Over 1,400 U.S. patient records were exposed as internal ID numbers with no names attached, fewer than 50 with identifying information, and the oncology-device maker says no treatment device was reached.
What happened
NovoCure Limited filed a Form 8-K with the Securities and Exchange Commission on Tuesday, September 1, 2026. EDGAR accepted it at 7:00:43 a.m. ET. The filing is checked under Item 8.01, Other Events, and Item 9.01, Financial Statements and Exhibits. The only exhibit is the cover page interactive data file. There is no Item 1.05.
The disclosure opens by dating the intrusion: “In mid-August 2026, NovoCure Limited (the ‘Company,’ ‘we,’ or ‘us’) through a subsidiary, became aware of unauthorized access to some of its information systems.” The company says it “activated its cybersecurity response plan, implemented containment measures, and initiated an internal investigation of the event,” and engaged outside forensic experts to review what was accessed.
What those experts found is stated in two tiers. The first is large and thin: “internal Company patient ID numbers for over 1,400 U.S. patient records (these ID numbers are only used internally and no patient names or other identifying data for these was exposed).” The second is small and thick: “patient data for fewer than 50 other patients in the western U.S. that included additional identifying information.” Beyond those two groups, the filing lists “general contact information for healthcare providers we work with” and “general contact information for Novocure employees, such as their job titles and phone numbers.”
Then the sentence patients will read first: “No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional.”
NovoCure makes Tumor Treating Fields devices — Optune Gio, Optune Lua, and Optune Pax — worn by patients being treated for glioblastoma, pleural mesothelioma, and, following a recent FDA approval, locally advanced pancreatic cancer. These are patient-operated appliances used at home for many hours a day. The company is registered in Jersey and trades on Nasdaq as NVCR.
On materiality, the filing says: “At this time, we do not believe that this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations; however, at the time of this filing we are continuing to ascertain additional information regarding this incident.”
And then it does something most Item 8.01 cyber filings do not. It writes its own trigger for the item it did not use: “If additional information is obtained whereby we determine this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations, we undertake to file an amendment to this Form 8-K filing under Item 1.05 containing such information within four business days after we, without unreasonable delay, determine such information, or within four business days after such information becomes available.”
On notification, the company says only that it “continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients.” No date is given. As of this writing there is no breach notice on novocure.com, and no press release accompanied the filing. A patient who wants to know whether their record is among the 1,400 currently has one place to look, and it is EDGAR.
Why it matters
The Item choice is not evasion here, and it is worth saying so directly, because Severity Daily has spent two days on filings where the Item choice was the story. Item 1.05 exists for a material cybersecurity incident and its four-business-day clock runs from the determination of materiality, not from discovery. Item 8.01 is the general-purpose box for events a company wants on the record without asserting materiality. When the SEC’s Division of Corporation Finance addressed this in 2024, its guidance pointed in exactly this direction: companies that have not determined an incident to be material should disclose under Item 8.01, so that a filing under 1.05 keeps its meaning as a materiality signal. A registrant that dumps every incident into 1.05 makes the item useless to investors. NovoCure filed the way the staff asked companies to file.
What makes this filing worth reading is the undertaking. Most 8.01 cyber disclosures stop at “we do not believe this is material.” NovoCure’s states the condition under which it will refile, names the item, and restates the four-business-day clock. That is a disclosure control written into the disclosure itself, and it is cheap to copy. It also creates a public commitment that can be checked later, which is more than most readers get.
The contrast with yesterday is instructive rather than accusatory. Nutex Health moved its breach disclosure from Item 8.01 to Item 1.05 seven days after first filing it, while still saying it did not expect a material impact — a refiling that raised the question of what the 1.05 designation was doing there at all. NovoCure has taken the other route: file 8.01, say plainly it is not material yet, and name in advance the circumstance that would change that. Two companies, two weeks apart, reaching opposite conclusions about the same pair of boxes. The boxes are the problem, not either filer.
On the data itself, the two-tier description deserves a careful read rather than a reassured one. “Internal Company patient ID numbers” with “no patient names or other identifying data” is a real distinction, and 1,400 bare identifiers are worth much less than 1,400 records. But the qualifier is that these IDs “are only used internally” — an assertion about how NovoCure uses them, not a claim that they are meaningless to someone who took them out of NovoCure’s internal systems. Whether an internal ID is re-identifiable depends on whether the party holding it can also reach a mapping. The filing does not say what else was in the environment those IDs came out of, and it does not name the subsidiary involved. Both are reasonable things to withhold mid-investigation. Both are also the difference between 1,400 numbers and 1,400 patients.
The “fewer than 50” tier is the one that carries the identifying information, and small numbers have consequences under the federal breach rules. HHS requires notice to affected individuals without unreasonable delay and no later than 60 days from discovery; breaches touching 500 or more residents of a single state additionally trigger prominent media notice and near-immediate reporting to the Secretary. A group of fewer than 50, concentrated in the western United States, sits below that threshold. That does not reduce NovoCure’s obligation to notify those individuals. It does mean the loudest parts of the notification machinery may never engage, which is a good reason for the company to publish something patients can find without an EDGAR search.
Finally, the device sentence. This is the second implanted- or worn-device story in three days: Boston Scientific said on Saturday that implanted cardiac devices still worked while newly implanted units stopped transmitting to remote monitoring. In both cases the therapy was unaffected and the data path around it was not. NovoCure’s statement is narrower than it first reads: it says no access to treatment devices was obtained, and that all systems are functional. It does not address whether any patient-facing service that sits beside the device — logging, support, adherence tracking — was interrupted. For a device worn for long daily stretches and supported by usage documentation, that surrounding layer is not incidental.
What to do
Patients and clinicians: no action is indicated by the filing. NovoCure says devices were not reached and that it will notify affected individuals. If you are treated with an Optune system and want to confirm your status, the company’s patient support line is the route; there is no public lookup.
Investors and disclosure teams: watch for an 8-K/A. The company has told the market, in writing, what would produce one. Its absence over the coming weeks is itself information.
Everyone else: the transferable item is the drafting. If your disclosure committee has an incident-response playbook, the paragraph NovoCure wrote — not material today, here is the item we would use, here is the clock — is a template worth stealing, and it costs nothing to have on the shelf before you need it. The second transferable item is less comfortable: the intrusion reached the group “through a subsidiary.” Subsidiary environments are where consolidated identity, shared service accounts, and inherited network trust tend to be least examined, and they are named in a growing share of these filings.
Sourcing note
Written from NovoCure Limited’s Form 8-K, SEC accession number 0001645113-26-000065, filed September 1, 2026 and accepted at 7:00:43 a.m. ET, retrieved from EDGAR; all quoted language is transcribed from that filing. Product and corporate details are from novocure.com, checked the same morning, which carries no breach notice. EDGAR full-text search was used to identify 8-K filings mentioning a cybersecurity incident on August 31 and September 1, 2026.
Not established: the name of the subsidiary, the initial access vector, whether the intruder retained access after containment, whether a ransom demand was made, when patient notifications will go out, and whether the internal patient ID numbers can be mapped to individuals using anything else taken in the same intrusion. NovoCure has not published a statement outside the filing, and no attacker has publicly claimed the incident as of this writing; nothing here should be read as attribution. The description of the SEC staff’s 2024 position on Item 8.01 versus Item 1.05 is a characterization of published guidance, not a quotation from it.
