iRhythm, the medical device maker known for its Zio Patch cardiac monitor, has disclosed a data breach affecting at least 360,000 people. The company filed breach notices in multiple states, including Texas with 298,647 affected individuals and South Carolina with 69,526, and also notified regulators in California. A spokesperson declined to provide a full victim count.
The incident occurred on June 8, with unauthorized access to company systems between June 3 and June 8. Hackers gained entry through a social engineering attack on third-party-hosted business applications. Stolen information includes names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service, and dates of birth.
iRhythm said the breach did not affect its clinical systems, medical devices, manufacturing, or distribution operations, and there was no loss of service. The company stated it has no evidence that the stolen data has been or will be used for identity theft. In a June 8 SEC filing, iRhythm said a threat actor demanded payment to avoid public disclosure, and the company confirmed that certain data was exfiltrated. No hacking group has publicly claimed responsibility.
The attack fits a broader pattern of cyber incidents hitting medical device companies, including Medtronic, Boston Scientific, and Stryker, which have leaked sensitive medical data and caused supply chain disruptions in recent years.