NEWTOWN, Pa., Oct. 06, 2026 (GLOBE NEWSWIRE) -- Edelson Lechtzin LLP, a national class action law firm, is investigating data privacy claims arising from a reported data breach at iRhythm Holdings, Inc. (NASDAQ: IRTC). Anyone who has received a data breach notice from iRhythm, or who believes their personal information may have been exposed, can request a free case evaluation.
iRhythm Holdings data breach — at a glance
Company: iRhythm Holdings, Inc. is a San Francisco-based heart-monitoring company and maker of the Zio cardiac monitoring platform, used by approximately 8 million patients in the U.S. and Europe.
Reported: iRhythm disclosed the incident to the U.S. Securities and Exchange Commission on a Form 8-K dated June 10, 2026, and, following its investigation, began notifying impacted individuals on October 2, 2026.
How it happened: An unauthorized party gained access to certain third-party-hosted business applications through social engineering; a threat actor then demanded payment not to disclose the data.
When: The unauthorized access was detected on or around June 8, 2026.
Who may be affected: Patients and others whose personal and protected health information iRhythm maintained and who received a notification.
Status: The total number of individuals affected has not been publicly confirmed; iRhythm has described the incident as material given the volume of data involved.
- Cost to you: Nothing. Click here for a free evaluation.
What Happened
On or around June 8, 2026, iRhythm detected unauthorized access to certain third-party-hosted business applications and activated its incident response plan. On June 9, 2026, a threat actor claimed to have obtained sensitive information — including patient protected health information — and demanded payment not to disclose it. iRhythm disclosed the incident to the SEC on June 10, 2026, as material given the volume of data involved, and, after completing its investigation, began notifying impacted individuals on October 2, 2026. The total number affected has not been publicly confirmed.
What Personal Information May Be at Risk
According to iRhythm, the information involved varied by individual and may include patient name; contact information (address, email, and phone number); iRhythm patient account number; device serial number; patient insurance number; date of service; and date of birth. iRhythm states it does not store individual financial account or payment card information and has no evidence that any information has been or will be used to commit identity theft.
Your Legal Options
Edelson Lechtzin LLP is investigating a potential class action on behalf of patients whose sensitive personal and health information may have been compromised. A successful case could recover compensation for losses such as lost time, out-of-pocket costs, and loss of privacy, and could push iRhythm to strengthen how it protects personal information. Anyone who received a breach notification may face an increased risk of identity theft and fraud and is encouraged to come forward. The firm will evaluate your rights and potential claims at no cost.
Recommended Steps to Protect Yourself
- Preserve any breach notice you received, and monitor your account statements and credit reports for suspicious activity.
- Because health and insurance information may be involved, guard against medical identity theft by reviewing explanation-of-benefits statements for services you did not receive.
- Consider placing a fraud alert or security freeze with Equifax, Experian, and TransUnion, and request your free annual credit reports at annualcreditreport.com.
Contact Us for a Free Case Evaluation
Speak confidentially with a data privacy attorney today: Marc Edelson, Esq., Edelson Lechtzin LLP, 411 S. State Street, Suite N-300, Newtown, PA 18940; Phone: 844-696-7492; Email: medelson@edelson-law.com; Web: www.edelson-law.com.
About Edelson Lechtzin LLP
Edelson Lechtzin LLP is a national class action law firm with offices in Pennsylvania and California. In addition to data breach litigation, the firm handles class and collective actions involving securities and investment fraud, federal antitrust violations, ERISA employee benefit plans, wage theft, and consumer fraud.
Legal Notice: This press release may be considered Attorney Advertising in some jurisdictions. Prior results do not guarantee a similar outcome. The data breach described above is based on iRhythm's public disclosures, including its Form 8-K and subsequent incident update; certain details, including the total number of individuals affected, remain unconfirmed.