Why Health Information Security Is Only as Strong as Your Weakest Supplier
Health information security is usually framed as something an organisation controls from the inside: patching, access controls, staff training. The recent AdaptHealth breach is a reminder that it rarely stays that contained.
AdaptHealth, a nationwide US supplier of home medical equipment such as wheelchairs, continuous glucose monitors and CPAP machines, has disclosed a data breach affecting an as yet undetermined number of patients. The company works closely with hospitals, physician practices and insurers, and the breach turned into a supply chain story as much as a health information security one.
What Happened?
On 15 June 2026, AdaptHealth was contacted by a threat actor claiming to have obtained data from its systems. The investigation that followed traced the breach back to a social engineering attack that compromised the login session of a third-party contractor. That single compromised session was enough to reach AdaptHealth’s own cloud-based business applications, including patient management and document storage systems. From there, attackers took passwords tied to insurance billing along with personal and protected health information.
AdaptHealth has since disabled the affected account, reset credentials and added further access controls, and is working with external forensics teams to establish the full scope. By 27 June, the company judged the incident material enough to disclose to the US Securities and Exchange Commission. At the time of writing, no group has publicly claimed responsibility, and AdaptHealth hasn’t said whether a ransom demand was made. The company maintains the incident hasn’t disrupted patient care and says it holds cyber insurance to cover part of the cost.
The Weak Point Wasn’t AdaptHealth
Nothing here suggests AdaptHealth’s own defences failed. The attackers didn’t need them to. They went after a contractor instead, a party AdaptHealth had already trusted with access, and used that trust to get where they wanted to go. This is the shape health information security risk usually takes: an organisation can invest heavily in its own controls and still be exposed through a supplier, contractor or vendor whose access it can’t fully see or verify.
Why a Questionnaire Wouldn’t Have Caught This
Most organisations manage third-party risk with a self-attested security questionnaire: the supplier fills in a form describing its own controls, and the relationship proceeds on the strength of that answer. It’s a workable starting point, but it has one obvious gap. It only ever reflects what a supplier is willing, or able, to say about itself, whether that falls short through deliberate misrepresentation or an honest misreading of what “good” actually requires. A form doesn’t test anything, and it certainly doesn’t verify health information security in practice. A stolen login session doesn’t care what the form said.
What Independent, Evidence-Based Verification Looks Like
This is the gap Australian Cyber Essentials (ACE) was built to close. Rather than taking a supplier’s word for it, ACE certification is issued only once Bureau Veritas, an independent, internationally recognised certification body, has reviewed actual evidence of the controls and governance a business has in place. It runs across three tiers, from foundational controls and governance (ACE Ready) through enhanced controls and mature governance (ACE Robust) to advanced, continuously improving assurance (ACE Resilient), underpinned by a proper information security management system rather than a checklist.
Every organisation handling patient or health data now depends on third parties for some part of that data’s journey. The AdaptHealth breach is a reminder to ask a harder question of the suppliers holding that access than “did they fill in the form?” The better question, and the one that actually protects health information security, is whether they can prove it.