iRhythm Began Notifying Patients of Data Breach
The medical technology firm confirmed unauthorized access to patient data occurred earlier this year.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Do you trust healthcare technology companies to securely manage your sensitive personal information?
iRhythm has started notifying individuals affected by a data breach that allowed unauthorized access to sensitive personal information. The breach occurred in June 2026, though the company maintains that no medical devices or patient safety were impacted.
Why it matters
The incident highlights ongoing risks to patient privacy in healthcare tech as firms manage large volumes of personal information. While no evidence of identity theft has emerged, the event underscores the importance of securing business applications that hold patient records.
Unauthorized parties accessed business applications and downloaded information including account and insurance numbers. The company confirmed it does not store financial account or payment card information within these impacted systems.
The players
iRhythm
This is a medical technology company headquartered in San Francisco that specializes in cardiac monitoring services.
The details
iRhythm implemented an incident response plan and hired external cybersecurity experts to conduct a forensic investigation into the unauthorized access. The investigation confirmed that stolen data included contact information, device serial numbers, and dates of birth, but found no threat to medical device functionality.
Timeline
June 3-8, 2026: Unauthorized data access occurred.
June 8, 2026: iRhythm detected the unauthorized access to business applications.
June 15, 2026: iRhythm filed a Form 8-K regarding the financial impact.
October 2, 2026: iRhythm began notifying impacted individuals.
The Tech Race
The incident reflects a broader trend of cybersecurity challenges facing medical technology providers as they digitize patient data to improve diagnostic speed. It signals a move toward more rigorous scrutiny of third-party business application security within the healthcare sector.
Impacted individuals can contact the company call center at 1-844-770-7175 for assistance and further information. The line is operational from 8:00 a.m. to 8:00 p.m. to help those concerned about their personal data records.
The takeaway
Patients should remain vigilant for suspicious communications and monitor their credit reports for unauthorized activity. Protecting sensitive medical information requires continuous verification of account security even when clinical device operations remain secure.
Further reading
Learn more about the latest developments in Cybersecurity to understand the evolving threats to data protection.
More information
For more details, visit the iRhythm data incident information page.
Live Poll
Do you trust healthcare technology companies to securely manage your sensitive personal information?










