iRhythm Notified Patients of June Data Breach

The company confirmed unauthorized access to patient data, though medical device functionality remained unaffected.

Updated on Oct. 2, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a modular server rack in navy and cream, evoking cybersecurity infrastructure.
iRhythm has begun notifying patients after an internal investigation confirmed that unauthorized parties accessed business applications and downloaded patient data in June. AI Illustration. Upload story photo >

Live Poll

Do you trust healthcare technology companies to securely manage your sensitive personal information?

iRhythm has begun notifying individuals after an internal investigation confirmed that unauthorized parties accessed business applications and downloaded patient data. The breach occurred between June 3 and June 8, 2026.

Why it matters

The incident highlights the ongoing cybersecurity risks facing healthcare technology companies that manage extensive patient health records. iRhythm states that no medical devices or patient safety systems were compromised during the unauthorized access.

The incident involved the exfiltration of patient names, contact information, insurance numbers, dates of service, dates of birth, and device serial numbers. iRhythm confirmed that no financial or payment card information was stored on the compromised systems.

The players

iRhythm

A San Francisco-based digital health company that produces wearable cardiac monitoring technology and cloud-based analytics services.

The details

iRhythm implemented an incident response plan and retained external cybersecurity professionals to perform a forensic investigation after detecting unauthorized access to business applications on June 8, 2026. This investigation identified that the breach occurred through unauthorized activity within those specific applications. The company noted that the compromise did not interfere with the clinical operations of its medical devices.

Timeline

  1. June 3-8, 2026: Unauthorized individuals accessed and downloaded data.

  2. June 8, 2026: iRhythm detected the unauthorized access.

  3. June 15, 2026: iRhythm filed a Form 8-K regarding the financial impact.

  4. October 2, 2026: The company began notifying affected individuals.

The Tech Race

This incident follows the compliance reporting requirements established by the HIPAA Breach Notification Rule. It underscores the ongoing struggle to secure health-focused digital infrastructure against increasingly sophisticated exfiltration attempts.

Affected individuals can contact the company via its dedicated call center at 1-844-770-7175. The line is open daily from 8:00 a.m. to 8:00 p.m. to provide information and address concerns regarding the breach.

The takeaway

While iRhythm maintains that device safety remains uncompromised, patients should monitor their insurance statements for unauthorized activity. Those affected should continue to check the official notification portal for updates regarding identity protection services.

Further reading

For broader context on how medical firms address system vulnerabilities, visit Cybersecurity.

More information

Review the full details of the incident on the iRhythm data incident information page.

Live Poll

Do you trust healthcare technology companies to securely manage your sensitive personal information?