Skip to content

iRhythm breach notices put patient data theft at 360,000+

iRhythm is filing state breach notices for a June social-engineering attack on third-party-hosted apps that exposed data on at least 360,000 cardiac-monitoring patients.

Published 3 min read

iRhythm Holdings, maker of the Zio ambulatory cardiac monitor, has begun filing state breach notifications for a June cyberattack that exposed patient data held in third-party business applications. State filings tallied this week put the count at at least 360,000 people — 298,647 in Texas and 69,526 in South Carolina, with California notices also filed. iRhythm has not published a single total. The company first disclosed the incident in an SEC Form 8-K, Item 1.05 on June 10; the scope is only now surfacing through state attorney-general filings reported by Recorded Future and Security Affairs.

Timeline

Per the 8-K, iRhythm identified unauthorized activity on June 8, 2026; a threat actor contacted the company on June 9; iRhythm determined the incident was material on June 10. Reporting puts the attacker's access window between June 3 and June 8. The filing says the affected data was "obtained through social engineering" and was limited to "certain third-party-hosted business applications."

What was exposed

The notifications list names, addresses, phone numbers, dates of birth, patient account numbers, device serial numbers, insurance (member/plan) numbers, and dates of service. iRhythm says no payment-card or financial-account data was involved, and it has "no evidence that any personal information has been or will be used to commit identity theft." The 8-K states the incident "does not involve the Company's clinical or medical device systems or connections to customers" — the Zio patches themselves were not touched.

Extortion status

iRhythm says it received a communication from a threat actor demanding payment to prevent disclosure. No group has publicly claimed the breach, and iRhythm has not named one. Treat the widely-reposted "8.2 million records" figure as unsupported — it traces to an aggregator headline not backed by the filing or the state counts. The verifiable floor remains the state-notification total of ~360,000.

Action checklist

If you were notified, or wore a Zio monitor in 2024–2026:

  1. Watch the mail for a notification letter and take the offered credit/identity monitoring — the exposed set (DOB + insurance number + account number) supports medical-identity and insurance fraud, not just card fraud.
  2. Flag your health insurer. Request an explanation-of-benefits review and set an alert for claims you didn't initiate; stolen member numbers enable fraudulent billing.
  3. Do not act on "iRhythm security" calls or emails asking you to verify details — breach notifications never ask for passwords, SSNs, or payment over the phone.

For security teams, the lesson is the vector, not the victim:

  1. Inventory your third-party-hosted business apps (the SaaS and outsourced back-office tier) and confirm each is behind phishing-resistant MFA, not SMS or push.
  2. Rehearse the help-desk social-engineering play — identity-verification steps for password/MFA resets are where this class of intrusion lands.

Context

This is a social-engineering-to-SaaS breach, not a product vulnerability: attackers talked their way into outsourced business applications rather than exploiting a CVE. It fits the dominant 2026 healthcare pattern — the damage sits in the third-party and back-office tier, and victim counts arrive months later through state attorney-general portals rather than vendor disclosure. iRhythm's clinical systems held; its vendor applications did not. The reporting gap between the June 8-K and this week's 360,000-person tally is itself the story: materiality to shareholders was declared in June, but the people whose cardiac-care records were taken are only being told now.

Related stories