Summary
- Environment: Third-party-hosted business applications
- Operational impact: No product or patient-safety impact identified by iRhythm
- Financial impact: No incident cost established in the reviewed evidence
- Record status: Developing record. Reviewed October 7, 2026; updated as evidence emerges.
What happened
Impact
Affected data included patient identity, contact, insurance, account and device identifiers, service dates and birth dates. [1]
Timeline
Threat Group & Attack Vector
The reviewed disclosure does not establish the initial access method.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
