed who was behind the attack.
Also this window: a genetic testing company's intrusion reached 2.8 million people, including medical testing information and laboratory results.
|
|
4.1M
affected by AdaptHealth's breach, per the HHS OCR breach portal. The company says Social Security numbers and financial information were not involved.
|
|
Since the last issue, September 2
|
2
major HHS-listed breaches reviewed this window
|
~1 week
Baylor Genetics' confirmed network-access window, June 11–17
|
No SSNs
AdaptHealth says Social Security and financial-account data were not in the affected systems
|
No historical mega-breaches resurfaced with fresh dates this window — the check we run every issue came back clean this time.
|
|
Breach of Note: AdaptHealth
HHS OCR portal · 4,115,802 affected · Hacking/IT Incident · Healthcare Provider
AdaptHealth is a publicly traded supplier of home medical equipment — sleep apnea machines, oxygen equipment, hospital beds, mobility devices — serving patients nationwide through 668 locations in 48 states. A threat actor contacted the company on June 15, 2026, claiming to have obtained data from its systems. AdaptHealth says the initial foothold was a socially engineered contractor session. The attacker then used that authenticated access to reach AdaptHealth's cloud applications, including patient management and document storage.
ShinyHunters was reported to have listed AdaptHealth on its extortion site. That listing has since disappeared, and no confirmed public release of the stolen data has been reported. AdaptHealth has not publicly attributed the attack. AdaptHealth's SEC filing confirmed that data was exfiltrated, including a stored password file associated with insurance billing. Its August notice says the potentially affected information may have included names, contact and demographic information, health-insurance information and health information. The company says Social Security numbers and financial-account information were not involved. HHS OCR's portal lists 4,115,802 affected. Vermont's filing alone lists 48,090 affected residents.
AdaptHealth says the documented initial foothold was a compromised contractor session. If a contractor can log into systems holding PHI, that account belongs in your vendor-risk review.
Worth asking: Do any of your vendors rely on third-party contractors with access to your patients' data, and do you know how those contractors authenticate? Has your practice trained staff to recognize social-engineering attempts specifically, not just phishing emails? If a vendor's leak-site listing vanished without explanation, would you treat that as resolved or as unresolved? Get your free score.
|
|
A week-long intrusion at a genetic testing company affected 2.8 million people
Baylor Genetics, a Houston-based genomics and genetic testing company headquartered at the Texas Medical Center, detected suspicious activity around June 15, 2026. The investigation found an unauthorized party had accessed portions of its network between June 11 and 17. HHS OCR's portal lists 2,810,878 affected. Selected state filings list 248,430 in Texas, 56,636 in Massachusetts, 50,495 in Illinois, 27,243 in Washington, and 2,630 in Vermont. Notifications began August 14. The company says it is not aware of any confirmed identity theft or misuse tied to the incident. We found no public claim of responsibility. The potentially involved information includes medical testing information and laboratory results, alongside names, birth dates and, for a very limited subset of patients, Social Security numbers. You can replace a card number. You can't make an exposed lab result private again.
|
|
30-minute system check
Five items, each tied to something above.
| 1. |
Ask your vendors how their contractors authenticate. AdaptHealth's initial foothold was a compromised contractor session. Ask whether subcontractors with PHI access are covered by the vendor's own BAAs and access controls. |
|
| 2. |
Train staff on social engineering specifically, not just phishing. A phishing quiz that only covers suspicious email links won't prepare anyone for a convincing phone call or a fake login prompt. Ask what your own training actually covers. |
|
| 3. |
If you work with a genetic testing or diagnostic lab, ask what happens to results after the report is sent. Baylor Genetics says potentially involved information included laboratory test results, not just contact information. Confirm how long the lab retains results and related testing data, and who else can access them. |
|
| 4. |
When a vendor breach makes headlines, check what the company says wasn't affected, not just what was. AdaptHealth's specific statement that Social Security and financial data weren't involved is more useful to patients than a vague "some information may have been exposed." |
|
| 5. |
Don't treat a vanished leak listing as a resolved incident. ShinyHunters was reported to have listed AdaptHealth, then the listing disappeared with no explanation. Absence of public proof isn't the same as absence of harm. |
|
|
The free Patient Protect Score gives you a five-minute read on your ePHI flow, operational safeguards, and where to look first. No account needed.
|
|
| |
|
A word from Patient Protect, who pays for this newsletter to exist
Your vendors are your attack surface. Track them like it.
Vendor inventory with offboarding and data-disposition tracking. BAA lifecycle tracking, including breach-notification terms. Continuous risk analysis. $39/month, no contracts, 14-day free trial.
|
|
|
Worth reading elsewhere
|
|
AdaptHealth started with a contractor session. Baylor involved direct network access. Different attacks, but the practical questions are the same: who can get into systems holding PHI, and what is sitting there when they do?
Next Pulse drops September 30.
Editorial coverage at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.
|
 |
Patient Protect |
Chicago, IL · patient-protect.com · HIPAA Pulse
|
Instagram
LinkedIn
X
|
|
AdaptHealth's affected count and breach classification reflect the HHS OCR breach portal; incident mechanics and data categories reflect AdaptHealth's SEC filing and August 14 notice. Baylor Genetics' affected count and breach classification reflect HHS OCR; its June 11–17 access window and data categories reflect Baylor Genetics' public notice. State counts reflect state breach-notification filings and contemporaneous reporting based on those filings.
You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Manage email preferences · Unsubscribe · Privacy Policy
© 2026 Patient Protect LLC. All rights reserved.
|
|
|