Digital health-care company iRhythm Holdings provided an update on a cybersecurity incident it disclosed in June, saying certain information about customers was downloaded by unauthorized individuals on June 3-8.
The company previously disclosed that on or around June 8 it detected unauthorized access in certain third party-hosted business applications. The company said it implemented its incident response plan, and also worked with external cybersecurity professionals.
Following a forensic investigation and review, the company said, it determined that impacted data included patient name, patient contact information, iRhythm device serial number and patient insurance number, among other information. The company added it has no evidence that any personal information has been or will be used to commit identity theft.
IRhythm doesn't store or retain individual financial account information or payment card information, it said.
The company also said it began notifying impacted individuals for whom it maintains contact information on Oct. 2.
IRhythm reiterated it hasn't identified any impact to its products, clinical or medical device systems, connections to customers, manufacturing and distribution operations, patient safety, or its ability to meet patient needs.
The company also reiterated it continues to believe the incident isn't reasonably likely to have a material impact on its financial condition or results of operations.
IRhythm said it utilizes wearable biosensors and cloud-based data analytics to distill data from millions of heartbeats into clinically actionable information.