iRhythm Provides Update on Cybersecurity Incident Previously Disclosed in June 2026
The affected records include patient identity and insurance information; iRhythm does not store financial account or payment card information.
Sentiment and the balance of points
Rhea-AI Sentiment reads the wording of the document, how positive or negative its language is on a 1 to 5 scale. The balance of points shown with the takes weighs what the document actually discloses, so the two can disagree, for example when a trial that missed its main goal is described in upbeat language.
Rhea-AI Summary
iRhythm (IRTC) has begun notifying affected individuals after completing its forensic investigation and data review of the previously disclosed cybersecurity incident. Certain stored data was accessed and downloaded by unauthorized individuals between June 3 and June 8, 2026 through third-party-hosted business applications. The affected data includes patient names, contact details, account and insurance numbers, device serial numbers, service dates and birth dates.
Notifications began October 2, 2026 for affected individuals whose contact information is held. No impact has been identified on products, clinical systems, customer connections, operations or patient safety. The company continues to believe a material financial impact is not reasonably likely.
How this balance works
Rhea-AI gives every point it takes from this document a weight. Minor counts 1, Moderate 3 and Major 9, so one Major point outweighs several Minor ones. The bar adds up the weights on each side, and when neither side holds more than 65% of the total the balance reads Mixed.
It reads the document as published, with the same rules for every company, and it does not look at what the market expected or at how the stock traded, so a point can be objectively good on a day the stock falls.
Rhea-AI Sentiment measures something else, the tone of the wording.
Positive
- Minor pointiRhythm continues to believe the incident is not reasonably likely to materially affect financial condition or operating results.
- Minor pointNo impact identified on products, clinical or medical device systems, customer connections, manufacturing, distribution, patient safety or meeting patient needs.
- Minor pointForensic investigation and data review completed; affected-individual notifications began October 2, 2026.
Negative
- Moderate pointPatient data accessed and downloaded without authorization between June 3 and June 8, 2026.
- Minor pointExposed data includes names, contact details, patient account numbers, device serial numbers, insurance numbers, service dates and birth dates.
News Explained
iRhythm reports no evidence that exposed personal information has been or will be used for identity theft, and says it does not retain individual financial-account or payment-card information.
Key Figures
- Unauthorized data access period
- June 3–June 8, 2026
- Period when unauthorized individuals accessed and downloaded data
- Notifications began
- October 2, 2026
- iRhythm began notifying impacted individuals for whom it has contact information
Key Terms
form 8-k regulatory
AI-generated analysis. How Rhea-AI works. Not financial advice.
Following completion of the forensic investigation, company begins notifying impacted individuals
SAN FRANCISCO, Oct. 02, 2026 (GLOBE NEWSWIRE) -- iRhythm Holdings, Inc. (NASDAQ:IRTC) today provided an update regarding the cybersecurity incident previously disclosed in June 2026. Following completion of the forensic investigation and subsequent review to determine the nature of the impacted data, the company has begun notifying impacted individuals.
As previously disclosed, on or around June 8, 2026, iRhythm detected unauthorized access in certain third-party-hosted business applications. Upon detecting the unauthorized access, iRhythm promptly implemented its incident response plan. As part of the investigation, iRhythm has been working very closely with external cybersecurity professionals experienced in handling these types of incidents. After completing the forensic investigation, iRhythm learned certain data it stores was accessed and downloaded by unauthorized individuals between June 3 and June 8, 2026.
Following the forensic investigation, iRhythm carried out a review to determine the nature of the impacted data. This review concluded the impacted data includes: patient name; patient contact information, including address, email address, and phone number; iRhythm patient account number; iRhythm device serial number; patient insurance number; date of service; and date of birth.
iRhythm has no evidence that any personal information has been or will be used to commit identity theft. However, beginning October 2, 2026, iRhythm began notifying impacted individuals for whom it maintains contact information. Notified individuals have been provided with instructions on best practices to protect their information.
Out of an abundance of caution, those served by iRhythm are encouraged to take steps to protect themselves. This includes protecting themselves against medical identity theft and identity fraud, placing a fraud alert/security freeze on their credit files, obtaining free credit reports, and remaining vigilant in reviewing financial account statements and credit reports for fraudulent or irregular activity on a regular basis.
iRhythm has also established a call center to address questions from impacted individuals. Representatives are available from 8:00 a.m. to 8:00 p.m. Eastern time, Monday through Friday, excluding major U.S. holidays, at 1-844-770-7175.
As iRhythm previously reported, the company has not identified any impact to our products, our clinical or medical device systems, our connections to customers, our manufacturing and distribution operations, patient safety, or our ability to meet patient needs. In addition, iRhythm does not store or retain individual financial account information or payment card information. The company continues to believe, as previously stated in the Current Report on Form 8-K dated June 15, 2026, that the incident is not reasonably likely to have a material impact on the Company’s financial condition or results of operations.
iRhythm is committed to maintaining the privacy and security of personal information in its possession and has taken precautions to safeguard it. iRhythm regularly evaluates and modifies its practices and internal controls to safeguard the security and privacy of the information it maintains and is taking steps to mitigate the risk to individuals impacted by this incident.
Individuals may visit iRhythm’s website https://www.irhythmtech.com/us/en/who-we-are/news-events/notice-of-data-event to learn more about the incident and steps they can take to protect their information.
About iRhythm Holdings
iRhythm is a leading digital health care company with a mission to boldly innovate to create trusted solutions that detect, predict, and prevent disease. Combining wearable biosensors and cloud-based data analytics with powerful proprietary algorithms, iRhythm distills data from millions of heartbeats into clinically actionable information. Through a relentless focus on patient care, iRhythm’s vision is to deliver better data, better insights, and better health for all.
iRhythm Contacts
| Investors | Media |
| Francis Pruell | Kassandra Perry |
| investors@irhythmtech.com | mediarelations@irhythmtech.com |
FAQ
AI-generated questions and answers. How Rhea-AI works. Not financial advice.
What patient information was affected by the iRhythm cybersecurity incident?
The affected data includes patient names, addresses, email addresses, phone numbers, iRhythm patient account numbers, device serial numbers, patient insurance numbers, dates of service and dates of birth. iRhythm does not store or retain individual financial account information or payment card information.
When did iRhythm begin notifying people affected by the cybersecurity incident?
iRhythm began notifying affected individuals for whom it maintains contact information on October 2, 2026. Notified individuals received instructions on practices to protect their information.