
Digital healthcare firm iRhythm Holdings has revealed a data breach in which hackers obtained patients' personal and medical information stored on third-party-operated business applications.
The company noted that its cardiac monitoring service has processed over 2 billion hours of curated heartbeat data from more than 12 million patients.
In a Monday filing with the U.S. Securities and Exchange Commission (SEC), iRhythm stated it identified the incident a day earlier, leading it to start an investigation alongside external cybersecurity specialists and implement its cybersecurity response plan to contain the breach.
It further indicated that the attackers made contact one week earlier, on June 9, demanding a ransom to avoid the online release of stolen health data, but did not link the attack to any specific threat actor or extortion group.
"On June 9, 2026, the Company received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information. The communications from the threat actor demanded payment in exchange for not publicly disclosing this information," iRhythm said.
"Since receipt of the communications, the Company has confirmed that certain data was exfiltrated from those applications. On June 10, 2026, the Company determined that the incident is material in light of the volume of the potentially affected data."
The company also mentioned that it has found no evidence the incident impacted "its products, clinical or medical device systems, patient safety, manufacturing and distribution operations, financial reporting systems," and noted that the threat actors accessed the data through social engineering.
iRhythm added that it does not retain patients' payment card or financial account details, and that the breach does not involve its clinical or medical device systems.
BleepingComputer contacted an iRhythm spokesperson for additional details about the incident, including how many individuals had their personal and patient data compromised in the breach, but no response was immediately provided.
Danish pharmaceutical giant Novo Nordisk, the world's leading insulin manufacturer, also revealed a data breach last week after hackers stole patient information from certain clinical trials in an incident involving compromised internal IT systems.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
Pharma giant Novo Nordisk discloses breach of clinical trials data
7-Eleven confirms data breach claimed by the ShinyHunters gang
Instructure reaches 'agreement' with ShinyHunters to stop data leak
Council of Europe investigates ShinyHunters data breach claims
Infinite Campus data breach affects 137,000 school staff accounts