Ardent Health’s Friday 8-K removes two adjustments after talks with the SEC’s Division of Corporation Finance, and leaves untouched a cybersecurity line that has run $35.6 million net positive since the November 2023 attack.
What happened
Ardent Health, Inc. (NYSE: ARDT) filed a Form 8-K on Friday, September 4, 2026, under Item 8.01, Other Events, and Item 9.01. It is not an incident disclosure. It revises the non-GAAP financial measures in the company’s Form 10-K for the year ended December 31, 2025, filed March 16, 2026 — at the SEC’s prompting.
The filing removes two adjustments from Adjusted EBITDA and Adjusted EBITDAR: “the Company’s (i) change in accounting estimate related to the collectability of accounts receivable” and “(ii) New Mexico professional liability accrual.” Both were confined to the third quarter of 2025. Together they came to $97.7 million. Ardent states the reason in one sentence: “these revisions are being made in connection with the Company’s discussions with the staff of the Securities and Exchange Commission’s Division of Corporation Finance to no longer include these adjustments.”
The effect is large. Adjusted EBITDA for the year ended December 31, 2025 falls from $545.0 million to $447.3 million. Adjusted EBITDAR falls from $709.3 million to $611.6 million. The 2023 and 2024 figures are unchanged, 2026 results are unaffected, and the company is explicit that “the removal of these two adjustments has no impact on the Company’s GAAP consolidated financial statements, financial condition, results of operations or cash flows, which remain unchanged.” Nothing audited moved. What moved is the number analysts quote and, as the exhibit notes, the number some of Ardent’s landlords measure it against.
What did not get removed is the part worth reading. Exhibit 99.1 restates the Adjusted EBITDA definition in full, and it still excludes “Cybersecurity incident recoveries, net of incremental information technology and litigation costs.” The reconciliation carries that line across three years, in thousands of dollars:
- Year ended December 31, 2023: 8,495
- Year ended December 31, 2024: (21,477)
- Year ended December 31, 2025: (22,655)
Footnote (b) explains it: “Cybersecurity incident (recoveries) expenses, net represent insurance recovery proceeds, net of incremental information technology and litigation costs, related to a cybersecurity incident that impacted our operations and information technology systems in November 2023.”
The signs matter. In 2023 the line is a positive add-back — a net cost of $8.5 million, added back to net income. In 2024 and 2025 it is negative, a gain being removed from net income, because insurance proceeds that year exceeded the incremental IT and litigation spend. Across the three years the line nets to $35.6 million in Ardent’s favor. The quarterly column in the same exhibit shows the line at zero for the three months ended December 31, 2025, so the recoveries had run out by the end of last year.
The incident behind the line is public and old. Ardent detected it “on the morning of November 23, 2023,” took its network offline, “suspending all user access to its information technology applications,” and said in a statement dated November 27, 2023 that the event “has since been determined to be a ransomware attack.” The same statement said: “At this time, we cannot confirm the extent of any patient health or financial data that has been compromised.” Ardent was privately held at the time; it priced its initial public offering in July 2024. The exhibit describes a company operating 30 acute care hospitals, 12 of them leased from two real estate investment trusts.
Why it matters
Non-GAAP adjustments are where a company tells investors which of its costs do not count. Corp Fin reviews them, and this filing is a dated window into what that review will and will not tolerate — on a document that also carries one of the longest-running public accountings of a hospital ransomware attack anyone has filed.
Look at the direction of travel. The two adjustments the SEC discussions removed were expenses being added back: a change in estimate on receivables collectability and a liability accrual, both of which raised Adjusted EBITDA, both confined to a single quarter, together worth $97.7 million. Add-backs that flatter a metric are the category regulators have been skeptical of for a decade. The cybersecurity line in 2024 and 2025 runs the opposite way — it takes a gain out, and excluding a windfall is harder to object to than excluding a cost. That is not proof the staff blessed the cyber line; the filing does not say the staff reviewed it. But the carve-out survived a round of scrutiny that $97.7 million of other adjustments did not.
The second thing worth taking away is the timing shape. Cyber incident costs land immediately; insurance recoveries land one to three years later, after the claim is adjudicated. Ardent’s own numbers make the point cleanly: a net cost in the year of the attack, then two consecutive years of net recoveries roughly two and a half times that cost, then zero. Anyone who models the financial impact of a ransomware event from a single year’s disclosure — in either direction — will get the wrong answer, and the error flips sign depending on which year they happen to pick.
That leads directly to what the line is not. It is insurance proceeds minus incremental IT and litigation costs. It is not the cost of the attack. The revenue that did not arrive in the fourth quarter of 2023, the clinical disruption, and the permanent security spending that became ordinary-course rather than incremental are all outside it, and Ardent has not broken any of it out. A reader who sees a three-year net of positive $35.6 million and concludes the company came out ahead on a ransomware attack has misread the label. What the number actually measures is that the insurance worked.
The last point is about where the record lives. Ardent’s incident happened in November 2023, while the company was private and roughly three weeks before Item 1.05 of Form 8-K — the SEC’s material cybersecurity incident item — took effect for most registrants. There was no Item 1.05 filing because there could not have been one. So the durable, filed public record of this incident’s financial consequence is not an incident report at all. It is a footnote in a non-GAAP reconciliation, restated on a Friday nearly three years later, in a document whose stated purpose is something else. This site has spent much of its Breach coverage on the difference between Item 1.05 and Item 8.01. Here neither item is the point: the incident is disclosed, durably and specifically, by an accounting definition that has outlived the attack by thirty-four months.
What to do
If you are on the finance side: know whether your own non-GAAP definitions carry a cyber carve-out, which direction it points in each period presented, and how long you intend to keep it. A carve-out that flips from cost to recovery is the normal shape of an insured incident, not an anomaly — but it needs an explanation ready before an analyst asks why an adjustment reduced adjusted earnings. And note that Ardent’s exhibit says “financial covenants in certain of our lease agreements, including the Ventas Master Lease, use Adjusted EBITDAR as a measure of compliance.” A non-GAAP adjustment a regulator disallows is not cosmetic when a covenant is computed on it.
If you are on the security side: this line is the number your board eventually sees, and its accuracy depends on bookkeeping that starts on day one. Ardent can report incremental IT and litigation costs separately from ordinary spend because someone tagged them at the time. Incident cost tracking that begins after the recovery is over produces a number no one can defend to an auditor, and an insurance claim that is harder to substantiate.
If you are reading someone else’s filings: read the reconciliation, not the headline metric. A cyber line inside an Adjusted EBITDA definition tells you an incident happened, roughly what it cost, and whether the insurer paid — often in more usable detail than the incident disclosure itself.
Sourcing note
Checked: Ardent Health, Inc.’s Form 8-K filed September 4, 2026, accession number 0001628280-26-060735, CIK 0001756655, read directly from SEC EDGAR — both the primary document and Exhibit 99.1, which is the source for every dollar figure, the Adjusted EBITDA and Adjusted EBITDAR definitions, the three-year reconciliation table, and footnote (b). Ardent’s own statement of November 27, 2023 is the source for the detection date and the ransomware confirmation, and the company’s pricing and closing announcements for the July 2024 IPO.
Could not reach: EDGAR’s company-browse interface disallows automated fetching, so the filing was located through EDGAR full-text search and read from its archive path. Ardent’s 2025 Form 10-K as originally filed on March 16, 2026 was not retrieved; the pre-revision figures of $545.0 million and $709.3 million are taken from the 8-K’s own description of what it is changing.
Unresolved: The 8-K does not say whether the SEC staff reviewed the cybersecurity adjustment, or whether it was discussed and retained. It says only that the two named adjustments are being removed in connection with those discussions. Nothing here should be read as the staff endorsing the cyber carve-out. Ardent has not published a total cost for the November 2023 incident inclusive of lost revenue, and no figure for that appears in this filing. The company has not stated whether further insurance recoveries are expected; the line reads zero for the fourth quarter of 2025, which is consistent with the claim being closed but does not confirm it.
