iRhythm Data Breach: Hackers Stole Patient Info

▼ Summary
– iRhythm Holdings disclosed a data breach after hackers stole patient personal and health information from third-party-hosted business applications.
– The attackers demanded a ransom on June 9, 2026, to prevent the disclosure of stolen data, including proprietary and patient protected health information.
– The company determined the incident is material due to the volume of potentially affected data, which was exfiltrated from the applications.
– iRhythm confirmed the breach was caused by social engineering and does not affect its products, clinical systems, or patient safety.
– The company has not yet disclosed how many individuals were affected by the data exposure.
Digital healthcare provider iRhythm Holdings has confirmed a data breach in which hackers accessed patient personal and health information stored on third-party-hosted business applications. The company, whose cardiac monitoring service has analyzed more than 2 billion hours of curated heartbeat data from over 12 million patients, reported the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on Monday.
According to the filing, iRhythm discovered the breach on Sunday and immediately launched an investigation with external cybersecurity experts while activating its cybersecurity response plan to contain the threat. The attackers first contacted the company a week earlier, on June 9, demanding a ransom to prevent the public release of stolen health data. However, iRhythm did not attribute the attack to any specific threat actor or extortion group.
“On June 9, 2026, the Company received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information. The communications from the threat actor demanded payment in exchange for not publicly disclosing this information,” iRhythm stated. “Since receipt of the communications, the Company has confirmed that certain data was exfiltrated from those applications. On June 10, 2026, the Company determined that the incident is material in light of the volume of the potentially affected data.”
The company emphasized that there is no evidence the breach affected “its products, clinical or medical device systems, patient safety, manufacturing and distribution operations, financial reporting systems.” It noted that the threat actors gained access through social engineering and that iRhythm does not store patients’ payment card or financial account information. The breach also does not involve its clinical or medical device systems.
BleepingComputer reached out to an iRhythm spokesperson for additional details, including the number of individuals whose data was exposed, but did not receive an immediate response. This incident follows a similar disclosure last week from Danish pharmaceutical giant Novo Nordisk, the world’s largest insulin producer, which reported that hackers stole patient information from certain clinical trials after compromising internal IT systems.
(Source: BleepingComputer)




