Leadership2 publishers2 min readPublished
AdaptHealth declared its breach material 12 days after it discovered the intrusion
The Item 1.05 filing names a contractor's hijacked session, an exfiltrated insurance-billing password file and patient health data, and promises amendments as the still-open investigation produces facts.
The Board Room · Leadership desk

What happened
- AdaptHealth Corp. told the SEC under Item 1.05 that a threat actor reached cloud-based business applications including internal patient management systems and document storage platforms.
- The company said it determined on June 27, 2026 that the incident was material because of the nature and potential volume of data at risk, with its investigation still running.
- That notice says the affected information did not include social security numbers, credit or debit card details, or bank account information.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- decision The determination date is the company's own to set, and every later filing gets read against it.
- constraint A vendor programme built around issuing and revoking contractor credentials still misses a live session in a contractor's hands. That is what failed here.
- contradiction An investor reading the 8-K learns that a billing credential file was exfiltrated; a patient reading the August notice gets categories of information, so the two audiences cannot compare exposure.
- precedent Filing an unfinished investigation with an explicit promise to amend gives other healthcare registrants a workable pattern for disclosing before the scope is settled.
AdaptHealth wrote that "To the extent any information required by Item 1.05 of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available" [10]. That sentence sits just before the safe-harbour language, and it is the one other filers will copy, because it lets a company report an intrusion it has not finished investigating [11].
The August notice says AdaptHealth discovered on June 15 that it had been attacked on June 5 [13], ten days earlier [1]. The 8-K puts something else on June 15: the company received a communication from a threat actor claiming to have obtained data from its systems [5]. The materiality determination came twelve days after the discovery [2].
AdaptHealth said it decided the incident was material "due to the nature and potential volume of the data that is at risk" [2], and said in the same filing that the investigation was continuing [11]. Materiality here rested on that characterisation. By then it had activated its incident response procedures, brought in external advisers and cybersecurity experts, and notified law enforcement [12].
AdaptHealth disabled the compromised user account, reset affected credentials, added access controls, and said the incident has been contained [9]. Those steps covered systems it controls. The access it describes went past its own tenancy: the actor was inside cloud-based business applications, and the filing also confirms that certain external electronic health record system portals were accessed [4][6].
AdaptHealth said the incident was "the result of a successful social engineering attack that compromised a user session associated with a third-party contractor" [8]. That puts the control question on live sessions.
To the SEC, AdaptHealth named what was exfiltrated: a stored password file associated with insurance billing [6]. To individuals in August, it described categories of information that may have been affected, said it was not aware of any actual or attempted identity theft, fraud or other misuse, and offered at least twelve months of credit monitoring at no charge [14][15][16]. The registrant on the 8-K is AdaptHealth Corp.; the notice comes from AdaptHealth, LLC [1][13]. Forty-eight days separate the determination from that notice [3], and seventy days separate the attack from it [4].
The 8-K does not state a number of affected individuals or an estimate of financial impact [17]. What it does is put June 27 on the record as the date the company decided the incident was material [2] and bind the company to amend as facts arrive [10], two fixed points a regulator or a plaintiff can measure against.
What to watch
- An amendment to the June 27 8-K adding an affected-individual count, a cost estimate or a wider scope of systems.
- Any move from AdaptHealth's position that it is not aware of misuse to identified fraudulent billing activity using the stolen insurance-billing passwords.
- Whether AdaptHealth Corp. quantifies the incident's financial impact in a later periodic filing.