iRhythm Began Notifying Patients of Data Breach

The medical technology firm confirmed unauthorized access to patient data occurred earlier this year.

Updated on Oct. 2, 2026 in Cybersecurity

Bold vector editorial illustration of a medical telemetry sensor resting on a clinical table, representing a healthcare technology data breach.
iRhythm has begun notifying patients about a data breach occurring earlier this year that involved unauthorized access to contact information and device serial numbers. AI Illustration. Upload story photo >

Live Poll

Do you trust healthcare technology companies to securely manage your sensitive personal information?

iRhythm has started notifying individuals affected by a data breach that allowed unauthorized access to sensitive personal information. The breach occurred in June 2026, though the company maintains that no medical devices or patient safety were impacted.

Why it matters

The incident highlights ongoing risks to patient privacy in healthcare tech as firms manage large volumes of personal information. While no evidence of identity theft has emerged, the event underscores the importance of securing business applications that hold patient records.

Unauthorized parties accessed business applications and downloaded information including account and insurance numbers. The company confirmed it does not store financial account or payment card information within these impacted systems.

The players

iRhythm

This is a medical technology company headquartered in San Francisco that specializes in cardiac monitoring services.

The details

iRhythm implemented an incident response plan and hired external cybersecurity experts to conduct a forensic investigation into the unauthorized access. The investigation confirmed that stolen data included contact information, device serial numbers, and dates of birth, but found no threat to medical device functionality.

Timeline

  1. June 3-8, 2026: Unauthorized data access occurred.

  2. June 8, 2026: iRhythm detected the unauthorized access to business applications.

  3. June 15, 2026: iRhythm filed a Form 8-K regarding the financial impact.

  4. October 2, 2026: iRhythm began notifying impacted individuals.

The Tech Race

The incident reflects a broader trend of cybersecurity challenges facing medical technology providers as they digitize patient data to improve diagnostic speed. It signals a move toward more rigorous scrutiny of third-party business application security within the healthcare sector.

Impacted individuals can contact the company call center at 1-844-770-7175 for assistance and further information. The line is operational from 8:00 a.m. to 8:00 p.m. to help those concerned about their personal data records.

The takeaway

Patients should remain vigilant for suspicious communications and monitor their credit reports for unauthorized activity. Protecting sensitive medical information requires continuous verification of account security even when clinical device operations remain secure.

Further reading

Learn more about the latest developments in Cybersecurity to understand the evolving threats to data protection.

More information

For more details, visit the iRhythm data incident information page.

Live Poll

Do you trust healthcare technology companies to securely manage your sensitive personal information?