Incident timing: Source describes a June 5 intrusion and July disclosure; this is a September impact update.
What is known
BleepingComputer reports that AdaptHealth's submission to the US Department of Health and Human Services listed 4,115,802 affected individuals. Earlier company disclosures described unauthorized access to cloud business applications following social engineering of a privileged third-party contractor account.
Timing and attribution
The source describes an intrusion in June, an initial public disclosure in July, and subsequent updates. The precise discovery chronology should be checked against the original disclosures. A reported link to an extortion group is distinct from the company's confirmation of data exposure.
Business context
The incident illustrates how a supplier's privileged access can reach several business systems. The reported categories of exposed information include health and insurance information; the impact figure should remain attributed to the cited regulatory submission.
Source & attribution
Read the original reporting at BleepingComputerAI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.