iRhythm Technologies Inc. disclosed a data security incident to the Texas Attorney General on October 6, 2026, triggering legally mandated notification letters. If you are one of the people who received iRhythm Technologies Inc.'s letter, your data may have been exposed and you could be entitled to compensation.
The Texas Attorney General filing confirms the breach notice — not a court case. This tracker shows settlement figures and deadlines solely where a public court record exists. Outcomes are never estimated or promised.
Per the Texas Attorney General filing, the iRhythm Technologies Inc. incident compromised these categories of personal information:
The more sensitive the data involved, the stronger the potential claim. Disclosure of these categories is legally recognized harm.
iRhythm Technologies Inc. operates at the intersection of digital health and cardiac care, specializing in advanced ambulatory electrocardiogram (ECG) monitoring solutions and AI-driven diagnostic software. Because their core business involves capturing, transmitting, and analyzing continuous cardiac telemetry data for patients nationwide, the company collects and maintains a vast repository of highly sensitive information. This includes not only standard administrative and demographic records but also deeply personal physiological data, real-time diagnostic histories, and continuous heart rhythm recordings collected via proprietary devices like the Zio patch. The proprietary nature of their services means they function as a critical data repository for cardiologists, hospitals, and patients, holding records that are uniquely intimate and irreplaceable.
In 2026, iRhythm Technologies Inc. reported a significant cybersecurity incident to the Texas Attorney General, triggering widespread concern among patients and healthcare providers alike. While specific forensic details continue to emerge, security events affecting medical device manufacturers and digital health platforms typically involve sophisticated network intrusions, unauthorized access to cloud-based clinical databases, or compromises within third-party vendor ecosystems. In the healthcare technology sector, threat actors frequently target the infrastructure used to store diagnostic telemetry and patient management systems, seeking to exfiltrate proprietary medical datasets, intellectual property, and extensive patient dossiers for illicit monetization on underground forums.
The data compromised in incidents involving health tech providers typically encompasses a dangerous combination of Protected Health Information (PHI) and Personally Identifiable Information (PII). For patients whose records were exposed in the iRhythm breach, this likely includes full names, dates of birth, Social Security numbers, health insurance details, medical record numbers, and detailed cardiac diagnostic and treatment information. Unlike basic retail data breaches where credit cards can be canceled, the exposure of continuous ECG monitoring data, clinical histories, and core demographic markers creates lifelong risks. Cybercriminals can exploit this information to perpetrate sophisticated medical identity theft—such as obtaining unauthorized prescription drugs, billing fraudulent procedures under a victim's insurance, or accessing specialized care networks—while also laying the groundwork for traditional financial fraud and targeted phishing campaigns.
As a digital health entity handling sensitive medical records, iRhythm Technologies Inc. is bound by stringent regulatory frameworks, including the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and applicable Texas data protection statutes. These laws mandate rigorous technical, physical, and administrative safeguards to protect electronic PHI from unauthorized access, disclosure, or theft. When a breach of this magnitude occurs, it often serves as prima facie evidence of systemic failures in data encryption, vulnerability management, or network segmentation, suggesting that the company may have fallen short of its legal duty to maintain reasonable and appropriate cybersecurity standards.
Receiving a formal data breach notification letter from iRhythm Technologies Inc. carries significant legal implications for affected individuals. Legally, the notification serves as an admission by the company that your confidential medical and personal data was compromised due to inadequate security controls. Under modern class action jurisprudence, the receipt of such a notice establishes legal standing to pursue litigation, allowing victims to seek accountability, injunctive relief, and financial compensation for the increased risk of identity theft and the time spent mitigating potential fraud. Crucially, affected individuals do not need to prove that financial loss has already occurred to participate in a class action lawsuit. Our firm investigates these matters on a strict contingency fee basis, meaning there are never any out-of-pocket costs or fees unless we successfully recover compensation on your behalf.
Notification Delay: Approximately 4 months elapsed between the reported date of the security incident and the company's notification to the Attorney General. Courts have found that excessive notification delays independently support legal claims.
You do not need to show financial loss to be eligible. Courts have treated exposure of personal data as real harm. You likely qualify if any of the statements below describe you:
You received a data breach notification letter from iRhythm Technologies Inc.
You were a customer, patient, employee, or client of iRhythm Technologies Inc.
Your personal information was stored in iRhythm Technologies Inc.'s systems
Your Social Security number or driver's license number was exposed
Your medical records, diagnoses, or health insurance information was compromised
You reside in the United States (all 50 states eligible)
That letter is legally required and confirms your data was exposed. It also gives you standing to file a claim.
What your notification letter means & what to do next →Do these four things as soon as possible; each one protects you and strengthens any claim:
Keep the iRhythm Technologies Inc. letter. It is the document that proves you were part of this breach; a claim without it is weaker. Store a scanned backup.
Your letter likely includes a monitoring activation code. Use it: free monitoring flags misuse of your data and records the harm for your case.
Place security freezes at all three bureaus — Equifax, Experian, TransUnion. New-account fraud dies at the freeze; you can unfreeze temporarily for legitimate applications.
Deadlines apply to breach claims. A free review of your iRhythm Technologies Inc. letter takes minutes, and we only get paid if you do.
Security Incident
2026-06-03
iRhythm Technologies Inc.'s systems were compromised, exposing stored personal records.
Reported to Attorney General
October 6, 2026
iRhythm Technologies Inc. filed its official breach notice with the Texas Attorney General.
Consumer Notification Letters Sent
Within weeks of AG filing
Affected individuals receive mailed notification letters as required by statute.
Legal Window — Act Now
Statute of limitations applies
Legal deadlines limit how long you have to act on this breach.
Breach victims may recover several categories of loss. What applies in the iRhythm Technologies Inc. matter depends on your state, the data involved, and the company's conduct.
Per-incident statutory damages may be available even without proof of fraud; California's $100–$750 statute is the leading example.
If the breach led to fraudulent charges or unauthorized transactions on your accounts, those losses are recoverable.
The time you lost to credit freezes, fraud disputes, and account monitoring counts as a recoverable inconvenience.
Credit-monitoring subscriptions and protection plans you bought because of the breach are recoverable expenses.
SSN and driver's license exposure creates long-term identity theft risk. Courts recognize the ongoing value of this harm and may award damages accordingly.
The unauthorized exposure of health and medical information may trigger HIPAA-related claims and additional state health privacy protections.
Texas's Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code § 521) requires notification within 60 days and imposes civil penalties up to $500,000 for violations. Texas residents may pursue civil action for data security failures.
Other companies have notified the Texas AG of breaches. Received one of these letters as well? You may have more than one claim.
Cleburne Independent School District
Texas · Oct 2026
Harman Fitness
Texas · Oct 2026
Capitol Pain Institute
Texas · Oct 2026
Edgewood ISD
Texas · Oct 2026
Flowco Holdings Inc.
Texas · Oct 2026
Sheppard, Mullin, Richter & Hampton LLP
Texas · Oct 2026
Contact us for a FREE consultation. No fee unless we win your case.
(786) 306-7278Free Claim ReviewLaw Office of David S. Harris