AdaptHealth attributes a breach to a contractor's compromised account
AdaptHealth reported that an attacker obtained patient information after compromising a contractor's account with access to cloud applications and management systems through social engineering.

News summary
AdaptHealth reported that an attacker obtained patient information after compromising a contractor's account with access to cloud applications and management systems through social engineering.
Third-party accounts should have least-privilege permissions, expiration dates and conditional access. A contractor does not need to indefinitely retain the same level of privilege.
Source: Reuters — 27 July 2026
What happened
AdaptHealth reported that an attacker obtained patient information after compromising, through social engineering, the account of a contractor with access to cloud applications and management systems. The case is part of the same series of incidents recorded by Reuters among US companies.
The access did not come through a direct AdaptHealth employee, but through an external third party whose credentials granted entry to systems holding patient data.
What it teaches about managing contractors and suppliers
Contractors are often given broad access to work quickly, and those permissions are rarely reviewed as often as those of in-house staff. An attacker who compromises that account inherits the same level of access as the contractor.
The external origin of the access does not reduce the affected company's responsibility: the compromised data belongs to its patients, regardless of where the attacker got in.
What to review
Specific measures for third-party accounts:
- Minimum permissions with an expiry date for external contractor accounts.
- Access conditioned by device, location or duration of the service contract.
- Regular review of which third-party accounts remain active and whether they are still needed.
- Mandatory two-factor authentication on every external account with access to patient or customer data.
Frequently Asked Questions
- Whose account was compromised?
- An external contractor's account with access to AdaptHealth's cloud applications and management systems.
- What information was affected?
- Patient information, as reported by the company itself.
- How can this risk be reduced with external suppliers?
- By limiting their permissions to the minimum necessary, with a defined expiry and regular review of granted access.
Concepts mentioned in this article: Cloud
Every company has different risks and needs. At Seintec, we can analyse your infrastructure and propose a tailored solution, without over-scaling or complicating your environment. Consult us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.