Medical device manufacturer iRhythm confirmed a data breach affecting at least 360,000 people. The incident, which occurred on June 8, involved unauthorized access to third-party systems. The company began filing breach notices in multiple states, including Texas, South Carolina, and California.
The stolen information includes names, addresses, phone numbers, iRhythm patient account numbers, iRhythm device serial numbers, patient insurance numbers, dates of service, and dates of birth. An investigation revealed that hackers had access to company systems between June 3 and June 8, gaining entry through a social engineering attack on unidentified third-party-hosted business applications.
iRhythm disclosed in an SEC filing that it received communications from a threat actor demanding payment in exchange for not publicly disclosing the sensitive information. The company stated it has no evidence that any personal information has been or will be used for identity theft. iRhythm also confirmed that the incident did not affect its clinical systems, medical devices, operations, or finances.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Medical device maker iRhythm reported a data breach affecting at least 360,000 individuals, where unauthorized access to third-party systems occurred in June. The breach exposed personal and health information, leading to ransom demands from the attackers.