Skip to content
Back to Blog
critical severity August 14, 2026 · 5 min read

AdaptHealth, LLC Data Breach Notice (Washington Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

AdaptHealth, LLC notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on August 14, 2026, and the notice lists name, full date of birth, health insurance policy or ID number, medical information and protected health information owned or licensed by a HIPAA covered entity among the information exposed. The filing puts the incident itself on June 05, 2026.

AdaptHealth, LLC Data Breach Notice (Washington Attorney General)

The filing from AdaptHealth, LLC shows that your name, full date of birth, health insurance policy or ID number, and medical information were exposed in an incident that occurred on June 05, 2026. The organisation notified the Washington Attorney General on August 14, 2026 — 70 days later. This gap between the incident and the official filing is the most striking detail in the record.

Health Insurance IDs and Medical Records Do Not Expire

Unlike a credit card or password, a health insurance ID number cannot be cancelled and reissued on demand. Once it is loose, it remains usable for years. The same is true of your full date of birth paired with your name. These two pieces of information, combined with medical details, allow someone to impersonate you when seeking treatment, filing claims, or requesting prescription records.

Medical identity theft is particularly damaging because incorrect treatment notes can enter your permanent health record. Correcting those entries often takes longer than fixing an erroneous bank charge. The 9,214 people named in this Washington filing now carry that long-term risk.

What the Exposed Categories Actually Enable

With a name, full date of birth, and health insurance ID, a thief can:

  • Obtain medical services in your name and have the bills sent to your insurer
  • Order prescriptions that appear on your pharmacy history
  • File fraudulent claims that distort your future coverage or premiums
  • Use your medical history to strengthen other identity theft attempts, such as opening accounts or filing tax returns

The filing also lists Protected Health Information owned or licensed by a HIPAA covered entity. This confirms the data came from AdaptHealth’s role as a provider of medical equipment and related services. No passwords or login credentials were exposed, so your AdaptHealth account itself was not directly compromised in a way that would require changing a password for this breach.

The Letter Is the Only Reliable Check

AdaptHealth is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not among the 9,214 affected in this incident. However, if you have moved since June 05, 2026, the letter may have gone to an old address. In that case, contact AdaptHealth directly to confirm whether you were included.

This is not speculation. The record contains only the categories listed above; it does not mention Social Security numbers, financial account numbers, driver’s license numbers, or any other government identifiers. That absence is meaningful. The exposure is serious but narrower than many healthcare breaches.

Why the 70-Day Interval Matters

The incident date of June 05, 2026, and the filing date of August 14, 2026, are both stated plainly in the Washington Attorney General’s record. The 70 days that passed is long enough to be the central newsworthy fact. Notification deadlines vary by state law and by when an investigation concludes, so the record does not establish fault. It simply shows that nearly ten weeks elapsed between the breach event and the official notification to regulators.

How This Exposure Differs From a Typical Retail Breach

Most people expect a breach to involve credit cards that can be replaced. Here the permanent elements are your date of birth and the link between your identity and your medical history. Those cannot be rotated like a card. The health insurance policy number functions more like a permanent key to your coverage than a temporary payment method.

Because the exposed data is medical rather than purely financial, the fraud patterns that follow are different. Thieves do not usually run up immediate visible charges. Instead they create invisible damage inside your insurance and medical files that can surface months or years later when you need care or face an audit.

What Remains Under Your Control

You cannot change your date of birth or erase the medical information that was taken. You can, however, reduce what a thief is able to do with it. Monitoring your Explanation of Benefits statements is the single most effective ongoing check. Any claim or service you do not recognise should be disputed immediately with your insurer.

Placing a freeze on your credit reports remains useful because medical identity theft sometimes leads to attempts to open other accounts using your health-derived personal information. The freeze does not stop medical fraud, but it blocks one common downstream consequence.

Reviewing your medical records annually through each provider’s patient portal can help you spot entries that do not belong to you. Early detection makes correction faster.

Practical Steps Specific to This Breach

  • Log into your health insurer’s portal weekly for the next six months and examine every Explanation of Benefits statement. Look for services you did not receive.
  • Contact AdaptHealth’s privacy office to ask whether your specific record was part of the 9,214 if you moved after June 05, 2026, and have not received a letter.
  • Request free annual credit reports from the three major bureaus and scan for accounts opened in your name that you do not recognise.
  • Consider a credit freeze if you do not already have one. It will not protect your insurance but limits identity theft that begins with medical data.
  • Keep records of every communication with AdaptHealth and your insurer about this incident. Documentation helps if incorrect information appears in your file later.

The record is silent on how the incident occurred, whether the data was copied or simply viewed, and whether the actor was external or internal. Those details are not available to the public. What is known is limited to the categories, the number of people, and the exact dates provided in the Washington filing.

This exposure will remain relevant for decades because medical and insurance identifiers do not expire. The most useful response is consistent monitoring of your insurance claims and medical records rather than one-time fixes. The letter from AdaptHealth remains the definitive answer to whether your information was included. Its absence, while not a guarantee, is the clearest signal the record allows that you were likely not affected.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on AdaptHealth, LLC.

  1. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  2. Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed August 14, 2026
Last reviewed August 14, 2026
Affected 9214
Data exposed NameFull Date of BirthHealth Insurance Policy or ID NumberMedical InformationProtected Health Information owned or licensed by a HIPAA covered entity
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email