Breach taxonomy
Summary
AdaptHealth is investigating a security incident in which a threat actor gained unauthorized access to cloud-based business applications, including internal patient management systems and document storage platforms, and exfiltrated data including a stored password file associated with insurance billing; external electronic health record portals were also accessed. The company received a communication from the threat actor on June 15, 2026 claiming to have obtained data, and determined the incident material on June 27, 2026 due to the nature and potential volume of data at risk.
Tagging rationale
ThreatUnknown
Filing refers only to 'a threat actor' with no attribution -> UNKNOWN.
MethodsData Exfil
Filing confirms 'certain data was exfiltrated from its systems including a stored password file associated with insurance billing' -> DATA-EXFIL.