Skip to content
Security & Trust

iRhythm says patient data was stolen from business apps, not clinical systems

The company says clinical systems and devices were unaffected. At least 360,000 people still had personal data taken.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
iRhythm says patient data was stolen from business apps, not clinical systems

Photo: Marta Branco / Pexels

In brief
  • iRhythm says at least 360,000 people had data stolen in a June attack that reached third-party-hosted business applications through social engineering.
  • The company says clinical systems and devices were unaffected, yet the stolen data included insurance numbers, device serial numbers and dates of birth.
  • Leaders should map which outside-hosted business apps hold regulated data, and who can be talked into granting access to them.

A company can say its clinical systems were unaffected and still lose its patients' personal data. That is the lesson of the iRhythm breach. The line between 'clinical' and 'business' systems matters to engineers. It matters far less to the person whose insurance number was stolen.

What iRhythm has said

iRhythm makes the Zio Patch, a chest sensor that monitors heart rhythm over long periods. According to The Record, the company has begun filing breach notices in several states. It says at least 360,000 people were affected.

360,000
People affected, at least
Source: iRhythm breach notices, reported by The Record (October 9, 2026)

State filings give the largest counts. iRhythm reported 298,647 people in Texas and 69,526 in South Carolina. It also filed notices in California. A spokesperson declined to give the full number of victims.

298,647
People affected in Texas
Source: iRhythm breach notices, reported by The Record (October 9, 2026)

An investigation found the intruders had access between June 3 and June 8. The stolen data includes names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service and dates of birth.

How the attack worked

The Record reports that the attackers got in through social engineering. That means they persuaded a person to give them access, rather than breaking software. They reached what the report calls unidentified third-party-hosted business applications. These are programs run by outside vendors that the company uses for daily work. The report does not name them.

The attackers then downloaded data. In a June filing with the U.S. Securities and Exchange Commission, iRhythm said it received messages from a threat actor claiming to hold sensitive data. The messages demanded payment in exchange for not disclosing it. The company later confirmed that certain data was taken.

The sources describe data theft and a payment demand. They do not describe locked or encrypted systems. No hacking group has publicly claimed the attack.

Why 'clinical systems unaffected' is not the whole answer

The company says clinical systems and devices were unaffected and service was not disrupted. It also says its products, manufacturing and distribution were not hit, and that its finances were not disturbed. As evidence on that last point, The Record notes that iRhythm reported $224.2 million in Q2 revenue. All of this is the company's own account. The report offers no independent check.

June 3 to June 8
Window of unauthorized access
Source: iRhythm statement, reported by The Record (October 9, 2026)

Even on that account, the data tells a different story. Patient account numbers, insurance numbers and device serial numbers are patient records. They sat in business applications hosted by outside vendors, which iRhythm sets apart from its clinical systems. The thesis here is simple: the perimeter people defend is not always the perimeter where the data lives.

Think of a hospital that locks its operating rooms but leaves the records office door open. Nothing in surgery changes. The patients' files are still gone.

A pattern in one sector

The Record says dozens of medical device companies have suffered cyber incidents over the past two years. Eight other manufacturers are named as targets, including Medtronic, Stryker and Zoll. The report says those attacks together leaked sensitive medical data on millions of people and caused supply chain problems.

That is the reporter's account of the sector. It does not show that iRhythm's attackers are linked to any of those cases.

Questions for your team

First, which outside-hosted business applications hold personal or health data? Could your team list them quickly? Second, who can log in to them, and how does your help desk confirm that a caller is who they claim to be?

Third, if one of those apps is emptied, how fast can you say whose data was in it? iRhythm said it notified people once the scope was verified. Its June filing confirmed that data was taken. The state notices followed this week. The sources do not explain the gap between those dates. Ask how long your own process would take.

Fourth, does your breach statement describe harm to customers, or only harm to operations? iRhythm says it has no evidence the data has been or will be used for identity theft. For the people affected, the stolen data is still out of their hands.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.

Share this insight