Skip to content
BREACH/TRIGGER
HEALTHCAREItem 1.05 · Form 8-KUpdated

SEC cyber 8-K disclosures in the healthcare sector

Providers, payers, and health-tech companies where a cyber incident is usually also a regulated health-data breach.

Informational only, not legal, security, or investment advice. This is a high-level summary of a fast-moving area. Verify every rule and filing against primary sources (sec.gov/edgar and the named regulators) before acting.

What is an SEC Item 1.05 cybersecurity 8-K?

The SEC adopted its cybersecurity disclosure rules in 2023. Item 1.05 of Form 8-K requires a public company to disclose a material cybersecurity incident within 4 business days of determining a cybersecurity incident is material. Companies sometimes file non-material or precautionary cyber disclosures under Item 8.01 instead of Item 1.05.

Why cyber 8-K disclosures matter for healthcare companies

In healthcare, a cybersecurity incident is frequently also a protected-health-information breach, so an SEC 8-K commonly runs in parallel with HIPAA breach-notification duties to individuals, regulators, and sometimes the media. The overlap makes materiality determinations complex, and the sector's filings often involve large affected-individual counts that draw regulator and litigation attention.

Overlapping rules for this sector

These run separately from, and often on shorter timelines than, the SEC 8-K:

  • HIPAA Breach Notification Rule

    Covered entities must notify affected individuals without unreasonable delay and no later than 60 days.

  • HHS OCR reporting

    Large breaches must be reported to the HHS Office for Civil Rights and posted publicly.

  • State breach-notification laws

    State medical-data statutes add their own notice duties on top of HIPAA and the SEC filing.

Monitoring note

Healthcare filings often reference substantial affected-population figures. Read the primary 8-K for the materiality basis rather than relying on headline victim counts, which evolve as investigations continue.

HEALTHCARE ALERTS

Catch healthcare cyber 8-Ks the day they file

BreachTrigger polls SEC EDGAR every 30 minutes and links every alert to the primary filing. The weekly sector digest is free; Instant Alerts adds same-day notification with sector and ticker filters.

See alert options →

Healthcare disclosure FAQ

What is an SEC Item 1.05 cybersecurity 8-K?
The SEC adopted its cybersecurity disclosure rules in 2023. Item 1.05 of Form 8-K requires a public company to disclose a material cybersecurity incident within 4 business days of determining a cybersecurity incident is material. Companies sometimes file non-material or precautionary cyber disclosures under Item 8.01 instead of Item 1.05.
Why do cyber 8-K disclosures matter for healthcare companies?
In healthcare, a cybersecurity incident is frequently also a protected-health-information breach, so an SEC 8-K commonly runs in parallel with HIPAA breach-notification duties to individuals, regulators, and sometimes the media. The overlap makes materiality determinations complex, and the sector's filings often involve large affected-individual counts that draw regulator and litigation attention.
Which other rules overlap for the healthcare sector?
HIPAA Breach Notification Rule: Covered entities must notify affected individuals without unreasonable delay and no later than 60 days. HHS OCR reporting: Large breaches must be reported to the HHS Office for Civil Rights and posted publicly. State breach-notification laws: State medical-data statutes add their own notice duties on top of HIPAA and the SEC filing. These run separately from, and often on shorter timelines than, the SEC 8-K.
How do I monitor healthcare breach disclosures?
Every 8-K is public on SEC EDGAR. You can poll EDGAR full-text search yourself, or set a same-day alert filtered to the healthcare sector. This is not legal, security, or investment advice — verify on sec.gov/edgar before acting.
Healthcare: SEC Cyber 8-K Disclosure Rules