AdaptHealth Corp. (Nasdaq: AHCO) filed a Current Report on Form 8-K on July 2, 2026 under Item 1.05, the disclosure line the U.S. Securities and Exchange Commission created for material cybersecurity incidents. The filing tells a careful, sequenced story, and the discipline for a business reader is to report exactly what it states and nothing more. According to the 8-K, AdaptHealth is investigating a security incident in which a threat actor gained unauthorized access to Company systems and exfiltrated certain data. The company says it activated its incident response procedures upon learning of the event, engaged external advisors and cybersecurity experts to assess and contain the threat, and notified law enforcement. On June 27, 2026, it states, it determined the incident is material "due to the nature and potential volume of the data that is at risk." The four-business-day disclosure clock that Item 1.05 sets runs from that materiality determination, not from the intrusion itself.

The filing is specific about what the company has been able to confirm and equally specific about what it has not. AdaptHealth states that, based on information obtained to date, it believes a threat actor gained unauthorized access to certain of the company's cloud-based business applications, including certain internal patient-management systems and document-storage platforms. It says it received a communication from a threat actor on June 15, 2026 claiming to have obtained data from its systems. The company then reports what it has verified about exfiltration and access.

The Company has confirmed that certain data was exfiltrated from its systems including a stored password file associated with insurance billing; the Company also has confirmed that certain external electronic health record system portals were accessed by the threat actor.— AdaptHealth Corp., Form 8-K (Item 1.05), filed July 2, 2026, source

On the categories of information involved, the 8-K states that the affected data includes passwords associated with insurance billing and certain personally identifiable information and protected health information of patients. It also draws two explicit boundaries around what is not implicated: the company says it does not collect Social Security numbers in the affected systems and does not store individual financial account information or payment card information in those systems. Those are the company's stated confirmations as of the filing date; the disclosure does not quantify how many individuals or records are involved, and this article does not infer a number the filing declines to give.

How the intrusion happened, per the filing

AdaptHealth attributes the entry point to a single cause. The incident, the 8-K states, "was the result of a successful social engineering attack that compromised a user session associated with a third-party contractor." That is the mechanism the company discloses; the filing does not name the threat actor, describe attribution, or characterize the actor's identity or affiliation, and neither does this report. The disclosure moves directly from cause to response. Following detection, the company says it promptly implemented containment measures, including disabling the compromised user account, resetting affected credentials, and implementing additional access controls, and it states that "the incident has been contained." The company adds that it is continuing to investigate the nature and scope of the incident with external forensics teams, and that it has taken steps intended to mitigate the risk of dissemination of the exfiltrated data.

Two limits on the disclosure are stated plainly. The company says the full scope of affected data sets has not yet been determined, and that specific information regarding the volume of data at issue is not yet available. It commits to amend the Current Report as required information is determined or becomes available. That amendment language is a routine feature of Item 1.05 filings made while an investigation is open, and it signals that the record here is a first disclosure rather than a final accounting.

What the filing says about impact, cost, and insurance

For a business-desk reader, the operative lines are the ones on impact. As of the date of the report, the company states, the incident has not had a material impact on its operations and has not affected its ability to service its patients. That sentence sits in tension, on its face, with the materiality determination that triggered the filing, but the two are answering different questions: Item 1.05 turns on the materiality of the incident given the nature and potential volume of data at risk, while the operational statement addresses whether business operations have been disrupted to date. The filing keeps those distinct, and so should any reading of it.

On the financial dimension, the company is explicit that the number is not yet knowable. It states that it is unable to determine the full financial impact of the incident, including remediation and response costs, legal, regulatory and notification-related matters, and possible effects on patients, counterparties and the company's reputation. It adds one balancing fact: it maintains cybersecurity insurance that may cover certain losses associated with the incident. The 8-K does not put a dollar figure on either the exposure or the coverage, and it does not estimate remediation cost, potential regulatory penalties, or notification expense. Those are the categories the company itself lists as unresolved, and they are the line items a later 10-Q or an amended 8-K would be the place to quantify.

The timeline the filing lays out is worth holding in one view: a threat-actor communication received June 15, 2026; a materiality determination reached June 27, 2026; and the Item 1.05 report filed July 2, 2026. AdaptHealth is a Conshohocken, Pennsylvania-based provider of home medical equipment and related healthcare services, and its systems footprint as described in the filing — cloud-based business applications, internal patient-management systems, document-storage platforms, and external electronic health record portals — is the surface across which the disclosed access and exfiltration occurred. The company frames the healthcare data at issue as the reason the incident cleared its materiality threshold.

Reading it straight

The forward-looking-statements section that closes the 8-K is itself informative about what remains open. AdaptHealth cautions that its statements about the nature and scope of the incident, its ongoing assessment of the extent, categories and volume of data accessed or exfiltrated, the adequacy of its insurance coverage, and the potential impact on its business are estimates subject to risk, and that actual results may differ. In plain terms, the company is telling readers that the confirmed facts in the filing are a snapshot of an active investigation, not a closed case. For coverage that aims to be quotable and defensible, that framing is the assignment: the confirmed facts are the exfiltration of an insurance-billing password file, the access to external EHR portals, the involvement of certain patient PII and PHI, the social-engineering entry via a third-party contractor's session, and the statement that the incident is contained and has not yet materially affected operations. The volume, the full data-set scope, the financial impact, and any regulatory or reputational consequences are the items the company says are still to be determined, and they are where the next filing in this docket will earn its attention.