At least 360,000 people had their names, birth dates and health insurance numbers taken from iRhythm Technologies, the company behind the Zio Patch chest-worn heart monitor, according to breach notices the company began filing with state regulators this week. The theft happened in early June, and the first victim notices went out in October, four months later.
The exposed records belong to patients who wore a Zio device, and the combination is the kind fraudsters use to impersonate someone at a clinic or an insurer.
Texas and South Carolina breach counts
The tally comes from regulators, not from iRhythm. The Record reported on Oct. 9 that the company told Texas that 298,647 people were affected and told South Carolina that 69,526 were affected. Those two figures add up to 368,173, which is above the “at least 360,000” the outlet used as its floor. A third notice was lodged in California, where the attorney general’s breach database lists iRhythm with breach dates of June 3 and June 8, 2026, but the California entry carries no count of residents.
An iRhythm spokesperson declined to give The Record a full national number. Because only three state filings have surfaced so far, and the California entry carries no count, the national total is probably larger than any figure now in public view. Patients who wore a Zio Patch in states that have not yet posted a notice cannot tell from the public record whether their records were among those taken, and the company has said only that it is notifying people for whom it holds contact information.
Dates of birth, insurance numbers and device serials
iRhythm’s own update, dated Oct. 5, lists what was accessed and downloaded between June 3 and June 8: patient name, address, email and phone number, an iRhythm patient account number, an iRhythm device serial number, the patient’s insurance number, the date of service and the date of birth. The company says it does not store financial account or payment card data, and none of those items appear in the list.
That list matters because of how the pieces fit. A date of birth together with an insurance number and a date of service gives a thief enough to file a false claim or open a medical account in someone else’s name. The device serial number also tells a would-be scammer which cardiac monitor the person wore and roughly when, detail that makes a phishing call sound credible. Pieter Arntz, a researcher at Malwarebytes, warned in June that stolen data of this kind feeds targeted phishing, medical identity theft and insurance fraud.
iRhythm said it has “no evidence that any personal information has been or will be used to commit identity theft,” and both its filing and its update stress that clinical systems and medical devices were not touched. The company has also said that its products, manufacturing and distribution were unaffected, which separates this episode from the device-maker attacks that stopped production lines elsewhere in the industry.
A social-engineering break-in and an extortion note
The route in was a person, not a software flaw. According to iRhythm’s Form 8-K, the company identified unauthorized activity on June 8 involving data held in certain third-party-hosted business applications, and the data was obtained through social engineering. The filing does not name the applications or the vendor that hosted them, so it remains unclear which system the social-engineering attempt succeeded against.
On June 9, the company received communications from someone claiming to hold proprietary data and patient health information. Those messages, the 8-K says, “demanded payment in exchange for not publicly disclosing this information.” iRhythm later confirmed that some data had been exfiltrated. On June 10 it determined the incident was material “in light of the volume of the potentially affected data,” while saying it did not expect a material effect on its finances. No hacking group has publicly claimed the intrusion, and the filing does not say whether the company paid.
Four months to a letter
The gap between the June intrusion and the October mailings is the part patients will notice. iRhythm said in its Oct. 5 update that it had finished a forensic review of the affected data and that notifications to people with contact information on file began Oct. 2. It opened a call center at 1-844-770-7175, staffed weekdays from 8 a.m. to 8 p.m. Eastern, and advised recipients to consider fraud alerts or security freezes and to review credit reports and statements for unusual activity. It did not mention a credit monitoring offer.
The Record placed the case among a run of device-industry incidents, noting recent attacks on Medtronic, Boston Scientific, Stryker, Masimo and Zoll. Whether iRhythm’s total ends up near 360,000 or well above it depends on filings from states that have not yet posted a count.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Two passengers died at an Ohio toll plaza, and the NTSB now wants the cash lanes shut
- Long use of a common prostate pill is tied to a higher chance of glaucoma
- Ford is recalling 223,472 F-150 pickups because the fuel tank can leak or detach
- Hybrids have 15% fewer problems than gas cars, while EVs and plug-in hybrids have about 80% more, Consumer Reports finds