---
title: "iRhythm third-party application data incident"
description: "iRhythm third-party application data breach: verified timeline, impact and response through October 7, 2026."
incident_type: "Data incident"
status: "active"
last_modified: "2026-10-07"
canonical_url: "https://www.ally.security/incidents/irhythm-third-party-application-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/irhythm-third-party-application-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/irhythm-third-party-application-data-incident-2026/stix.json"
---

# iRhythm third-party application data incident

iRhythm confirmed unauthorized downloading from third-party-hosted business applications.

Last modified Oct 7, 2026 · 1 source

## Summary

- **Environment:** Third-party-hosted business applications
- **Operational impact:** No product or patient-safety impact identified by iRhythm
- **Financial impact:** No incident cost established in the reviewed evidence

## What happened

[iRhythm](https://www.irhythmtech.com/) confirmed unauthorized downloading from third-party-hosted business applications. [1](#source-1)

## Impact

Affected data included patient identity, contact, insurance, account and device identifiers, service dates and birth dates. [1](#source-1)

## Timeline

### June 3, 2026 — Access window begins

First date in the confirmed access window. [1](#source-1)

### June 8, 2026 — Access window ends

Last date in the confirmed access window. [1](#source-1)

### October 2, 2026 — Patient notifications

Notifications and the updated notice were issued. [1](#source-1)

### October 7, 2026 — Briefing updated

This briefing was last reviewed and updated on October 7, 2026.

## Threat Group & Attack Vector

The reviewed disclosure does not establish the initial access method.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

iRhythm investigated with external specialists and began individual notifications on October 2. [1](#source-1)

It reported no identified impact to products or patient safety. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/irhythm-third-party-application-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Notice of Data Event

official · iRhythm Holdings, Inc. · Oct 2, 2026

<https://www.irhythmtech.com/us/en/who-we-are/news-events/notice-of-data-event>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   iRhythm third-party application data breach: Patient notifications
2. **Began At · 100% confidence · current**  
   iRhythm third-party application data breach: 2026-06-03
3. **Resulted In · 100% confidence · current**  
   iRhythm third-party application data breach: iRhythm confirmed unauthorized downloading from third-party-hosted business applications.
4. **Affected Organization · 100% confidence · current**  
   iRhythm third-party application data breach: iRhythm Holdings, Inc.
5. **Exposed Data Category · 100% confidence · current**  
   iRhythm third-party application data breach: Names
6. **Ended At · 100% confidence · current**  
   iRhythm third-party application data breach: 2026-06-08
7. **Resulted In · 100% confidence · current**  
   iRhythm third-party application data breach: It reported no identified impact to products or patient safety.
8. **Resulted In · 100% confidence · current**  
   iRhythm third-party application data breach: iRhythm investigated with external specialists and began individual notifications on October 2.
9. **Exposed Data Category · 100% confidence · current**  
   iRhythm third-party application data breach: Health insurance information
10. **Resulted In · 100% confidence · current**  
   iRhythm third-party application data breach: Affected data included patient identity, contact, insurance, account and device identifiers, service dates and birth dates.
11. **Exposed Data Category · 100% confidence · current**  
   iRhythm third-party application data breach: Patient account numbers
12. **Exposed Data Category · 100% confidence · current**  
   iRhythm third-party application data breach: Device information
13. **Exposed Data Category · 100% confidence · current**  
   iRhythm third-party application data breach: Dates of birth
14. **Exposed Data Category · 100% confidence · current**  
   iRhythm third-party application data breach: Contact information
15. **Occurred At · 100% confidence · current**  
   Patient notifications: 2026-10-02

</details>
