Business Context and Reporting Period
Company: iRhythm Holdings, Inc.
Filing Type: Form 8-K (Current Report)
Date of Report: June 10, 2026
Event Date: June 8, 2026 (Incident Identification)
Subject: Material Cybersecurity Incident (Item 1.05)
Key Financial Metrics
This filing is a current report regarding a cybersecurity incident and does not contain financial statements. Consequently, specific values for revenue, profit, cash flow, margins, debt, and liquidity are not provided in this document.
Material Changes and Incident Details
- Incident Nature: Unauthorized activity involving data on third-party-hosted business applications identified on June 8, 2026.
- Method of Entry: Social engineering.
- Data Compromised: Proprietary data, patient protected health information (PHI), and other personal information.
- Threat Actor Activity: On June 9, 2026, a threat actor claimed possession of the data and demanded payment to prevent public disclosure. The Company confirmed data exfiltration.
- Materiality: The incident was deemed material on June 10, 2026, due to the volume of potentially affected data.
- Operational Impact: No impact identified on products, clinical/medical device systems, patient safety, manufacturing, distribution, or financial reporting systems.
- Financial Data: The Company does not store individual financial account or payment card information.
Outlook, Risks, and Management Commentary
- Financial Impact Assessment: Management believes the incident is not reasonably likely to have a material impact on the Company's financial condition or results of operations as of the filing date.
- Insurance: The Company maintains cybersecurity insurance that may cover certain losses, though there is no assurance coverage will be sufficient for all incurred losses.
- Ongoing Investigation: The Company is continuing to assess the nature, scope, categories, and volume of data involved, as well as the number of individuals affected.
- Current Status: No evidence of ongoing unauthorized access has been identified as of the filing date.
- Risks: Potential risks include legal, regulatory, reputational, and financial consequences, as well as the potential publication or misuse of affected data by the threat actor.
Key Facts for Investor Verification
- Verify the final volume and specific categories of data exfiltrated once the investigation concludes.
- Monitor for any future amendments to this 8-K regarding the scope of the incident or regulatory inquiries.
- Assess the adequacy of the Company's cybersecurity insurance coverage relative to potential legal and remediation costs.
- Watch for any impact on customer trust or regulatory penalties that could affect future revenue, despite current management assertions.
- Confirm that no ongoing unauthorized access exists as the investigation progresses.