Medical device maker iRhythm has reported that attackers used social engineering to reach data held in certain third-party-hosted business applications. In its Form 8-K, the company says it identified the unauthorized activity on June 8, 2026. The next day it received communications from a threat actor claiming to hold sensitive information, including patient protected health information, and demanding payment in exchange for not disclosing it. iRhythm says it has since confirmed that certain data was exfiltrated.

On June 10 the company determined the incident was material because of the volume of potentially affected data. A breach notification posted by the California Attorney General lists breach dates of June 3 to June 8, 2026.

The filing is specific about scope. iRhythm says it has not identified any effect on its products, clinical or medical device systems, patient safety, or manufacturing and distribution operations. It also says it has not found evidence of ongoing unauthorized access, and that it does not store individual financial account or payment card information. The 8-K says the company would amend it as more information on the nature and volume of the data became available.

Why it matters: the company says the data came from business applications hosted by third parties and that the route was social engineering. The exposure sat in outside accounts and in the people who can approve access to them.

Our read: companies that keep patient or customer records in outside applications should treat identity checks for password resets and support requests as a control over that data. We made the same argument about the help desk door nobody locked, and the Arizona courts case shows how copied files outside the primary system can drive a breach count.

Source: iRhythm Holdings, Form 8-K, Item 1.05 (June 2026)