HIPAA Pulse by Patient Protect logo

HIPAA Pulse by Patient Protect

Archives
Log in
September 16, 2026

HIPAA Pulse | Sept 16

HIPAA Pulse — September 16, 2026
A social-engineering attack compromised a contractor session at a medical equipment supplier. ShinyHunters — the group that claimed DentaQuest — was also reported to have listed AdaptHealth, then the listing disappeared. Plus: 2.8 million affected at Baylor Genetics. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Patient Protect
HIPAA Pulse

HIPAA PULSE

September 16, 2026  ·  Bi-Weekly Briefing

A 4.1 Million-Person Breach, a Vanished Leak Listing, and 2.8 Million More at a Genetics Lab

An attacker compromised a third-party contractor's authenticated session, then reached a medical equipment supplier's own systems. 4.1 million people. ShinyHunters — the group that claimed the DentaQuest breach — was also reported to have listed AdaptHealth.

AdaptHealth says the initial foothold was a socially engineered contractor session, which the attacker then used to reach AdaptHealth's own cloud applications. ShinyHunters was reported to have listed the company on its extortion site; that listing has since disappeared. We found no confirmed public release of the data. AdaptHealth has not confirmed who was behind the attack.

Also this window: a genetic testing company's intrusion reached 2.8 million people, including medical testing information and laboratory results.

4.1M

affected by AdaptHealth's breach, per the HHS OCR breach portal. The company says Social Security numbers and financial information were not involved.

Since the last issue, September 2

2

major HHS-listed breaches reviewed this window

~1 week

Baylor Genetics' confirmed network-access window, June 11–17

No SSNs

AdaptHealth says Social Security and financial-account data were not in the affected systems

No historical mega-breaches resurfaced with fresh dates this window — the check we run every issue came back clean this time.

Open the live dashboard Free · No account · Updated nightly

Breach of Note: AdaptHealth

HHS OCR portal  ·  4,115,802 affected  ·  Hacking/IT Incident  ·  Healthcare Provider

AdaptHealth is a publicly traded supplier of home medical equipment — sleep apnea machines, oxygen equipment, hospital beds, mobility devices — serving patients nationwide through 668 locations in 48 states. A threat actor contacted the company on June 15, 2026, claiming to have obtained data from its systems. AdaptHealth says the initial foothold was a socially engineered contractor session. The attacker then used that authenticated access to reach AdaptHealth's cloud applications, including patient management and document storage.

ShinyHunters was reported to have listed AdaptHealth on its extortion site. That listing has since disappeared, and no confirmed public release of the stolen data has been reported. AdaptHealth has not publicly attributed the attack. AdaptHealth's SEC filing confirmed that data was exfiltrated, including a stored password file associated with insurance billing. Its August notice says the potentially affected information may have included names, contact and demographic information, health-insurance information and health information. The company says Social Security numbers and financial-account information were not involved. HHS OCR's portal lists 4,115,802 affected. Vermont's filing alone lists 48,090 affected residents.

AdaptHealth says the documented initial foothold was a compromised contractor session. If a contractor can log into systems holding PHI, that account belongs in your vendor-risk review.

Worth asking: Do any of your vendors rely on third-party contractors with access to your patients' data, and do you know how those contractors authenticate? Has your practice trained staff to recognize social-engineering attempts specifically, not just phishing emails? If a vendor's leak-site listing vanished without explanation, would you treat that as resolved or as unresolved? Get your free score.

A week-long intrusion at a genetic testing company affected 2.8 million people

Baylor Genetics, a Houston-based genomics and genetic testing company headquartered at the Texas Medical Center, detected suspicious activity around June 15, 2026. The investigation found an unauthorized party had accessed portions of its network between June 11 and 17. HHS OCR's portal lists 2,810,878 affected. Selected state filings list 248,430 in Texas, 56,636 in Massachusetts, 50,495 in Illinois, 27,243 in Washington, and 2,630 in Vermont. Notifications began August 14. The company says it is not aware of any confirmed identity theft or misuse tied to the incident. We found no public claim of responsibility. The potentially involved information includes medical testing information and laboratory results, alongside names, birth dates and, for a very limited subset of patients, Social Security numbers. You can replace a card number. You can't make an exposed lab result private again.

30-minute system check

Five items, each tied to something above.

1.

Ask your vendors how their contractors authenticate. AdaptHealth's initial foothold was a compromised contractor session. Ask whether subcontractors with PHI access are covered by the vendor's own BAAs and access controls.

2.

Train staff on social engineering specifically, not just phishing. A phishing quiz that only covers suspicious email links won't prepare anyone for a convincing phone call or a fake login prompt. Ask what your own training actually covers.

3.

If you work with a genetic testing or diagnostic lab, ask what happens to results after the report is sent. Baylor Genetics says potentially involved information included laboratory test results, not just contact information. Confirm how long the lab retains results and related testing data, and who else can access them.

4.

When a vendor breach makes headlines, check what the company says wasn't affected, not just what was. AdaptHealth's specific statement that Social Security and financial data weren't involved is more useful to patients than a vague "some information may have been exposed."

5.

Don't treat a vanished leak listing as a resolved incident. ShinyHunters was reported to have listed AdaptHealth, then the listing disappeared with no explanation. Absence of public proof isn't the same as absence of harm.

The free Patient Protect Score gives you a five-minute read on your ePHI flow, operational safeguards, and where to look first. No account needed.

Get your free score Free · No account · ~5 minutes
 

A word from Patient Protect, who pays for this newsletter to exist

Your vendors are your attack surface. Track them like it.

Vendor inventory with offboarding and data-disposition tracking. BAA lifecycle tracking, including breach-notification terms. Continuous risk analysis. $39/month, no contracts, 14-day free trial.

Start free trial See pricing

Worth reading elsewhere

  4.1 Million Impacted by AdaptHealth Data Breach

Covers the HHS count, the contractor-session mechanics, the June timeline, and what AdaptHealth says was not involved. Source: SecurityWeek.

  Millions of patients warned after DNA testing data breach

Includes the national Baylor Genetics count and several state-level totals drawn from breach filings reviewed by Hearst Television's National Consumer Unit. Source: Cybernews.

AdaptHealth started with a contractor session. Baylor involved direct network access. Different attacks, but the practical questions are the same: who can get into systems holding PHI, and what is sitting there when they do?

Next Pulse drops September 30.

Editorial coverage at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.

Patient Protect

Chicago, IL  ·  patient-protect.com  ·  HIPAA Pulse

Instagram LinkedIn X

AdaptHealth's affected count and breach classification reflect the HHS OCR breach portal; incident mechanics and data categories reflect AdaptHealth's SEC filing and August 14 notice. Baylor Genetics' affected count and breach classification reflect HHS OCR; its June 11–17 access window and data categories reflect Baylor Genetics' public notice. State counts reflect state breach-notification filings and contemporaneous reporting based on those filings.

You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Manage email preferences  ·  Unsubscribe  ·  Privacy Policy

© 2026 Patient Protect LLC. All rights reserved.

Don't miss what's next. Subscribe to HIPAA Pulse by Patient Protect:
Older → HIPAA Pulse | Sept 2nd
Instagram
Twitter
LinkedIn
YouTube