Skip to content
iRhythm Holdings Data Breach Exposes Patient Information

iRhythm Holdings Data Breach Exposes Patient Information

First seen 7 Oct 2026, 09:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 10:57 UTC
  • •Unauthorized access to iRhythm's systems detected on June 8, 2026.
  • •Personal and protected health information of patients may have been exposed.
  • •Edelson Lechtzin LLP is offering free case evaluations for affected individuals.

Edelson Lechtzin LLP is investigating a data breach at iRhythm Holdings, Inc., a heart-monitoring company. The breach was reported on June 10, 2026, after unauthorized access was detected on June 8, 2026, through social engineering targeting third-party applications. Affected individuals include patients whose personal and protected health information may have been compromised. Notifications to impacted individuals began on October 2, 2026. The breach is considered material due to the volume of data involved, though the total number of affected individuals has not been confirmed. Information potentially exposed includes names, contact details, insurance numbers, and dates of service. iRhythm has stated that no financial account or payment card information was stored and there is no evidence of identity theft. The investigation aims to determine the extent of the breach and potential class action claims.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-08
Unauthorized access detected
iRhythm Holdings detected unauthorized access to third-party-hosted applications through social engineering.
Natlawreview
2026-06-10
Incident disclosed to SEC
iRhythm disclosed the data breach incident to the U.S. Securities and Exchange Commission as material.
Globenewswire
2026-10-02
Notifications to affected individuals
iRhythm began notifying individuals whose data may have been compromised as part of the breach.
Natlawreview

More articles in this cluster (2)

Following this threat?

Track Edelson Lechtzin LLP in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Who is affected by the breach?
Patients whose personal and protected health information was maintained by iRhythm may be affected.
How did the breach occur?
The breach occurred through unauthorized access via social engineering targeting third-party-hosted applications.
What information may have been exposed?
Potentially exposed information includes names, contact details, insurance numbers, and dates of service.