[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CYBER WATCH / Data breaches

AdaptHealth reporting puts breach impact at more than four million people

An update reported by BleepingComputer puts the AdaptHealth breach's affected population at approximately 4.1 million people. The incident involved a compromised contractor account and access to cloud business applications. This is an impact update about an earlier intrusion, not evidence of a new attack in September.

All updates
Reported ReportedPublished 21 September 2026

Incident timing: Source describes a June 5 intrusion and July disclosure; this is a September impact update.

What is known

BleepingComputer reports that AdaptHealth's submission to the US Department of Health and Human Services listed 4,115,802 affected individuals. Earlier company disclosures described unauthorized access to cloud business applications following social engineering of a privileged third-party contractor account.

Timing and attribution

The source describes an intrusion in June, an initial public disclosure in July, and subsequent updates. The precise discovery chronology should be checked against the original disclosures. A reported link to an extortion group is distinct from the company's confirmation of data exposure.

Business context

The incident illustrates how a supplier's privileged access can reach several business systems. The reported categories of exposed information include health and insurance information; the impact figure should remain attributed to the cited regulatory submission.

Source & attribution

Read the original reporting at BleepingComputer

AI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.

Editorial policy & corrections