United States healthcare firm reports massive patient data breach
PUBLISHED Jun 16, 2026, 5:42 AM ET
Read, Watch or Listen
iRhythm Holdings, a U.S.-based digital healthcare company specializing in cardiac monitoring, has reported a major cybersecurity incident exposing personal and protected health information of approximately 12 million patients. The company disclosed the breach in a U.S. Securities and Exchange Commission filing on Monday, June 15, 2026. According to iRhythm, attackers gained unauthorized access to third-party-hosted business applications, not its internal clinical or medical device systems. The threat actors contacted the company on June 9, 2026, claiming data theft and demanding ransom. iRhythm initiated its cybersecurity incident response plan, engaged external experts, and notified law enforcement and regulators as investigations continue.
By Neha R. | JQJO News
Timeline of Events
- June 9, 2026 Hackers contact iRhythm demanding ransom
- June 9, 2026 Attackers claim exfiltrated patient information
- June 14, 2026 Company formally discovers cybersecurity incident
- June 14, 2026 Cybersecurity incident response plan activated
- June 14, 2026 External forensic cybersecurity experts engaged
- June 15, 2026 Breach disclosed in SEC filing
- June 15, 2026 Law enforcement and regulators notified
News Intelligence
- Your privacy could be at stake. If you're one of iRhythm's 12 million patients, your personal and health data might be exposed. It's a good time to review your credit report and watch for any suspicious activity.
Comments