Open report — full analysis, no account required.

Sign up to generate reports and read filings that aren't on the open list.

Sign up free

Get notified when IRTC files again. Create a free account and we'll email you the moment its next filing is analyzed.

Get filing alerts
NASDAQ: IRTC iRhythm Holdings, Inc. 8-K

iRhythm discloses material cybersecurity breach exposing patient health data and proprietary info

Filed June 15, 2026 · Period ending June 10, 2026 · ~1 min read

4 key changes 2 high relevance 1 section

Key Changes

  • high

    Threat actor exfiltrated patient protected health information and proprietary data through social engineering attack on third-party business applications, demanding ransom payment to prevent public disclosure.

  • high

    Company determined incident material on June 10 based on volume of potentially affected data, triggering immediate 8-K disclosure within days of detection.

  • medium

    Core operations including medical devices, patient safety, manufacturing, distribution, and financial reporting systems remain unaffected by the breach.

  • medium

    Management believes incident not reasonably likely to materially impact financial results; cybersecurity insurance may cover losses but adequacy uncertain.

Summary

iRhythm detected unauthorized access to third-party business applications on June 8, 2026, and within 24 hours received ransom demands from a threat actor claiming to have stolen patient protected health information and proprietary data. The company confirmed actual data exfiltration occurred through social engineering tactics and deemed the incident material based on the volume of affected data. While core medical device systems, patient safety operations, and financial reporting remain intact, the exposure of sensitive patient health information creates significant regulatory and reputational risk.

Retail investors should monitor several developments: potential HIPAA penalties from HHS, class action litigation from affected patients, and whether cybersecurity insurance proves adequate to cover remediation costs and legal expenses. The company's assertion that financial impact will be immaterial may prove optimistic if regulatory fines or settlement costs escalate. Watch for updates on the number of affected patients, any operational disruptions from remediation efforts, and whether the threat actor follows through on disclosure threats.

Section-by-Section Diff

Event · Item 1.05

~900 words

iRhythm disclosed a material cybersecurity breach involving exfiltration of proprietary data and patient health information via social engineering.

5 Added
Added Material cybersecurity incident high

Added in current filing · verify on EDGAR →

On June 8, 2026, iRhythm Holdings, Inc. (the “Company”) identified unauthorized activity involving data maintained on certain third-party-hosted business applications. The Company promptly activated its cybersecurity response plan and launched an investigation with the support of external advisors and cybersecurity experts to assess and contain the threat.

The company detected unauthorized access to third-party business applications on June 8, 2026, and immediately began investigating with external cybersecurity experts. This represents a significant security incident requiring formal disclosure under Item 1.05.

Added Data exfiltration and ransom demand high

Added in current filing · verify on EDGAR →

On June 9, 2026, the Company received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information. The communications from the threat actor demanded payment in exchange for not publicly disclosing this information. Since receipt of the communications, the Company has confirmed that certain data was exfiltrated from those applications.

A threat actor contacted the company claiming to have stolen proprietary data and patient protected health information, demanding ransom payment. The company has confirmed actual data exfiltration occurred, making this a material breach involving sensitive patient data.

Added Materiality determination high

Added in current filing · verify on EDGAR →

On June 10, 2026, the Company determined that the incident is material in light of the volume of the potentially affected data.

Management formally determined the incident material based on the volume of potentially affected data, triggering this 8-K filing. This indicates the breach scope is significant enough to warrant immediate public disclosure.

Added Scope and impact assessment medium

Added in current filing · verify on EDGAR →

Based on its investigation as of the date of this Current Report on Form 8-K, (1) the Company has not identified any impact to its products, clinical or medical device systems, patient safety, manufacturing and distribution operations, financial reporting systems, or the Company’s ability to meet patient needs and (2) the affected data was obtained through social engineering and is from certain third-party-hosted business applications.

The company states that core operations including medical devices, patient safety, manufacturing, and financial reporting remain unaffected. The breach occurred through social engineering targeting third-party business applications, not clinical systems. This limits operational disruption but still involves sensitive data exposure.

Added Financial impact assessment medium

Added in current filing · verify on EDGAR →

The Company believes, as of the date of this Current Report on Form 8-K, that the incident is not reasonably likely to have a material impact on the Company’s financial condition or results of operations. The Company maintains cybersecurity insurance that may cover certain losses associated with the incident, although there can be no assurance that such coverage will be sufficient to cover all losses the Company may incur.

Management currently believes the breach will not materially impact financial results and notes cybersecurity insurance coverage exists, though adequacy is uncertain. This assessment may change as investigation continues and potential regulatory penalties, litigation costs, and remediation expenses become clearer.

Was this report useful?

Figures/quotes linked to EDGAR · Narrative written by AI · Jun 15, 2026 · How we verify