iRhythm Holdings updates on a cybersecurity incident, notifying affected individuals and providing guidance on protecting personal information.
Quiver AI Summary
iRhythm Holdings, Inc. has provided an update on a cybersecurity incident from June 2026, where unauthorized access to third-party-hosted business applications was detected. Following a forensic investigation, the company has begun notifying affected individuals about the compromised data, which includes personal information such as names, contact details, patient account numbers, and insurance numbers. While there is no evidence suggesting this data will be used for identity theft, iRhythm is advising individuals to take protective measures, including monitoring their financial accounts and placing fraud alerts. The company has established a call center to assist those impacted and confirmed that the incident has not affected its products or patient services. iRhythm reassures stakeholders that it is committed to safeguarding personal information and has taken steps to improve data privacy and security practices. Additional information is available on iRhythm’s website.
Potential Positives
- iRhythm has taken proactive measures by implementing its incident response plan promptly after detecting unauthorized access, demonstrating its commitment to security.
- The company has been transparent about the incident, informing impacted individuals and providing them with guidelines to protect their information, which builds trust with customers.
- There is no indication that the incident has affected the company's products or patient safety, ensuring continuity in its operations and maintaining confidence in its services.
- iRhythm continues to evaluate and improve its security practices, reinforcing its commitment to safeguarding personal information moving forward.
Potential Negatives
- Significant cybersecurity breach exposed sensitive patient data, including names, contact information, and insurance numbers, potentially leading to a loss of trust among patients and stakeholders.
- The incident may necessitate increased scrutiny from regulatory bodies, which could result in compliance costs or fines if deemed negligent in safeguarding personal information.
- The need to establish a call center for affected individuals suggests a resource drain and reflects the seriousness of the incident, which could distract from normal business operations.
FAQ
What was the nature of the cybersecurity incident at iRhythm?
iRhythm detected unauthorized access to certain third-party-hosted business applications, leading to the download of impacted data.
What data was accessed in the iRhythm cybersecurity incident?
The impacted data includes patient names, contact information, account numbers, device serial numbers, insurance numbers, service dates, and birth dates.
How is iRhythm handling the situation?
iRhythm has notified impacted individuals and provided them with best practices to protect their information, along with a dedicated call center for support.
Is there any evidence of identity theft from the incident?
iRhythm found no evidence that personal information has been or will be used for identity theft.
What measures is iRhythm taking to protect personal information?
iRhythm is committed to safeguarding personal information and regularly evaluates and updates its security practices and controls.
Disclaimer: This is an AI-generated summary of a press release distributed by GlobeNewswire. The model used to summarize this release may make mistakes. See the full release here.
$IRTC Insider Trading Activity
$IRTC insiders have traded $IRTC stock on the open market 9 times in the past 6 months. Of those trades, 0 have been purchases and 9 have been sales.
Here’s a breakdown of recent trading of $IRTC stock by insiders over the last 6 months:
- QUENTIN S. BLACKFORD (President and CEO) sold 26,859 shares for an estimated $3,348,011
- MINANG TURAKHIA (CHIEF MED/SCI OFCR EVP ADVTECH) has made 0 purchases and 2 sales selling 8,516 shares for an estimated $1,061,613.
- CHAD PATTERSON (CHIEF COMM & PRODUCT OFFICER) sold 7,093 shares for an estimated $884,170
- PATRICK MICHAEL MURPHY (CBO and CLO) sold 7,093 shares for an estimated $884,155
- SUMI SHRISHRIMAL (EVP, Chief Risk Officer) sold 5,372 shares for an estimated $669,640
- BRIAN LEE LAWRENCE (Chief Technology Officer) sold 1,014 shares for an estimated $122,491
- SEAN CLINTON FREEMAN (EVP, Strategy & Corp Devt) sold 918 shares for an estimated $114,483
- DANIEL G. WILSON (Chief Financial Officer) sold 773 shares for an estimated $94,174
To track insider transactions, check out Quiver Quantitative's insider trading dashboard. You can access data on insider stock transactions through the Quiver Quantitative API insider transaction endpoint.
$IRTC Revenue
$IRTC had revenues of $224.2M in Q2 2026. This is an increase of 20.08% from the same period in the prior year.
You can track IRTC financials on Quiver Quantitative's IRTC stock page.
You can access data on IRTC stock through the Quiver Quantitative API.
$IRTC Hedge Fund Activity
We have seen 151 institutional investors add shares of $IRTC stock to their portfolio, and 131 decrease their positions in their most recent quarter.
Here are some of the largest recent moves:
- SANDS CAPITAL MANAGEMENT, LLC removed 1,699,645 shares (-100.0%) from their portfolio in Q2 2026, for an estimated $202,172,772
- JPMORGAN CHASE & CO added 766,216 shares (+inf%) to their portfolio in Q2 2026, for an estimated $91,141,393
- RTW INVESTMENTS, LP added 514,131 shares (+30.8%) to their portfolio in Q2 2026, for an estimated $61,155,882
- HOLOCENE ADVISORS, LP removed 465,022 shares (-37.2%) from their portfolio in Q2 2026, for an estimated $55,314,366
- BRAIDWELL LP added 436,917 shares (+201.0%) to their portfolio in Q2 2026, for an estimated $51,971,277
- MACKENZIE FINANCIAL CORP removed 371,475 shares (-100.0%) from their portfolio in Q2 2026, for an estimated $44,186,951
- POINT72 ASSET MANAGEMENT, L.P. removed 326,243 shares (-54.4%) from their portfolio in Q2 2026, for an estimated $38,806,604
To track hedge funds' stock portfolios, check out Quiver Quantitative's institutional holdings dashboard. You can access data on hedge funds moves and 13F filings through the Quiver Quantitative API 13F endpoint.
$IRTC Analyst Ratings
Wall Street analysts have issued reports on $IRTC in the last several months. We have seen 2 firms issue buy ratings on the stock, and 0 firms issue sell ratings.
Here are some recent analyst ratings:
- BTIG issued a "Buy" rating on 06/10/2026
- Needham issued a "Buy" rating on 05/01/2026
To track analyst ratings and price targets for $IRTC, check out Quiver Quantitative's $IRTC forecast page.
$IRTC Price Targets
Multiple analysts have issued price targets for $IRTC recently. We have seen 10 analysts offer price targets for $IRTC in the last 6 months, with a median target of $172.5.
Here are some recent targets:
- Vijay Kumar from Evercore ISI Group set a target price of $150.0 on 07/06/2026
- Marie Thibault from BTIG set a target price of $185.0 on 06/22/2026
- William Plovanic from Canaccord Genuity set a target price of $152.0 on 06/01/2026
- Stephanie Piazzola from B of A Securities set a target price of $180.0 on 05/18/2026
- Joanne Wuensch from Citigroup set a target price of $157.0 on 05/04/2026
- David Saxon from Needham set a target price of $255.0 on 05/01/2026
- Nathan Treybeck from Wells Fargo set a target price of $180.0 on 05/01/2026
Full Release
SAN FRANCISCO, Oct. 02, 2026 (GLOBE NEWSWIRE) -- iRhythm Holdings, Inc. (NASDAQ:IRTC) today provided an update regarding the cybersecurity incident previously disclosed in June 2026. Following completion of the forensic investigation and subsequent review to determine the nature of the impacted data, the company has begun notifying impacted individuals.
As previously disclosed, on or around June 8, 2026, iRhythm detected unauthorized access in certain third-party-hosted business applications. Upon detecting the unauthorized access, iRhythm promptly implemented its incident response plan. As part of the investigation, iRhythm has been working very closely with external cybersecurity professionals experienced in handling these types of incidents. After completing the forensic investigation, iRhythm learned certain data it stores was accessed and downloaded by unauthorized individuals between June 3 and June 8, 2026.
Following the forensic investigation, iRhythm carried out a review to determine the nature of the impacted data. This review concluded the impacted data includes: patient name; patient contact information, including address, email address, and phone number; iRhythm patient account number; iRhythm device serial number; patient insurance number; date of service; and date of birth.
iRhythm has no evidence that any personal information has been or will be used to commit identity theft. However, beginning October 2, 2026, iRhythm began notifying impacted individuals for whom it maintains contact information. Notified individuals have been provided with instructions on best practices to protect their information.
Out of an abundance of caution, those served by iRhythm are encouraged to take steps to protect themselves. This includes protecting themselves against medical identity theft and identity fraud, placing a fraud alert/security freeze on their credit files, obtaining free credit reports, and remaining vigilant in reviewing financial account statements and credit reports for fraudulent or irregular activity on a regular basis.
iRhythm has also established a call center to address questions from impacted individuals. Representatives are available from 8:00 a.m. to 8:00 p.m. Eastern time, Monday through Friday, excluding major U.S. holidays, at 1-844-770-7175.
As iRhythm previously reported, the company has not identified any impact to our products, our clinical or medical device systems, our connections to customers, our manufacturing and distribution operations, patient safety, or our ability to meet patient needs. In addition, iRhythm does not store or retain individual financial account information or payment card information. The company continues to believe, as previously stated in the Current Report on Form 8-K dated June 15, 2026, that the incident is not reasonably likely to have a material impact on the Company’s financial condition or results of operations.
iRhythm is committed to maintaining the privacy and security of personal information in its possession and has taken precautions to safeguard it. iRhythm regularly evaluates and modifies its practices and internal controls to safeguard the security and privacy of the information it maintains and is taking steps to mitigate the risk to individuals impacted by this incident.
Individuals may visit iRhythm’s website https://www.irhythmtech.com/us/en/who-we-are/news-events/notice-of-data-event to learn more about the incident and steps they can take to protect their information.
About iRhythm Holdings
iRhythm is a leading digital health care company with a mission to boldly innovate to create trusted solutions that detect, predict, and prevent disease. Combining wearable biosensors and cloud-based data analytics with powerful proprietary algorithms, iRhythm distills data from millions of heartbeats into clinically actionable information. Through a relentless focus on patient care, iRhythm’s vision is to deliver better data, better insights, and better health for all.
iRhythm Contacts
| Investors | Media |
| Francis Pruell | Kassandra Perry |
| [email protected] | [email protected] |