iRhythm third-party application data incident

iRhythm confirmed unauthorized downloading from third-party-hosted business applications.

Last modified

Summary

  • Environment: Third-party-hosted business applications
  • Operational impact: No product or patient-safety impact identified by iRhythm
  • Financial impact: No incident cost established in the reviewed evidence
  • Record status: Developing record. Reviewed October 7, 2026; updated as evidence emerges.

What happened

iRhythm confirmed unauthorized downloading from third-party-hosted business applications. [1]

Impact

Affected data included patient identity, contact, insurance, account and device identifiers, service dates and birth dates. [1]

Timeline

  1. Access window begins

    First date in the confirmed access window.

    [1]
  2. Access window ends

    Last date in the confirmed access window.

    [1]
  3. Patient notifications

    Notifications and the updated notice were issued.

    [1]
  4. Briefing updated

    This briefing was last reviewed and updated on October 7, 2026.

Threat Group & Attack Vector

The reviewed disclosure does not establish the initial access method.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

iRhythm investigated with external specialists and began individual notifications on October 2. [1]

It reported no identified impact to products or patient safety. [1]