AdaptHealth, LLC Data Breach Notice (California Attorney General)
If you were named in this filing, here’s what’s now in circulation.
AdaptHealth, LLC notified California residents of a data breach in a filing reported to the California Attorney General on August 14, 2026. The filing puts the incident itself on June 05, 2026.
If you received a breach notification from AdaptHealth, your personal information was included in an incident the company reported to the California Attorney General. The filing lists personal information as exposed but does not disclose the exact data fields involved. No passwords, no government identifiers such as Social Security numbers, and no permanent biographic details that cannot be reissued were exposed.
This is genuinely good news. Because no credentials were exposed and no unchangeable identifiers were listed, the immediate risk to your accounts at AdaptHealth itself is limited. The exposure centers on demographic and medical-related personal information that retains value for identity thieves over years, not days. The record does not state how many people were affected.
What the Filing Actually Lists
The California Attorney General filing names only one broad category: personal information. It does not break that down into specific elements such as dates of birth, addresses, phone numbers, medical record numbers, insurance details, or treatment information. The letter you received is the only document that can tell you precisely which pieces of your data were included. If your letter arrived, read it carefully; its absence is also meaningful because AdaptHealth is required to notify affected individuals directly.
Medical and demographic details, once exposed, do not expire. A date of birth combined with an address or insurance information can be used to file fraudulent claims, open accounts in your name, or support more sophisticated identity fraud years later. Unlike a credit card, these pieces cannot simply be cancelled and replaced. That permanence is what makes this category matter long after the initial headlines fade.
The Gap Between Incident and Notification
The filing does not provide an incident date, only the disclosure through the California Attorney General process. Without a clear timeline it is impossible to know how long the data may have been accessible before the company discovered and reported it. What matters to you is that the exposure has now been made official. The people whose details were included should have received direct notice by mail or email from AdaptHealth.
What This Incident Shows About AdaptHealth’s Posture
The record itself does not reveal the root cause, the attack vector, whether data was merely viewed or exfiltrated, or the precise controls that failed. It does show that personal information held by a healthcare services provider was accessible in a way that triggered regulatory notification. Healthcare-related organisations routinely handle sensitive demographic and insurance data that cannot be rotated like a password. When that data leaves the organisation’s control, the consequences fall on the individuals rather than the company. This filing adds AdaptHealth to the long list of healthcare-adjacent firms that have had to report exactly this category of exposure.
Why Medical-Related Personal Information Keeps Its Value
Identity thieves do not need your password to cause damage. They need enough stable personal details to pass verification with insurers, government agencies, or financial institutions. A combination of name, date of birth, address history, and insurance policy number is often sufficient to file false medical claims that can damage your credit or create tax complications. Because none of the exposed categories can be changed at will, the exposure is effectively permanent for practical purposes.
The good news is that no passwords or account credentials were listed. You do not need to change your AdaptHealth password in response to this incident. Doing so would be unnecessary work that does not address the actual exposure. Your account login itself appears to remain secure.
The Pattern Healthcare Providers Keep Repeating
Organisations that manage billing, durable medical equipment, or home healthcare records sit on exactly the kind of demographic and insurance data that appears in this filing. When those records are exposed, the risk is not dramatic overnight fraud but slow, hard-to-detect identity abuse that can surface months or years later. The absence of permanent government identifiers in the listed categories reduces one high-severity risk, but the remaining personal information still requires ongoing attention.
Future breaches will almost certainly involve similar categories because the underlying data—patient names, addresses, dates of birth, policy numbers—cannot be fully retired. The usable lesson is that medical-adjacent providers should be treated as high-value targets for your personal information. Any company that sends you an explanation of benefits or bills your insurance holds data worth protecting the same way you protect your tax records.
Concrete Actions That Address This Exposure
- Review your AdaptHealth letter immediately. It is the only document that confirms exactly which of your records were involved. If you have not received one, contact their privacy office to ask why.
- Place a fraud alert with the three major credit bureaus. Even without a Social Security number exposure, medical and demographic data can support synthetic identity attempts or insurance fraud that eventually touches your credit.
- Monitor Explanation of Benefits statements closely. Check every EOB from your health insurer for claims you did not receive services for. Fraudulent medical billing is a common follow-on from this type of exposure.
- Freeze your credit reports if you rarely open new accounts. This prevents new credit lines from being opened with your demographic details even if an attacker builds a convincing profile.
- Set up alerts with your health insurance provider. Many insurers now allow notifications for any new claim or change to your policy so you can catch unauthorized activity quickly.
The exposure cannot be undone, but its practical impact remains under your control. The absence of passwords and permanent identifiers in the reported categories means the breach is narrower than many healthcare incidents. Treat the data that was exposed as permanent, watch your medical and credit records for unusual activity, and move on knowing the most dangerous credential fields were not part of this incident.
Report details & sourcing
Related breaches
First Commerce LLC Listed by Pear Ransomware Group
Privately held real estate investment and development company…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…