{"id":204038,"date":"2026-06-17T10:44:56","date_gmt":"2026-06-17T07:44:56","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=204038"},"modified":"2026-06-17T10:44:56","modified_gmt":"2026-06-17T07:44:56","slug":"irhythm-data-breach-hackers-stole-patient-info","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/business\/204038\/irhythm-data-breach-hackers-stole-patient-info\/","title":{"rendered":"iRhythm Data Breach: Hackers Stole Patient Info"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; iRhythm Holdings disclosed a data breach after hackers stole patient personal and health information from third-party-hosted business applications.<br>&#8211; The attackers demanded a ransom on June 9, 2026, to prevent the disclosure of stolen data, including proprietary and patient protected health information.<br>&#8211; The company determined the incident is material due to the volume of potentially affected data, which was exfiltrated from the applications.<br>&#8211; iRhythm confirmed the breach was caused by social engineering and does not affect its products, clinical systems, or patient safety.<br>&#8211; The company has not yet disclosed how many individuals were affected by the data exposure.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">D<\/mark>igital healthcare provider <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/irhythm-holdings\/\" class=\"acp-entity-link\" data-entity-id=\"266808\" data-entity-category=\"Organization\" title=\"Learn more about iRhythm Holdings\" target=\"_blank\" rel=\"noopener noreferrer\">iRhythm Holdings<\/a><\/strong> has confirmed a <strong><a href=\"https:\/\/digitrendz.blog\/z\/trending-news\/235050\/ringcentral-breach-exposes-data-of-1-6m-accounts\/\" class=\"acp-article-link\" data-article-id=\"235050\" title=\"RingCentral breach exposes data of 1.6M accounts\" target=\"_blank\" rel=\"noopener noreferrer\">data breach<\/a><\/strong> in which hackers accessed patient personal and health information stored on third-party-hosted business applications. The company, whose <a href=\"https:\/\/digitrendz.blog\/z\/topic\/cardiac-monitoring-service\/\" class=\"acp-topic-link\" data-topic-id=\"237313\" title=\"Explore: cardiac monitoring service\" target=\"_blank\" rel=\"noopener noreferrer\">cardiac monitoring service<\/a> has analyzed more than <strong>2 billion hours of curated heartbeat data<\/strong> from over <strong>12 million patients<\/strong>, reported the incident in a filing with the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/u-s-securities-and-exchange-commission\/\" class=\"acp-entity-link\" data-entity-id=\"90630\" data-entity-category=\"Organization\" title=\"Learn more about U.S. Securities and Exchange Commission\" target=\"_blank\" rel=\"noopener noreferrer\">U.S. Securities and Exchange Commission<\/a> (<a href=\"https:\/\/digitrendz.blog\/z\/entity\/sec\/\" class=\"acp-entity-link\" data-entity-id=\"14682\" data-entity-category=\"Organization\" title=\"Learn more about SEC\" target=\"_blank\" rel=\"noopener noreferrer\">SEC<\/a>) on Monday.<\/p>\n\n<p class=\"wp-block-paragraph\">According to the filing, iRhythm discovered the breach on Sunday and immediately launched an investigation with external <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/business\/228303\/analog-devices-data-breach-disclosed-operations-unaffected\/\" class=\"acp-article-link\" data-article-id=\"228303\" title=\"Analog Devices data breach disclosed, operations unaffected\" target=\"_blank\" rel=\"noopener noreferrer\">cybersecurity<\/a> experts while activating its <strong>cybersecurity response plan<\/strong> to contain the threat. The attackers first contacted the company a week earlier, on June 9, demanding a ransom to prevent the public release of stolen health data. However, iRhythm did not attribute the attack to any specific threat actor or <a href=\"https:\/\/digitrendz.blog\/z\/topic\/extortion-group\/\" class=\"acp-topic-link\" data-topic-id=\"150071\" title=\"Explore: extortion group\" target=\"_blank\" rel=\"noopener noreferrer\">extortion group<\/a>.<\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;On June 9, 2026, the Company received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/fintech\/135123\/figure-data-breach-exposes-1-million-accounts\/\" class=\"acp-article-link\" data-article-id=\"135123\" title=\"Figure Data Breach Exposes 1 Million Accounts\" target=\"_blank\" rel=\"noopener noreferrer\">personal information<\/a>. The communications from the threat actor demanded payment in exchange for not publicly disclosing this information,&#8221; iRhythm stated. &#8220;Since receipt of the communications, the Company has confirmed that certain data was exfiltrated from those applications. On June 10, 2026, the Company determined that the incident is material in light of the volume of the potentially affected data.&#8221;<\/p>\n\n<p class=\"wp-block-paragraph\">The company emphasized that there is no evidence the breach affected &#8220;its products, clinical or medical device systems, patient safety, manufacturing and distribution operations, financial reporting systems.&#8221; It noted that the <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/business\/128640\/shinyhunters-new-mfa-bypass-fuels-data-theft\/\" class=\"acp-article-link\" data-article-id=\"128640\" title=\"ShinyHunters&#039; New MFA Bypass Fuels Data Theft\" target=\"_blank\" rel=\"noopener noreferrer\">threat actors<\/a> gained access through <strong><a href=\"https:\/\/digitrendz.blog\/z\/newswire\/business\/222434\/italy-fined-e1-7m-over-security-flaws-linked-to-two-data-breaches\/\" class=\"acp-article-link\" data-article-id=\"222434\" title=\"Italy fined \u20ac1.7M over security flaws linked to two data breaches\" target=\"_blank\" rel=\"noopener noreferrer\">social engineering<\/a><\/strong> and that iRhythm does not store patients&#8217; payment card or financial account information. The breach also does not involve its clinical or medical device systems.<\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/digitrendz.blog\/z\/entity\/bleepingcomputer\/\" class=\"acp-entity-link\" data-entity-id=\"32653\" data-entity-category=\"Organization\" title=\"Learn more about BLEEPINGCOMPUTER\" target=\"_blank\" rel=\"noopener noreferrer\">BleepingComputer<\/a> reached out to an iRhythm spokesperson for additional details, including the number of individuals whose data was exposed, but did not receive an immediate response. This incident follows a similar disclosure last week from Danish pharmaceutical giant <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/novo-nordisk\/\" class=\"acp-entity-link\" data-entity-id=\"23628\" data-entity-category=\"Organization\" title=\"Learn more about Novo Nordisk\" target=\"_blank\" rel=\"noopener noreferrer\">Novo Nordisk<\/a><\/strong>, the world&#8217;s largest insulin producer, which reported that hackers stole patient information from certain clinical trials after compromising internal IT systems.<\/p>\n\n<em>(Source: <a href='https:\/\/bleepingcomputer.com\/news\/security\/irhythm-discloses-data-breach-says-hackers-stole-patient-info\/' target='_blank'>BleepingComputer<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>iRhythm Holdings confirmed a data breach where hackers accessed patient personal and health information from third-party-hosted business applications, reported in an SEC filing on June 16, 2026. The attackers contacted iRhythm on June 9 demanding a ransom to prevent public release of stolen data,&#8230;<\/p>\n","protected":false},"author":1,"featured_media":204037,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[3253,3297,3327,3254],"tags":[222579,222580,222581,73548,8494],"entities":[59998,222582,16361,8990,57187],"class_list":["post-204038","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","category-cybersecurity","category-newswire","category-technology","tag-cardiac-monitoring","tag-irhythm-data-breach","tag-patient-health-information","tag-sec-filing","tag-social-engineering-attack","entity-bleepingcomputer-2","entity-irhythm-holdings","entity-novo-nordisk","entity-sec","entity-u-s-securities-and-exchange-commission"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/204038","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=204038"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/204038\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/204037"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=204038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=204038"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=204038"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=204038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}