Security News

Medical Device Maker iRhythm Confirms Data Breach Affecting at Least 360,000 People

The Record · 10 Oct 2026
Key Takeaway Train staff to spot social engineering attempts, and review the security of any third-party-hosted business applications that hold customer or patient data.

Medical device company iRhythm has confirmed that the data of at least 360,000 people was stolen in a cyberattack. The company says the incident was detected on June 8, and investigators found that attackers had access to its systems between June 3 and June 8. They reached unidentified third-party-hosted business applications through a social engineering attack. iRhythm is best known for the Zio Patch, a chest-worn sensor used for long-term heart monitoring.

Breach notices show 298,647 people affected in Texas and 69,526 in South Carolina, with further notices filed in California. The company declined to give the full victim count. The stolen information includes names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service and dates of birth. iRhythm says its clinical systems, medical devices and operations were not affected, and it has no evidence the data has been or will be used for identity theft.

In a regulatory filing, iRhythm said it received messages from a threat actor claiming to hold sensitive data, including patient health information, and demanding payment to keep it private. No hacking group has publicly claimed the attack.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.