iRhythm Technologies has disclosed unauthorized access to data stored in certain business applications hosted by third parties. The company disclosed details of the data breach in a recent SEC filing, stating that sensitive information, including protected health information (PHI), may have been compromised and extracted by a threat actor.

According to the SEC filing, iRhythm detected suspicious activity on June 8 and immediately activated its response protocols cybersecurity. The company launched an investigation with the help of external consultants and cybersecurity experts to determine the scope of the incident and implement mitigation measures.
Decoding the iRhythm Data Breach
The company said that on June 9, a threat actor contacted it and claimed to have obtained “sensitive information” from the affected systems. According to iRhythm, the allegedly compromised data included proprietary company information, protected health information and other forms of personal information.
The threat actor demanded payment in exchange for not disclosing the information. After being contacted, iRhythm conducted additional checks and confirmed that some data had indeed been extracted from the affected third-party hosted applications. By June 10, the company determined that the incident was significant due to the volume of information potentially affected.
The SEC filing noted that the company continues to investigate the nature and extent of the iRhythm data breach.
See also: Proton Data Breach Observatory: Notifies you when your personal data appears on the Dark Web

Basic Functions Remain Unaffected
Despite the severity of the incident, iRhythm said it has not identified any disruption to its products, patient services or operational capabilities.
According to the SEC filing, the company has found no impact on:
– Products and services
– Clinical systems
– Medical device systems
– Patient safety
– Production operations
– Distribution activities
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
– Financial reporting systems
– The company's ability to continue serving patients
See also: Data brokers and the sale of personal information
iRhythm said the data breach stemmed from a social engineering attack that targeted certain business applications hosted by third parties, not its clinical infrastructure.
The company further emphasized that the incident did not impact its clinical or medical device systems, nor did it involve connections used by customers. In addition, iRhythm said that it does not store or maintain individual financial account information or payment card information, reducing the likelihood that such data was compromised.
The Research Continues
According to the latest SEC filing, iRhythm said it has found no evidence of ongoing unauthorized access to its systems.

The company said its investigation remains active and that it continues to assess the extent of the exposure and the potential consequences arising from the incident. At this time, iRhythm believes that the cybersecurity incident will not have a material impact on its financial condition or results of operations.
See also: BreachForums: Data leak exposes 324,000 criminals
The company also noted that it maintains cybersecurity insurance that could potentially offset some losses related to the incident. However, iRhythm cautioned that there can be no assurance that the insurance coverage will fully compensate for all losses related to the breach.
Overall, the incident at iRhythm Technologies highlights once again the growing risks associated with social engineering attacks and the reliance on third-party providers to host critical business applications. While the company reacted promptly and activated response mechanisms, the potential leakage of protected health information and personal data underscores the seriousness of such incidents, especially in the sensitive healthcare space.
At the same time, the fact that the company's core functions were not affected operationally or clinically demonstrates a relative resilience of its, but does not diminish the need for further investigation and strengthening of security measures. As the investigation continues, the incident serves as a reminder that cybersecurity is not a static process but an ongoing challenge, with implications that can extend beyond the immediate technical level and touch the trust of patients and partners.
