iRhythm discloses material cybersecurity incident
iRhythm Holdings, Inc. reported a material cybersecurity incident after detecting unauthorized activity on certain third-party-hosted business applications on June 8, 2026.
Rhea-AI Filing Summary
iRhythm Holdings, Inc. reported a material cybersecurity incident after detecting unauthorized activity on certain third-party-hosted business applications on June 8, 2026. A threat actor later claimed to have obtained proprietary data, patient protected health information, and other personal information and demanded payment to avoid disclosure.
The company has confirmed that some data was exfiltrated but, as of this report, has not found any impact on its products, clinical or medical device systems, patient safety, operations, or financial reporting systems. The affected data was accessed via social engineering and did not involve clinical systems or individual financial account or payment card information.
iRhythm is continuing to investigate the nature and scope of the incident and the individuals affected. It currently believes the incident is not reasonably likely to have a material impact on its financial condition or results of operations and notes that it maintains cybersecurity insurance that may cover certain losses.
Positive
- None.
Negative
- Material cybersecurity incident with sensitive data exfiltration, including proprietary information and patient protected health information, and an extortion demand from a threat actor, which may create future legal, regulatory, and reputational risks despite no current operational disruption.
Insights
Material data breach with PHI exposure but no current system disruption.
iRhythm has classified this as a material cybersecurity incident involving third-party-hosted business applications. A threat actor claims to hold proprietary data and patient protected health information and has demanded payment, while the company has confirmed some data exfiltration.
Importantly, iRhythm states there is no identified impact to products, clinical or medical device systems, patient safety, or manufacturing and distribution operations as of this report. The company also does not store individual financial account or payment card information, which limits certain fraud-related risks.
The company believes the event is not reasonably likely to have a material impact on financial condition or results of operations, and it maintains cybersecurity insurance. However, future legal, regulatory, or reputational consequences will depend on the final scope of affected data and any subsequent misuse or publication.
8-K Event Classification
Key Figures
Key Terms
material cybersecurity incident regulatory
social engineering technical
patient protected health information medical
cybersecurity insurance financial
forward-looking statements regulatory
FAQ
What cybersecurity incident did iRhythm Holdings (IRTC) disclose?
Did the iRhythm (IRTC) cyber incident affect medical devices or patient safety?
What kind of data was involved in iRhythm’s material cybersecurity incident?
Is the iRhythm (IRTC) cyber incident expected to impact financial results?
How did the threat actor gain access in the iRhythm cybersecurity incident?
Does iRhythm (IRTC) store financial account or payment card data affected by the breach?
AI-generated analysis. How Rhea-AI works. Not financial advice.