{"filing":{"accession_number":"0001388658-26-000055","cik":"0001388658","ticker":"IRTC","company_name":"iRhythm Holdings, Inc.","form":"8-K","filing_date":"2026-06-15","report_date":null,"primary_document":"irtc-20260610.htm","primary_document_url":"https://www.sec.gov/Archives/edgar/data/1388658/000138865826000055/irtc-20260610.htm"},"events":[{"id":11084,"run_id":9718,"accession_number":"0001388658-26-000055","anchor_item_number":"1.05","event_type":"cybersecurity_incident","event_domain":"legal","is_material":true,"confidence":0.98,"summary":"iRhythm disclosed a material cybersecurity incident under Item 1.05 involving unauthorized access to third-party-hosted business applications, exfiltration of sensitive data including patient protected health information, and extortion demands from a threat actor. The Company explicitly determined on June 10, 2026 that \"the incident is material in light of the volume of the potentially affected data,\" and the disclosure covers the required elements: discovery date (June 8), threat actor communications (June 9), confirmation of data exfiltration, and assessment of impact. While the Company states the incident is not reasonably likely to have material financial impact and does not affect clinical systems or patient safety, the materiality determination and the nature of the breach (PHI exfiltration with extortion) clearly qualify this as a material cybersecurity incident under the 2023 8-K cybersecurity disclosure rules.","company_name":"iRhythm Holdings, Inc.","ticker":"IRTC","filing_date":"2026-06-15","form":"8-K","submitted_at":null,"items":[{"id":7582,"accession_number":"0001388658-26-000055","item_number":"1.05","item_title":"Material Cybersecurity Incidents.","event_type":"cybersecurity_incident","event_domain":"legal","is_material":true,"confidence":0.98,"reasoning":"iRhythm disclosed a material cybersecurity incident under Item 1.05 involving unauthorized access to third-party-hosted business applications, exfiltration of sensitive data including patient protected health information, and extortion demands from a threat actor. The Company explicitly determined on June 10, 2026 that \"the incident is material in light of the volume of the potentially affected data,\" and the disclosure covers the required elements: discovery date (June 8), threat actor communications (June 9), confirmation of data exfiltration, and assessment of impact. While the Company states the incident is not reasonably likely to have material financial impact and does not affect clinical systems or patient safety, the materiality determination and the nature of the breach (PHI exfiltration with extortion) clearly qualify this as a material cybersecurity incident under the 2023 8-K cybersecurity disclosure rules.","classifier_version":"claude-haiku-4-5-20251001+prompt-9e0ffca5","taxonomy_version":"v1","classified_at":"2026-06-15T20:31:19.761359+00:00","company_name":"","ticker":null,"filing_date":""}]}],"classifications":[{"id":7582,"accession_number":"0001388658-26-000055","item_number":"1.05","item_title":"Material Cybersecurity Incidents.","event_type":"cybersecurity_incident","event_domain":"legal","is_material":true,"confidence":0.98,"reasoning":"iRhythm disclosed a material cybersecurity incident under Item 1.05 involving unauthorized access to third-party-hosted business applications, exfiltration of sensitive data including patient protected health information, and extortion demands from a threat actor. The Company explicitly determined on June 10, 2026 that \"the incident is material in light of the volume of the potentially affected data,\" and the disclosure covers the required elements: discovery date (June 8), threat actor communications (June 9), confirmation of data exfiltration, and assessment of impact. While the Company states the incident is not reasonably likely to have material financial impact and does not affect clinical systems or patient safety, the materiality determination and the nature of the breach (PHI exfiltration with extortion) clearly qualify this as a material cybersecurity incident under the 2023 8-K cybersecurity disclosure rules.","classifier_version":"claude-haiku-4-5-20251001+prompt-9e0ffca5","taxonomy_version":"v1","classified_at":"2026-06-15T20:31:19.761359+00:00","company_name":"iRhythm Holdings, Inc.","ticker":"IRTC","filing_date":"2026-06-15"}]}
