Skip to main content

AdaptHealth attributes a breach to a contractor's compromised account

AdaptHealth reported that an attacker obtained patient information after compromising a contractor's account with access to cloud applications and management systems through social engineering.

CybersecuritySeintec team2-3 min read
AdaptHealth attributes a breach to a contractor's compromised account

News summary

AdaptHealth reported that an attacker obtained patient information after compromising a contractor's account with access to cloud applications and management systems through social engineering.

Third-party accounts should have least-privilege permissions, expiration dates and conditional access. A contractor does not need to indefinitely retain the same level of privilege.

Source: Reuters — 27 July 2026

What happened

AdaptHealth reported that an attacker obtained patient information after compromising, through social engineering, the account of a contractor with access to cloud applications and management systems. The case is part of the same series of incidents recorded by Reuters among US companies.

The access did not come through a direct AdaptHealth employee, but through an external third party whose credentials granted entry to systems holding patient data.

What it teaches about managing contractors and suppliers

Contractors are often given broad access to work quickly, and those permissions are rarely reviewed as often as those of in-house staff. An attacker who compromises that account inherits the same level of access as the contractor.

The external origin of the access does not reduce the affected company's responsibility: the compromised data belongs to its patients, regardless of where the attacker got in.

What to review

Specific measures for third-party accounts:

  • Minimum permissions with an expiry date for external contractor accounts.
  • Access conditioned by device, location or duration of the service contract.
  • Regular review of which third-party accounts remain active and whether they are still needed.
  • Mandatory two-factor authentication on every external account with access to patient or customer data.

Frequently Asked Questions

Whose account was compromised?
An external contractor's account with access to AdaptHealth's cloud applications and management systems.
What information was affected?
Patient information, as reported by the company itself.
How can this risk be reduced with external suppliers?
By limiting their permissions to the minimum necessary, with a defined expiry and regular review of granted access.

Concepts mentioned in this article: Cloud

Every company has different risks and needs. At Seintec, we can analyse your infrastructure and propose a tailored solution, without over-scaling or complicating your environment. Consult us.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.