Health Care

AdaptHealth breach exposed health records of one in 13 Vermonters

Getting your Trinity Audio player ready...

AdaptHealth sells and rents durable medical equipment — the industry term for medical gear people use at home rather than in a hospital or clinic.

by Compass Vermont

One company’s data breach exposed the health records of 48,090 Vermonters — about one in every 13 people living in the state.

AdaptHealth, LLC reported the breach to the Vermont Attorney General’s Office on Aug. 14. The entry on the state’s public breach list is five fields long: the date, the company name, the industry, the number of Vermont residents affected, and one category of data — health records.

That single entry is larger than every other breach on the list put together.

The scale

Vermont’s current breach list begins on April 17, 2026. Since then, 290 breaches have been reported to the Attorney General’s Office, affecting a combined 85,073 Vermonters.

AdaptHealth accounts for 48,090 of them. That is 57 percent of everyone on the list — more than the other 289 breaches combined. Set against Vermont’s population, which the Census Bureau put at 644,663 in its most recent estimate, 48,090 people is 7.5 percent of the state.

The next four largest entries:

  • Medtronic — 8,668 Vermonters (June 28)
  • BAYADA Home Health Care — 6,097 (July 17)
  • Carnival Corporation — 3,915 (May 28)
  • Baylor Genetics — 2,630 (Aug. 14)

AdaptHealth is five and a half times the size of the next-largest breach on the list.

The Attorney General’s Office notes on the same page that these counts can rise as companies finish determining how many residents were affected. The 48,090 figure is a floor, not a final number.

Why one company holds that many Vermont files

AdaptHealth sells and rents durable medical equipment — the industry term for medical gear people use at home rather than in a hospital or clinic. In practice that means CPAP and BiPAP machines for sleep apnea, oxygen concentrators, wheelchairs and walkers, hospital beds, continuous glucose monitors for diabetes, ostomy and incontinence supplies, and breast pumps.

The company’s New England arm is licensed to deliver prescription medical devices in all six New England states, including Vermont, and appears in the Vermont 211 directory as a provider of respiratory and sleep therapy, mobility equipment, ramps and stairlifts.

That is how a single out-of-state company ends up holding the medical files of one in 13 Vermonters. A Vermonter on an oxygen concentrator does not choose that arrangement or usually know it exists. The equipment shows up, the insurance gets billed, and the file lives somewhere far away.

What happened

The timeline comes from a filing with the Securities and Exchange Commission by AdaptHealth Corp., the publicly traded parent of the AdaptHealth, LLC entity named on Vermont’s list. The filing is a Form 8-K — the disclosure a public company makes when something material happens between quarterly reports.

  • June 15 — Someone contacted AdaptHealth claiming to have obtained files containing patient data.
  • June 27 — The company determined the incident was material given the nature and potential volume of the data at risk.
  • July 2 — AdaptHealth filed the Form 8-K disclosing the breach.
  • Aug. 14 — The company reported the breach to the Vermont Attorney General’s Office.

The break-in was not technical. AdaptHealth attributed it to social engineering — a con rather than a hack, in which someone talks their way into credentials. In this case the compromised account belonged to a third-party contractor.

From that account, according to the filing, the intruder reached cloud-based business applications including internal patient management systems and document storage, external electronic health record portals, and a stored password file connected to insurance billing. Patient data was exfiltrated — copied out of the company’s systems.

A criminal group known as ShinyHunters has claimed responsibility, added AdaptHealth to its data leak site, and threatened to publish the stolen files.

What “Health Records” tells a Vermonter, and what it doesn’t

The state’s list assigns AdaptHealth one data category: health records. No Social Security numbers, no financial account codes, no government ID numbers. For comparison, Baylor Genetics — reported the same day, 2,630 Vermonters — carries five categories.

Read at face value, that is the narrower exposure. It also deserves a second look, because AdaptHealth’s own filing describes a stolen password file tied to insurance billing and access to health record portals, which is the plumbing that connects patients to payers.

There is a second reason not to treat “health records only” as the lighter category. A stolen credit card gets cancelled and reissued in a week. A stolen medical file cannot be reissued. It contains diagnoses, prescriptions, equipment orders, and insurance identifiers, and those do not change.

The letter you cannot read

Compass reported earlier this year on the Attorney General’s Office decision to stop posting the notice letters that companies send to affected consumers. To meet digital accessibility standards for state websites, the office claims it can no longer publishes those PDFs. What it publishes instead is the summary table, and an email address — AGO.SecurityBreach@vermont.gov — where anyone can request a copy of the sample consumer notice for a particular breach.

The accessibility rationale is straightforward and the request channel is public. The practical effect is that the largest breach on Vermont’s list arrives as one row of a table, with no document behind it, unless a Vermonter knows to write to a state inbox and ask.

If you use home medical equipment in Vermont

  • Watch your mail. Vermont law requires companies to notify affected residents as soon as possible and no later than 45 days after they discover a breach. AdaptHealth reported to the state on Aug. 14.
  • You can ask for the notice yourself. The sample consumer notice is available on request from AGO.SecurityBreach@vermont.gov. That channel is open to any Vermonter, not just to reporters.
  • Read your explanation of benefits statements. Medical identity theft shows up as care you never received, billed to your insurance. It is the specific risk when health records are taken, and it is not the risk that credit monitoring is built to catch.
  • Treat unexpected contact with suspicion. People whose stolen files sit on a leak site sometimes get contacted directly by the people holding them.

Sources

Figures reflect the Attorney General’s table as of its Aug. 17, 2026 update.


Discover more from Vermont Daily Chronicle

Subscribe to get the latest posts sent to your email.

Categories: Health Care, Public Safety

All topics and opinions welcome! No mocking or personal criticism of other commenters. No profanity, explicitly racist or sexist language allowed. Real, full names are now required. All comments without real full names will be unapproved or trashed.