iRhythm says social-engineering breach let hackers steal patient health information from third-party business apps

iRhythm disclosed a data breach after hackers stole patient personal and health information from business applications hosted by a third party. The company said the attackers contacted it on June 9, 2026 with a ransom demand and it later confirmed data was exfiltrated; iRhythm says the intrusion involved social engineering and did not affect its cardiac monitoring devices, clinical systems, payment-card data, manufacturing, or distribution operations.
Why it matters: This affects healthcare patients whose protected health information may now be exposed or used in scams and identity abuse. Healthcare organizations and vendors should review third-party app access, harden staff against social-engineering attacks, and watch for follow-on extortion or phishing tied to stolen patient data.

Sources

iRhythm Confirms Data Stolen in Hack
Eduard Kovacs 2026.06.16 97% relevant
This article is a direct update on the same iRhythm incident and adds that the company has now confirmed some data was actually stolen after initially disclosing the social-engineering breach involving third-party-hosted business applications and a ransom demand.
Cardiac monitor maker's security skips a beat as data thieves go for the jugular
2026.06.16 99% relevant
This article reports the same incident and adds details from iRhythm's SEC filing: unauthorized activity was detected June 8, the extortion message arrived June 9, the company deemed the incident material on June 10, and iRhythm says clinical systems, medical devices, and customer connections were not accessed.
iRhythm discloses data breach, says hackers stole patient info
Sergiu Gatlan 2026.06.16 100% relevant
This article appears to be the first tracked disclosure of iRhythm's own breach event, including the company’s SEC filing, attack vector, and confirmation that patient data was exfiltrated.
← Back to all stories