Healthcare Data Breaches Hit Vendor Systems
Coverage from DataBreacheToday, Rescana, and others

Healthcare providers and medical-service companies are disclosing breaches in which attackers stole patient personal information and protected health information from business applications, contractor accounts, and external electronic health record portals.
iRhythm and AdaptHealth both linked their incidents to social engineering and threat-actor extortion, while Ikron reported a ransomware incident involving separate intrusions into operational and health-record systems. The disclosures show that patient data exposure can occur outside core clinical infrastructure, while the full number of affected individuals and the precise data involved may remain unclear during investigations.
The main update is a reframing of the healthcare breach story around a third incident, Ikron's ransomware case, which now adds separate unauthorized intrusions and broader data categories. The overall picture also sharpens slightly around attack methods and affected systems, but the core theme remains the same.
The story now centers on specific confirmed incidents at iRhythm, AdaptHealth, and Ikron, with clearer evidence of how attackers gained access and what data was taken. The update also adds a named ransomware group, more concrete affected-person counts, and a stronger sense that investigations and regulatory fallout are still unfolding.
