iRhythm discloses data breach, says hackers stole patient info
iRhythm Holdings disclosed a data breach in which hackers stole patients’ personal and health information from third‑party applications used with its cardiac monitoring service. The attackers contacted the company on June 9 with ransom demands, and iRhythm confirmed data exfiltration on June 10, deeming the incident material due to the data volume. The breach reportedly does not affect iRhythm’s products or medical devices, and no payment card data were involved; the company is investigating with external cybersecurity experts.

iRhythm Disclosure: Hackers Exfiltrate Patient Data via Third-Party Applications
Publication Date: June 16, 2026
OverviewDigital health company iRhythm Holdings disclosed a data breach involving unauthorized access to personal and health information stored within third-party-hosted business applications. The incident centers on data used in the company’s cardiac monitoring service, which processes vast amounts of heartbeat data from a large patient population. Officials say there is no indication that the breach affected iRhythm’s medical devices, products, or patient safety, but the exposed data raises concerns about privacy and the security of outsourcing environments.
How the Breach Unfolded
- Access method: The attackers gained entry through social engineering that targeted the third-party applications used by iRhythm. The breach did not involve the company’s direct medical device systems or patient-facing clinical platforms.
- Data exposure pathway: Once inside, data exfiltration occurred from those third-party-hosted applications, enabling theft of personal and health information linked to patients.
- Scope of risk: iRhythm asserts that the breach did not involve payment card or financial account details stored by the company.
Timeline of Events
- June 9, 2026: The company received communications from a threat actor claiming possession of sensitive information, including patient data and other proprietary materials. The attackers demanded payment to avoid public disclosure of the stolen data.
- June 10, 2026: iRhythm determined the incident to be material in light of the volume of potentially affected data and proceeded with a formal investigation and breach response measures.
- June 16, 2026: iRhythm disclosed the breach publicly, noting that external cybersecurity experts were engaged and the company activated its breach response plan to contain and assess the incident.
Data Involved and Potential Impact
- Data types affected: The breach potentially exposed a range of information, including patient identifiers, personal information, and health data associated with iRhythm’s heart monitoring services.
- Volume and reach: iRhythm reports that its cardiac monitoring program has analyzed more than 2 billion hours of curated heartbeat data from over 12 million patients. The scale of data involved underscores the potential scope of exposure.
- No device or product impact: The company stated there is no evidence that the breach affected its products, clinical or medical device systems, patient safety, or the company’s manufacturing and distribution operations.
Scope of Access and Security posture
- Access vector: The attackers accessed information through social engineering techniques targeting third-party applications, rather than breaching iRhythm’s internal systems directly.
- Payment data: iRhythm clarified that it does not store patients’ payment card information or financial account data, and those assets were not implicated in the breach.
- Systems involved: The incident appears to be isolated to third-party-hosted applications associated with business operations, with no reported impact on the company’s core clinical or device platforms.
Response and Remediation Efforts
- Incident reporting and investigation: Upon discovery of the incident, iRhythm engaged external cybersecurity experts and activated its cybersecurity response plan to contain the breach and determine the extent of data exposure.
- Ongoing assessment: The company is conducting a formal review of affected systems and data flows, and it continues to seek additional information to quantify the number of individuals affected and the exact nature of exposed records.
- Communications with stakeholders: iRhythm has stated that it received ransom-related communications from the threat actor, but the company has not attributed the attack to any specific group or actor.
Context and Related Developments
- Industry context: The breach follows a separate disclosure by Novo Nordisk, the insulin producer, which reported a data breach involving clinical trial data stemming from compromised internal IT systems. The concurrent headlines highlight ongoing concerns about data security in healthcare and pharma sectors, particularly where sensitive information is handled within complex, multi-party environments.
- Public commentary and press inquiries: Journalistic entities reached out for additional details, including the number of individuals affected, but official responses were limited pending the ongoing investigation.
Current Status and Implications
- Status: As of the disclosure, iRhythm emphasizes that its products and patient safety are not believed to be compromised, while acknowledging that certain non-clinical data accessed via third-party applications has been exfiltrated.
- Implications for patients: The breach raises questions about the privacy and protection of health information stored in third-party systems and the resilience of vendor ecosystems used in digital health monitoring.
- Next steps for the company: The focus remains on completing the investigation, understanding the data scope, implementing additional containment measures, and communicating relevant findings to affected parties and regulators as appropriate.


