If you wore an iRhythm heart monitor this year, a notification started heading your way this week. I run AliasFleet, an email-alias service built so one site's spill stays on one address, and that is the lens I read this breach through. Between 3 and 8 June 2026, someone downloaded patient records with email addresses, phone numbers, insurance numbers and device serial numbers. iRhythm knew on or around 8 June. It took until 2 October to say what was taken.
That gap is the story. Four months between "we were breached" and "here is what they got." During those four months the data sat wherever the attacker put it, and the people in it had no idea they were in it.
The download, and what we know about it
iRhythm Holdings is a San Francisco digital health company (NASDAQ: IRTC). It makes wearable heart monitors, the kind your cardiologist sticks on you for days at a time to catch arrhythmias, with cloud analytics behind them.
On or around 8 June 2026, iRhythm detected unauthorized access in certain third-party-hosted business applications. That is the whole public description of the attack surface. The company has not named the application, given a CVE, or said when the access started. The confirmed download window was 3 to 8 June, the day the intrusion was detected.
The company disclosed the incident in June (a current report on Form 8-K dated 15 June 2026, referenced in the October release). Then silence. On 2 October, iRhythm posted a notice of data event and issued a press release confirming the data classes and starting individual notifications.
So the timeline reads like this: intrusion in early June, detection on or around 8 June, partial disclosure mid-June, full confirmation of the stolen data in October. Four months between detection and confirmation, and for the victims, four months of not knowing whether their data was in the pile. The company has not said why the confirmation took that long.
What the notice confirms
The confirmed data list, from iRhythm's own notice:
- Patient name
- Address, email address and phone number
- iRhythm patient account number
- iRhythm device serial number
- Insurance number
- Date of service
- Date of birth
No financial account or payment card information, because iRhythm does not store it. The company says it has no evidence of identity theft so far, and says its products, clinical systems and manufacturing were unaffected.
What we do not know: how many people are affected. The company has not disclosed a number. Anyone citing a figure is guessing.
Now look at the list again: name, email, phone, date of birth, insurance number, device serial. That is not a spam list. It is a medical identity theft starter kit.
Medical identity theft works differently from credit card fraud. A stolen card gets cancelled. A stolen medical identity gets used to book appointments, fill prescriptions and bill procedures in your name, and the fraudulent records end up inside your actual medical file. Untangling that is not a phone call to the bank. It is months of arguing with providers and insurers about records that have your name and your insurance number on them. iRhythm's own notice leads with a section titled "Protecting Your Medical Information," which tells you the company knows exactly what this data combination enables.
The device serial number sharpens the phishing angle. Picture a call or an email to an older cardiac patient: "This is iRhythm support, calling about monitor serial number 7-4-1-9 from your June appointment." The details are real. The caller is not. That is the attack this dataset was built for, and the demographic, people with heart conditions, skews older, the demographic most exposed to phone and phishing fraud. The Medela breach ran the same playbook on a different patient population.
The four-month gap
Here is the uncomfortable part. Breach forensics genuinely takes time. Reviewing logs, determining exactly which records were touched, doing it defensibly enough for regulators and lawyers: that is real work, and rushing it produces wrong victim lists.
But the victims pay for the delay in risk, not the company. Between June and October, every person in that dataset walked around unprotected against misuse of data the attacker already had. Phishing does not wait for the forensic report. If someone bought or downloaded that data in June, the "be vigilant" advice arriving in October is four months late.
This is not a criticism of iRhythm specifically. Delayed forensic confirmation is the industry norm. It is worth saying plainly anyway: a breach notice that takes four months to name the data is a notice that arrives after the window where early action helps most. The sooner you hear about your exposure, the sooner you can freeze credit, watch your statements and treat suspicious contact as hostile. Every month of silence is a month you spent treating it as friendly.
What to do now
If you received the notification letter, or you used an iRhythm device this year and have not heard anything, do these in order. The general version of this checklist lives in our breach response guide.
1. Do not wait for Have I Been Pwned. The breach is not listed there yet (checked 5 October 2026). iRhythm says it is notifying impacted individuals directly, starting 2 October. If you are a patient and you get the notification, you are in it. If you used a device and get nothing, that is not proof you are clear; people whose contact details were stale may not have been reached.
2. Freeze or alert your credit files. This is the single highest-value action. A fraud alert tells creditors to verify your identity before opening accounts; a security freeze locks the file entirely. Both are free. iRhythm's notice lists the three bureaus and the process; the FTC's identity theft resources cover the same ground.
3. Watch your explanation of benefits. Your insurer sends statements showing what was billed in your name. Read them. Anything you do not recognise gets a call to the insurer first, then the provider, because medical identity theft shows up here before it shows up anywhere else.
4. Treat iRhythm-flavoured contact as hostile. Calls, texts, emails referencing your device, your appointment date, your serial number: verify through a separate channel before you act on anything. The data to make these convincing is now in circulation. iRhythm's real call center is 1-844-770-7175, 8am to 8pm ET on weekdays. If someone calls you claiming to be them, hang up and call that number yourself.
5. Watch the email address that was on file. That address is now paired with your name, phone, date of birth and insurance number in someone's dataset. Expect phishing that knows too much. Anything asking you to "verify" or "update" details gets ignored until you navigate to the site yourself.
The part an alias actually fixes
Here is the structural point, and it is why we write about breaches this way. Every one of those patient email addresses was a real address sitting in a vendor's business application, handed over once and then out of the patient's control forever.
A per-provider email alias changes what happens on the receiving end. Give your health-tech provider its own alias, and every future email from them arrives at an address only they were given. The day a "billing update from iRhythm" lands at the alias you gave your airline, it is phishing by construction. No link inspection, no header forensics. The wrong address is the detection.
An alias would not have stopped the June download. Nothing a patient does stops the theft itself, and anyone selling you that story is lying. What the alias does is shrink the phishing surface the stolen data creates: the attacker's most convincing weapon, a message that knows your details, has to arrive at the right address to work, and the alias gets to decide what the right address is.
I run AliasFleet, which does exactly this: one alias per website, forwarding to your real inbox, pausable in one click. The free tier covers 10 active aliases, which is enough to cover every health provider, insurer and pharmacy you deal with. The mechanics are explained in our guide on what an email alias is, and how to tell which website leaked your email covers the tracing side.
One more honest note. An alias does not fix the medical identity theft part. If your insurance number and date of birth are in the dataset, no email trickery keeps someone from booking an appointment in your name. The alias handles the phishing. The credit freeze and the EOB watching handle the rest. No single tool covers a breach like this, and a privacy company telling you otherwise would be selling, not informing.
Top comments (0)