AdaptHealth, LLC Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do
AdaptHealth, LLC has disclosed a data breach that occurred on June 5, 2026, exposing the personal and medical information of 9,214 individuals. Washington Attorney General’s notice urges affected people to review the details and contact the company or their health plan to determine whether their data was involved and what protective steps to take.
A data breach notice filed with the Washington State Attorney General shows that AdaptHealth, LLC has reported an incident affecting 9,214 people, with the company notifying Washington residents that personal and health-related information may have been exposed. For anyone who has used AdaptHealth services or shared medical and insurance details with the firm, the practical stakes are straightforward: identifiers that can be reused for fraud, insurance misuse, or targeted scams may now sit outside the company’s control.
Public detail is limited to what appears in that filing. The incident itself is dated June 5, 2026; the notice to the Attorney General is dated August 14, 2026. Named data types include name, full date of birth, health insurance policy or ID number, medical information, and protected health information owned or licensed by a HIPAA covered entity. How the intrusion occurred, what systems were involved, and whether every listed field was confirmed for every person are not further described in the disclosed record.
Inside the incident
According to the Washington Attorney General filing, AdaptHealth, LLC reported a data breach and notified affected Washington residents. The filing places the incident on June 5, 2026, and the report date as August 14, 2026. The number of people affected is stated as 9,214.
The notice lists the categories of information exposed as name, full date of birth, health insurance policy or ID number, medical information, and protected health information owned or licensed by a HIPAA covered entity. No public detail in the provided record describes the technical method of access, the duration of unauthorized access, whether data was exfiltrated in bulk or selectively, or whether encryption or other controls limited what an unauthorized party could use. Those points remain undisclosed.
What is established is the regulatory path: a formal notice to the state Attorney General tied to Washington residents, with the data categories and headcount above. Anything beyond that filing—such as internal investigation findings, third-party forensic conclusions, or claims by external parties—is not part of the facts given here.
How a breach like this happens
Incidents that expose health and insurance data often follow familiar patterns, even when a specific case does not name a method. Organizations that bill insurers, coordinate durable medical equipment, or manage patient records typically store identity fields alongside clinical and coverage details. Attackers who gain a foothold—through stolen credentials, phishing that yields remote access, compromised vendor connections, misconfigured cloud storage, or malware on internal systems—may reach databases, document stores, or backup sets that hold those fields together.
Once inside, the path is often lateral movement to higher-value systems, copying of files or database extracts, and quiet exfiltration. In other cases the exposure is accidental: a system left reachable from the internet, an email sent to the wrong recipient, or a partner receiving more data than needed. Ransomware groups sometimes pair encryption with theft and later claim to publish or sell the data; other actors simply resell identity and insurance packages on criminal markets. No threat group is attributed in the AdaptHealth filing, so none should be assumed here.
Health-sector breaches are consequential because the same record often contains both durable identifiers (name and date of birth) and context that makes social-engineering or insurance fraud easier. Background of this kind explains why notices list medical and insurance fields together; it does not establish how this particular incident unfolded.
AdaptHealth, LLC and its sector
AdaptHealth, LLC operates in the health-care services space associated with home medical equipment and related patient support. Companies in this sector routinely handle patient demographics, insurance eligibility and policy identifiers, clinical notes or device-related medical information, and other protected health information subject to HIPAA when they are covered entities or business associates.
That mix of data is why a breach notice from such an organization matters beyond a generic credential dump. Insurance policy numbers and medical details can support fraudulent claims, benefit diversion, or highly convincing phishing that references real treatment or equipment. Name and full date of birth anchor credit, medical, and government identity checks. When a HIPAA-covered data set is involved, regulators and patients treat the event as a privacy and safety issue, not only a financial one.
The Washington filing does not itself prove negligence or assign legal fault; it documents notification and the categories the company reported as exposed. Sector context simply clarifies why those categories carry elevated real-world weight.
The information in question
The filing names the following as among the information exposed: name, full date of birth, health insurance policy or ID number, medical information, and protected health information owned or licensed by a HIPAA covered entity. Those are the only data types established by the disclosed record.
Organizations like AdaptHealth typically also hold addresses, contact numbers, device or order histories, and billing artifacts; whether any of those appeared in this incident is unconfirmed in the facts provided and should not be stated as fact. Exact file formats, record counts per field, or samples of what was taken are not described in the notice summary given here.
The real-world impact
For affected individuals, the concrete risks track the named fields. Name combined with full date of birth supports identity verification abuse. Health insurance policy or ID numbers can be misused to attempt false claims, obtain services under someone else’s coverage, or open related accounts. Medical information and broader protected health information can fuel targeted scams, embarrassment, discrimination concerns, or blackmail-style contact, and they are difficult to “reset” the way a password can be reset.
For the organization, consequences typically include regulatory scrutiny under state breach laws and HIPAA-related obligations, notification and support costs, potential contractual issues with payers and partners, and reputational harm among patients who depend on continuity of equipment or care coordination. The filing does not state dollar losses, lawsuits, or enforcement outcomes; those remain outside the provided facts.
Impact is uneven: some people may see no misuse; others may face months of monitoring insurance explanations of benefits, credit activity, and unexpected medical bills. Calm, early checking reduces the window in which fraud can run unnoticed.
Were you affected?
If you are a current or former AdaptHealth patient or customer—especially a Washington resident—treat the June 5, 2026 incident date and the August 14, 2026 notice as reason to verify your status with official company communications rather than with unsolicited calls or links. Practical first steps include:
- Read any breach letter carefully for the exact data categories tied to you and for any offer of credit or identity monitoring.
- Watch insurance explanations of benefits and claim denials for services you did not receive; report anomalies to your insurer promptly.
- Place fraud alerts or freezes with major credit bureaus if name and date of birth were involved, and document any suspicious medical bills.
- Use unique passwords and multi-factor authentication on patient portals and email accounts tied to health care.
- Be skeptical of phone or email outreach that cites the breach and asks for more personal data or payment.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets elsewhere online. That check does not replace AdaptHealth’s official notice list, but it can show whether your email is circulating in broader dumps and help you prioritize password changes and monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ASOS US Sales LLC Data Breach Notice (Washington Attorney General)Nebraska Orthopaedic Center (Aesto, LLC) Data Breach Notice (Washington Attorney General)Turner Construction Data Breach Notice (Washington Attorney General)Lennar Mortgage, LLC Data Breach Notice (Washington Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.