- iRhythm said the incident involved unauthorized access to third-party systems.
- iRhythm said its clinical systems and medical devices were not affected.
- iRhythm said a June cyberattack breached the data of at least 360,000 people.
iRhythm said the data of at least 360,000 people was breached in a June cyberattack, and that the incident occurred on June 8 and involved unauthorized access to third-party systems.
The Record reported that the affected information included names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service and dates of birth. iRhythm said cybercriminals accessed and downloaded the information.
On this page
Hackers accessed third-party business applications through social engineering
The Record said an investigation found that hackers had access to company systems between June 3 and June 8. They gained access to unidentified third-party-hosted business applications through a social engineering attack.
The Record said the information included iRhythm patient account numbers, device serial numbers and patient insurance numbers, along with personal and service details. iRhythm later confirmed that certain data had been exfiltrated from the applications.
iRhythm said the threat actor demanded payment
iRhythm said communications from the threat actor demanded payment in exchange for not publicly disclosing the information. The company said the cyberattack did not affect its products, devices, manufacturing process or distribution operations, and that its finances were not disturbed.
iRhythm said it responded promptly after detecting the unauthorized access and, once it verified the scope, notified affected individuals and applicable regulators.
FAQ
What happened in the iRhythm cyberattack?
iRhythm said a June 8 cyberattack involved unauthorized access to third-party systems and breached data affecting at least 360,000 people.
What information was accessed in the iRhythm breach?
The Record said the information included names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service and dates of birth.
Did the iRhythm attack affect medical devices or clinical systems?
iRhythm said the incident did not affect its clinical systems or medical devices and did not disrupt operations.
Sources
How we checked this story
| Claim | Source | Status |
|---|---|---|
| iRhythm said a June cyberattack breached the data of at least 360,000 people. | iRhythm, via The Record | Attributed |
| iRhythm said 298,647 people in Texas and 69,526 in South Carolina had information stolen. | iRhythm, via The Record | Attributed |
| iRhythm said it responded promptly, verified the scope, and notified affected individuals and regulators. | iRhythm, via The Record | Attributed |
| iRhythm said the incident did not affect its clinical systems or medical devices and did not disrupt operations. | iRhythm, via The Record | Attributed |
| The Record reported that hackers had access to company systems between June 3 and June 8 through a social engineering attack. | The Record | Attributed |
| The Record said the stolen information included names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service, and dates of birth. | The Record | Attributed |
| iRhythm said cybercriminals accessed and downloaded the information. | iRhythm, via The Record | Attributed |
| iRhythm said it had no evidence that personal information had been or would be used for identity theft. | iRhythm, via The Record | Attributed |
| The Record said no hacking group publicly took credit for the attack. | The Record | Attributed |
| iRhythm said the cyberattack did not affect its products, devices, manufacturing, distribution operations, or finances. | iRhythm, via The Record | Attributed |
| iRhythm reported $224.2 million in second-quarter revenue. | iRhythm, via The Record | Attributed |
| iRhythm said the threat actor demanded payment to prevent public disclosure of the information. | iRhythm, via The Record | Attributed |
| iRhythm said it confirmed that certain data had been exfiltrated from the applications. | iRhythm, via The Record | Attributed |
| Cardiac monitoring generally refers to continuous or intermittent monitoring of heart activity to assess a patient’s condition relative to cardiac rhythm. | Wikipedia | Confirmed |
| Ambulatory cardiac monitoring uses small wearable devices such as Holter monitors, wireless ambulatory ECGs, or implantable loop recorders. | Wikipedia | Confirmed |
Could not verify
- Whether the full number of affected people is established
- Whether the stolen information has been misused is not established
- Whether a hacking group was responsible is not established



