iRhythm Data Breach Impacts Hundreds of Thousands of Patients
Biosensor firm iRhythm disclosed a data breach affecting at least 360,000 individuals, with sensitive personal and health information accessed by attackers.

Medical device manufacturer iRhythm has confirmed that the personal data of at least 360,000 individuals was compromised in a cyberattack that occurred on June 8, 2026. The company, known for its Zio Patch cardiac monitoring device, began notifying affected individuals and state regulators this week about the breach.
The incident involved unauthorized access to third-party systems where iRhythm hosted business applications. Hackers gained access between June 3 and June 8, 2026, through a social engineering attack targeting these external platforms. The compromised information includes names, addresses, phone numbers, patient account numbers, device serial numbers, insurance information, dates of service, and dates of birth.
While iRhythm has filed breach notices in multiple states, including Texas (298,647 individuals) and South Carolina (69,526 individuals), the company has not disclosed the total number of victims nationwide. A spokesperson stated that the company responded promptly upon detecting the unauthorized access and notified affected parties and regulators once the scope was verified.
According to an 8-K filing with the Securities and Exchange Commission (SEC), iRhythm received communications from a threat actor claiming to possess proprietary data, protected health information, and other personal information. The threat actor demanded payment in exchange for not publicly disclosing this data. The company has since confirmed that data was indeed exfiltrated from the affected applications.
Despite the breach, iRhythm emphasized that the incident did not impact its clinical systems, medical devices, or operational services. The company also reported no disruption to its manufacturing or distribution processes and stated that its financial performance remained unaffected, with Q2 revenue reported at $224.2 million.
While the attackers downloaded the compromised information, iRhythm stated that it has found no evidence to suggest that the personal data has been or will be used for identity theft. No hacking group has publicly claimed responsibility for the attack.
This incident highlights the ongoing vulnerability of the healthcare and medical device sectors to cyberattacks. Numerous companies in this space, including Medtronic, Boston Scientific, and Stryker, have experienced similar breaches in recent years, leading to the exposure of sensitive medical data and disruptions to supply chains.
iRhythm's disclosure underscores the critical need for robust security measures, particularly for third-party vendors handling sensitive patient information. The company's response, including prompt notification and investigation, is a standard procedure following such incidents, though the full impact on affected individuals remains to be seen.