Desk live·
ForensicPost
Ransomware/Medical devices/File 26-0617

A Cardiac Monitor Produces a Continuous Record of You

iRhythm reported unauthorised access to third-party applications in June 2026, with protected health information and proprietary data taken. Ambulatory monitoring data is unusually revealing and unusually long.

Constructed geometry · not a chart of case data
TargetiRhythm
ActorExtortion actor, unnamed
S. Rosler8 min readConfidence: medium1 source reviewed

iRhythm, which makes ambulatory cardiac monitoring devices, reported unauthorised access to third-party applications with detection around 8 June 2026. Protected health information and proprietary data were described as taken.

Most health records are episodic — a visit, a test, a result. Ambulatory monitoring is not. A patch worn for up to two weeks produces a continuous physiological record.

Continuous Data Describes Behaviour, Not Just Physiology

A continuous cardiac record contains more than cardiac information. Heart rate over a fortnight indicates sleep and waking times, exertion, periods of stress, and disruptions to routine. It is a behavioural record produced as a by-product of a clinical one.

Patients consent to cardiac monitoring for a cardiac reason. It is not obvious that consent extends to the inferences the same data supports, and that gap is not addressed by any notification letter.

The Third-Party Application Layer, Again

The reported route is unauthorised access to third-party applications — the same structural pattern this desk has filed repeatedly this year. A medical device company is a software company with a regulated hardware product attached, and its software estate includes integrations it does not operate.

Device regulation scrutinises the device. The application ecosystem around it is governed as ordinary enterprise software, and that is where this incident occurred.

How we reported this

Compiled from public reporting, listed below. The affected population has not been disclosed. We have not reviewed the affected data. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary