SEC cyber 8-K disclosures in the healthcare sector
Providers, payers, and health-tech companies where a cyber incident is usually also a regulated health-data breach.
What is an SEC Item 1.05 cybersecurity 8-K?
The SEC adopted its cybersecurity disclosure rules in 2023. Item 1.05 of Form 8-K requires a public company to disclose a material cybersecurity incident within 4 business days of determining a cybersecurity incident is material. Companies sometimes file non-material or precautionary cyber disclosures under Item 8.01 instead of Item 1.05.
Why cyber 8-K disclosures matter for healthcare companies
In healthcare, a cybersecurity incident is frequently also a protected-health-information breach, so an SEC 8-K commonly runs in parallel with HIPAA breach-notification duties to individuals, regulators, and sometimes the media. The overlap makes materiality determinations complex, and the sector's filings often involve large affected-individual counts that draw regulator and litigation attention.
Overlapping rules for this sector
These run separately from, and often on shorter timelines than, the SEC 8-K:
HIPAA Breach Notification Rule
Covered entities must notify affected individuals without unreasonable delay and no later than 60 days.
HHS OCR reporting
Large breaches must be reported to the HHS Office for Civil Rights and posted publicly.
State breach-notification laws
State medical-data statutes add their own notice duties on top of HIPAA and the SEC filing.
Monitoring note
Healthcare filings often reference substantial affected-population figures. Read the primary 8-K for the materiality basis rather than relying on headline victim counts, which evolve as investigations continue.
HEALTHCARE ALERTS
Catch healthcare cyber 8-Ks the day they file
BreachTrigger polls SEC EDGAR every 30 minutes and links every alert to the primary filing. The weekly sector digest is free; Instant Alerts adds same-day notification with sector and ticker filters.
See alert options →Healthcare disclosure FAQ
- What is an SEC Item 1.05 cybersecurity 8-K?
- The SEC adopted its cybersecurity disclosure rules in 2023. Item 1.05 of Form 8-K requires a public company to disclose a material cybersecurity incident within 4 business days of determining a cybersecurity incident is material. Companies sometimes file non-material or precautionary cyber disclosures under Item 8.01 instead of Item 1.05.
- Why do cyber 8-K disclosures matter for healthcare companies?
- In healthcare, a cybersecurity incident is frequently also a protected-health-information breach, so an SEC 8-K commonly runs in parallel with HIPAA breach-notification duties to individuals, regulators, and sometimes the media. The overlap makes materiality determinations complex, and the sector's filings often involve large affected-individual counts that draw regulator and litigation attention.
- Which other rules overlap for the healthcare sector?
- HIPAA Breach Notification Rule: Covered entities must notify affected individuals without unreasonable delay and no later than 60 days. HHS OCR reporting: Large breaches must be reported to the HHS Office for Civil Rights and posted publicly. State breach-notification laws: State medical-data statutes add their own notice duties on top of HIPAA and the SEC filing. These run separately from, and often on shorter timelines than, the SEC 8-K.
- How do I monitor healthcare breach disclosures?
- Every 8-K is public on SEC EDGAR. You can poll EDGAR full-text search yourself, or set a same-day alert filtered to the healthcare sector. This is not legal, security, or investment advice — verify on sec.gov/edgar before acting.