iRhythm begins notifying patients after June cyberattack exposes personal data
IRTC•iRhythm said it is notifying patients after unauthorized individuals accessed or downloaded data from third-party-hosted business applications between June 3 and June 8, 2026. The information included names, contact details, dates of birth, insurance numbers and device serial numbers; the company said it has seen no evidence of identity theft or impact to operations or patient safety.
1. Data access and response
iRhythm detected unauthorized access in certain third-party-hosted business applications around June 8, 2026. Forensic findings showed that unauthorized individuals accessed or downloaded data between June 3 and June 8, including patient identifiers and service details such as names, contact data, dates of birth, insurance numbers and device serial numbers. The company said it has seen no evidence of identity theft tied to the incident and identified no impact to products, clinical systems, customer connections, manufacturing, distribution, patient safety or its ability to meet patient needs.




