Business Context and Reporting Period
Company: iRhythm Holdings, Inc.
Filing Type: Form 8-K (Current Report)
Date of Report: June 10, 2026
Event Date: June 8, 2026 (Incident Identification)
Subject: Material Cybersecurity Incident (Item 1.05)
Key Financial Metrics
This filing is a current report regarding a cybersecurity incident and does not contain financial statements, revenue, profit, cash flow, margin, debt, or liquidity metrics. The filing text does not provide a clear value for these items.
Material Changes and Incident Details
- Incident Nature: Unauthorized activity involving data on third-party-hosted business applications identified on June 8, 2026.
- Method of Access: Social engineering.
- Data Compromised: Proprietary data, patient protected health information (PHI), and other personal information.
- Threat Actor Activity: On June 9, 2026, a threat actor claimed possession of the data and demanded payment to prevent public disclosure. The Company confirmed data exfiltration.
- Materiality: Determined material on June 10, 2026, due to the volume of potentially affected data.
- Operational Impact: No impact identified on products, clinical/medical device systems, patient safety, manufacturing, distribution, or financial reporting systems.
- Financial Data: The Company does not store individual financial account or payment card information.
Outlook, Risks, and Management Commentary
- Financial Impact Assessment: Management believes the incident is not reasonably likely to have a material impact on the Company's financial condition or results of operations as of the filing date.
- Insurance: The Company maintains cybersecurity insurance that may cover certain losses, though no assurance is given that coverage will be sufficient for all losses.
- Current Status: No evidence of ongoing unauthorized access has been identified. Investigation into the scope and categories of data continues.
- Risks: Potential legal, regulatory, reputational, and financial risks remain. The threat actor may still publish or misuse the data.
- Future Filings: The Company will amend this report if additional information regarding the incident becomes available.
Investor Verification Checklist
- Verify the final volume and specific categories of patient and personal data exfiltrated once the investigation concludes.
- Monitor for any public disclosure of data by the threat actor despite payment demands.
- Assess the adequacy of the Company's cybersecurity insurance coverage relative to potential regulatory fines and remediation costs.
- Watch for future amendments to this 8-K or subsequent 10-Q filings for updates on legal or regulatory actions.
- Confirm that no patient safety issues arise from the incident, despite the current assessment of no impact on medical devices.