The 8-K was accepted at 4:05 p.m. ET on September 1, two business days after the company found unauthorized access on its network — and it went in under the one Form 8-K item the SEC’s own staff has told companies not to use when materiality has not been determined.
What happened
Park Dental Partners, Inc. (ticker PARK, CIK 0002069604) filed a Form 8-K on Tuesday, September 1, 2026, accepted by EDGAR at 4:05 p.m. ET — five minutes after the closing bell. The accession number is 0001104659-26-104300. The period of report is August 28, 2026. The filing carries two items: Item 1.05, “Material Cybersecurity Incidents,” and Item 9.01, whose sole exhibit is the cover page inline XBRL. It is signed by Christopher J. Bernander, chief financial officer.
The disclosure opens: “On August 28, 2026, Park Dental Partners, Inc. (‘we’ or the ‘Company’) identified unauthorized access to its computer network. The Company promptly initiated its incident response protocols, and engaged its external cybersecurity and forensic specialists. The Company is continuing to investigate the nature and scope of this incident, including the scope of any compromise of personal or protected health information.”
The same paragraph closes with the sentence that explains the item choice: “As of the date of this Current Report on Form 8-K, the incident has not materially disrupted the Company’s operations, however, due to the possible access of patient data, we are treating this as a reportable event.”
Two paragraphs later the filing states: “The Company is in the process of estimating any financial, legal, operational, and reputational impact of the incident. As of the date of this report, an estimate is not reasonably possible, however, the Company has not identified any material impact on its financial condition, results of operations, or business operations.”
It closes: “The investigation remains ongoing, and additional information may become available that could affect the Company’s assessment of the incident and its impact.”
The filing names no number of affected individuals, no systems, no locations, no threat actor, and no ransom demand. It does not say whether clinical or scheduling systems were reached, or how many of the company’s practices touch the affected network.
Scale, from Park’s own filed materials: in a press release filed to EDGAR as Exhibit 99.1, the company describes itself as “a dental resource organization that has put patients first since the establishment of its general dentistry group in 1972,” reporting 222 affiliated doctors across 87 practice locations in three states, supported by roughly 990 hygienists, dental assistants, and patient care coordinators.
The timeline in the filing is fast by the standards of this beat: identified Friday, August 28, filed Tuesday, September 1. August 31 was the only intervening business day.
Why it matters
Item 1.05 is not a general-purpose cybersecurity item. It is triggered by a determination that an incident is material, and its four-business-day clock runs from that determination rather than from discovery. Park’s filing does not make that determination. It says an estimate of impact “is not reasonably possible” and, in the same sentence, that the company “has not identified any material impact.”
The SEC’s staff addressed this directly. In a statement dated May 21, 2024, titled “Disclosure of Cybersecurity Incidents Determined To Be Material and Other Cybersecurity Incidents,” Erik Gerding, then director of the Division of Corporation Finance, wrote that “if a company chooses to disclose a cybersecurity incident for which it has not yet made a materiality determination, or a cybersecurity incident that the company determined was not material, the Division of Corporation Finance encourages the company to disclose that cybersecurity incident under a different item of Form 8-K (for example, Item 8.01).” The stated reason was that keeping Item 1.05 for material incidents lets investors “more easily distinguish between the two and make better investment and voting decisions.”
Park filed under 1.05 anyway. The company’s own explanation is in the text — “due to the possible access of patient data, we are treating this as a reportable event” — and that phrase is doing real work. Reportable is a health-privacy concept. A dental group that may have exposed protected health information has obligations under the HIPAA Breach Notification Rule and under state breach statutes, and those obligations attach regardless of whether the incident moves the stock. Materiality under the securities rules is a separate question with a separate test. The filing collapses the two, using the securities item reserved for one to satisfy an instinct that belongs to the other.
What makes this worth writing down is that it is the third distinct reading of the same rule this publication has seen this week. NovoCure filed under Item 8.01 on September 1 and wrote its own future 1.05 trigger into the text of the filing. Nutex Health filed under 8.01 and then moved the same disclosure to Item 1.05 seven days later, also while saying it had identified no material impact. Park went straight to 1.05 on day two and disclaimed material impact in the same breath. Three registrants, three procedures, one rule.
The direction of the error matters more than the error. Filing under 1.05 when materiality is undetermined is the conservative choice for a company and its counsel — nobody has ever been sued for disclosing too promptly under the wrong heading. But it is the expensive choice for everyone reading the wire, because the entire design of the two-item split is to make “the company has concluded this is material” a distinguishable signal. If 1.05 becomes the default heading for any incident involving regulated data, the item stops carrying information, and the only way to tell a material incident from a precautionary one is to read every filing in full. That is precisely the outcome the 2024 staff statement was written to prevent, and two years on, the drift is visible in a single week’s filings.
One paragraph in the filing deserves a careful read rather than a quotation. Park states that it “maintains a cybersecurity risk-management program designed to assess, identify, and manage material risks arising from cybersecurity threats, consistent with the standards reported by peer companies in the dental and medical industries, which commonly leverage the National Institute of Standards and Technology (‘NIST’) Cybersecurity Framework as a basis for security posture measurement and risk management.” That is not a claim that Park follows the NIST CSF. It is a claim that its program is consistent with what peer companies report about themselves, and that those peers commonly use the framework. The construction sits two removes from any assertion about Park’s own controls.
What to do
For patients and for employers whose plans route to Park practices, there is nothing actionable in this filing. It names no affected population and offers no notice. The document to watch is not the next 8-K but the U.S. Department of Health and Human Services Office for Civil Rights breach portal: if protected health information is confirmed and 500 or more individuals are affected, the incident must be reported there within 60 days of discovery, which would put the deadline in late October. State attorney general filings typically arrive on a similar or faster schedule.
For anyone tracking the filing itself: Item 1.05 requires an amendment on Form 8-K/A within four business days of the registrant obtaining information that was unavailable at the time of the original filing. Park has told the market its investigation is ongoing and that additional information “may become available that could affect the Company’s assessment.” An 8-K/A is the expected next document, and its item choice will say whether the company has since made a materiality determination or is standing on the original heading.
For filers and their counsel, the practical takeaway is narrow: if you have not determined materiality, the staff’s stated preference is Item 8.01, and using 1.05 as a precaution does not create a safe harbor — it creates a public record that says you determined an incident was material when your own text says you did not.
Sourcing note
Checked: EDGAR full-text search for Form 8-K filings carrying Item 1.05 between August 31 and September 2, 2026, which returned Park Dental Partners and Nutex Health; the filing index for accession 0001104659-26-104300, which gives the filing date of September 1, 2026, the period of report of August 28, 2026, and the EDGAR acceptance timestamp of 4:05 p.m. ET; and the filing document park-20260828x8k.htm itself, from which every quotation above is taken verbatim. Also checked: the SEC Division of Corporation Finance statement of May 21, 2024, quoted directly; and Park’s own Exhibit 99.1 press release for the practice, doctor, and staff counts.
Could not reach: Maine’s attorney general breach portal, which remains offline pending the office’s review of what it has described as an apparent abuse of its reporting system. No corresponding notice was found on the HHS Office for Civil Rights portal at the time of writing, which is expected this early.
Unresolved: how many individuals are affected; whether protected health information was in fact accessed rather than potentially accessed; which of the 87 practice locations sit on the affected network; and whether Park made a materiality determination before filing under an item that presupposes one. No attacker claim is associated with this incident in any source consulted, and nothing here should be read as attribution. Related coverage: Nutex Health’s move from Item 8.01 to Item 1.05 and NovoCure’s Item 8.01 filing with a self-written 1.05 undertaking.



