Severity Daily

IT and AI security incidents, checked against the primary source

Tag: materiality

  • The SEC made Ardent Health drop $97.7 million in non-GAAP add-backs. Its 2023 ransomware carve-out survived.

    The SEC made Ardent Health drop $97.7 million in non-GAAP add-backs. Its 2023 ransomware carve-out survived.

    Ardent Health’s Friday 8-K removes two adjustments after talks with the SEC’s Division of Corporation Finance, and leaves untouched a cybersecurity line that has run $35.6 million net positive since the November 2023 attack.

    What happened

    Ardent Health, Inc. (NYSE: ARDT) filed a Form 8-K on Friday, September 4, 2026, under Item 8.01, Other Events, and Item 9.01. It is not an incident disclosure. It revises the non-GAAP financial measures in the company’s Form 10-K for the year ended December 31, 2025, filed March 16, 2026 — at the SEC’s prompting.

    The filing removes two adjustments from Adjusted EBITDA and Adjusted EBITDAR: “the Company’s (i) change in accounting estimate related to the collectability of accounts receivable” and “(ii) New Mexico professional liability accrual.” Both were confined to the third quarter of 2025. Together they came to $97.7 million. Ardent states the reason in one sentence: “these revisions are being made in connection with the Company’s discussions with the staff of the Securities and Exchange Commission’s Division of Corporation Finance to no longer include these adjustments.”

    The effect is large. Adjusted EBITDA for the year ended December 31, 2025 falls from $545.0 million to $447.3 million. Adjusted EBITDAR falls from $709.3 million to $611.6 million. The 2023 and 2024 figures are unchanged, 2026 results are unaffected, and the company is explicit that “the removal of these two adjustments has no impact on the Company’s GAAP consolidated financial statements, financial condition, results of operations or cash flows, which remain unchanged.” Nothing audited moved. What moved is the number analysts quote and, as the exhibit notes, the number some of Ardent’s landlords measure it against.

    What did not get removed is the part worth reading. Exhibit 99.1 restates the Adjusted EBITDA definition in full, and it still excludes “Cybersecurity incident recoveries, net of incremental information technology and litigation costs.” The reconciliation carries that line across three years, in thousands of dollars:

    • Year ended December 31, 2023: 8,495
    • Year ended December 31, 2024: (21,477)
    • Year ended December 31, 2025: (22,655)

    Footnote (b) explains it: “Cybersecurity incident (recoveries) expenses, net represent insurance recovery proceeds, net of incremental information technology and litigation costs, related to a cybersecurity incident that impacted our operations and information technology systems in November 2023.”

    The signs matter. In 2023 the line is a positive add-back — a net cost of $8.5 million, added back to net income. In 2024 and 2025 it is negative, a gain being removed from net income, because insurance proceeds that year exceeded the incremental IT and litigation spend. Across the three years the line nets to $35.6 million in Ardent’s favor. The quarterly column in the same exhibit shows the line at zero for the three months ended December 31, 2025, so the recoveries had run out by the end of last year.

    The incident behind the line is public and old. Ardent detected it “on the morning of November 23, 2023,” took its network offline, “suspending all user access to its information technology applications,” and said in a statement dated November 27, 2023 that the event “has since been determined to be a ransomware attack.” The same statement said: “At this time, we cannot confirm the extent of any patient health or financial data that has been compromised.” Ardent was privately held at the time; it priced its initial public offering in July 2024. The exhibit describes a company operating 30 acute care hospitals, 12 of them leased from two real estate investment trusts.

    Why it matters

    Non-GAAP adjustments are where a company tells investors which of its costs do not count. Corp Fin reviews them, and this filing is a dated window into what that review will and will not tolerate — on a document that also carries one of the longest-running public accountings of a hospital ransomware attack anyone has filed.

    Look at the direction of travel. The two adjustments the SEC discussions removed were expenses being added back: a change in estimate on receivables collectability and a liability accrual, both of which raised Adjusted EBITDA, both confined to a single quarter, together worth $97.7 million. Add-backs that flatter a metric are the category regulators have been skeptical of for a decade. The cybersecurity line in 2024 and 2025 runs the opposite way — it takes a gain out, and excluding a windfall is harder to object to than excluding a cost. That is not proof the staff blessed the cyber line; the filing does not say the staff reviewed it. But the carve-out survived a round of scrutiny that $97.7 million of other adjustments did not.

    The second thing worth taking away is the timing shape. Cyber incident costs land immediately; insurance recoveries land one to three years later, after the claim is adjudicated. Ardent’s own numbers make the point cleanly: a net cost in the year of the attack, then two consecutive years of net recoveries roughly two and a half times that cost, then zero. Anyone who models the financial impact of a ransomware event from a single year’s disclosure — in either direction — will get the wrong answer, and the error flips sign depending on which year they happen to pick.

    That leads directly to what the line is not. It is insurance proceeds minus incremental IT and litigation costs. It is not the cost of the attack. The revenue that did not arrive in the fourth quarter of 2023, the clinical disruption, and the permanent security spending that became ordinary-course rather than incremental are all outside it, and Ardent has not broken any of it out. A reader who sees a three-year net of positive $35.6 million and concludes the company came out ahead on a ransomware attack has misread the label. What the number actually measures is that the insurance worked.

    The last point is about where the record lives. Ardent’s incident happened in November 2023, while the company was private and roughly three weeks before Item 1.05 of Form 8-K — the SEC’s material cybersecurity incident item — took effect for most registrants. There was no Item 1.05 filing because there could not have been one. So the durable, filed public record of this incident’s financial consequence is not an incident report at all. It is a footnote in a non-GAAP reconciliation, restated on a Friday nearly three years later, in a document whose stated purpose is something else. This site has spent much of its Breach coverage on the difference between Item 1.05 and Item 8.01. Here neither item is the point: the incident is disclosed, durably and specifically, by an accounting definition that has outlived the attack by thirty-four months.

    What to do

    If you are on the finance side: know whether your own non-GAAP definitions carry a cyber carve-out, which direction it points in each period presented, and how long you intend to keep it. A carve-out that flips from cost to recovery is the normal shape of an insured incident, not an anomaly — but it needs an explanation ready before an analyst asks why an adjustment reduced adjusted earnings. And note that Ardent’s exhibit says “financial covenants in certain of our lease agreements, including the Ventas Master Lease, use Adjusted EBITDAR as a measure of compliance.” A non-GAAP adjustment a regulator disallows is not cosmetic when a covenant is computed on it.

    If you are on the security side: this line is the number your board eventually sees, and its accuracy depends on bookkeeping that starts on day one. Ardent can report incremental IT and litigation costs separately from ordinary spend because someone tagged them at the time. Incident cost tracking that begins after the recovery is over produces a number no one can defend to an auditor, and an insurance claim that is harder to substantiate.

    If you are reading someone else’s filings: read the reconciliation, not the headline metric. A cyber line inside an Adjusted EBITDA definition tells you an incident happened, roughly what it cost, and whether the insurer paid — often in more usable detail than the incident disclosure itself.

    Sourcing note

    Checked: Ardent Health, Inc.’s Form 8-K filed September 4, 2026, accession number 0001628280-26-060735, CIK 0001756655, read directly from SEC EDGAR — both the primary document and Exhibit 99.1, which is the source for every dollar figure, the Adjusted EBITDA and Adjusted EBITDAR definitions, the three-year reconciliation table, and footnote (b). Ardent’s own statement of November 27, 2023 is the source for the detection date and the ransomware confirmation, and the company’s pricing and closing announcements for the July 2024 IPO.

    Could not reach: EDGAR’s company-browse interface disallows automated fetching, so the filing was located through EDGAR full-text search and read from its archive path. Ardent’s 2025 Form 10-K as originally filed on March 16, 2026 was not retrieved; the pre-revision figures of $545.0 million and $709.3 million are taken from the 8-K’s own description of what it is changing.

    Unresolved: The 8-K does not say whether the SEC staff reviewed the cybersecurity adjustment, or whether it was discussed and retained. It says only that the two named adjustments are being removed in connection with those discussions. Nothing here should be read as the staff endorsing the cyber carve-out. Ardent has not published a total cost for the November 2023 incident inclusive of lost revenue, and no figure for that appears in this filing. The company has not stated whether further insurance recoveries are expected; the line reads zero for the fourth quarter of 2025, which is consistent with the claim being closed but does not confirm it.

  • Park Dental Partners filed its breach under the SEC item reserved for material incidents, then said it has found no material impact

    Park Dental Partners filed its breach under the SEC item reserved for material incidents, then said it has found no material impact

    The 8-K was accepted at 4:05 p.m. ET on September 1, two business days after the company found unauthorized access on its network — and it went in under the one Form 8-K item the SEC’s own staff has told companies not to use when materiality has not been determined.

    What happened

    Park Dental Partners, Inc. (ticker PARK, CIK 0002069604) filed a Form 8-K on Tuesday, September 1, 2026, accepted by EDGAR at 4:05 p.m. ET — five minutes after the closing bell. The accession number is 0001104659-26-104300. The period of report is August 28, 2026. The filing carries two items: Item 1.05, “Material Cybersecurity Incidents,” and Item 9.01, whose sole exhibit is the cover page inline XBRL. It is signed by Christopher J. Bernander, chief financial officer.

    The disclosure opens: “On August 28, 2026, Park Dental Partners, Inc. (‘we’ or the ‘Company’) identified unauthorized access to its computer network. The Company promptly initiated its incident response protocols, and engaged its external cybersecurity and forensic specialists. The Company is continuing to investigate the nature and scope of this incident, including the scope of any compromise of personal or protected health information.”

    The same paragraph closes with the sentence that explains the item choice: “As of the date of this Current Report on Form 8-K, the incident has not materially disrupted the Company’s operations, however, due to the possible access of patient data, we are treating this as a reportable event.”

    Two paragraphs later the filing states: “The Company is in the process of estimating any financial, legal, operational, and reputational impact of the incident. As of the date of this report, an estimate is not reasonably possible, however, the Company has not identified any material impact on its financial condition, results of operations, or business operations.”

    It closes: “The investigation remains ongoing, and additional information may become available that could affect the Company’s assessment of the incident and its impact.”

    The filing names no number of affected individuals, no systems, no locations, no threat actor, and no ransom demand. It does not say whether clinical or scheduling systems were reached, or how many of the company’s practices touch the affected network.

    Scale, from Park’s own filed materials: in a press release filed to EDGAR as Exhibit 99.1, the company describes itself as “a dental resource organization that has put patients first since the establishment of its general dentistry group in 1972,” reporting 222 affiliated doctors across 87 practice locations in three states, supported by roughly 990 hygienists, dental assistants, and patient care coordinators.

    The timeline in the filing is fast by the standards of this beat: identified Friday, August 28, filed Tuesday, September 1. August 31 was the only intervening business day.

    Why it matters

    Item 1.05 is not a general-purpose cybersecurity item. It is triggered by a determination that an incident is material, and its four-business-day clock runs from that determination rather than from discovery. Park’s filing does not make that determination. It says an estimate of impact “is not reasonably possible” and, in the same sentence, that the company “has not identified any material impact.”

    The SEC’s staff addressed this directly. In a statement dated May 21, 2024, titled “Disclosure of Cybersecurity Incidents Determined To Be Material and Other Cybersecurity Incidents,” Erik Gerding, then director of the Division of Corporation Finance, wrote that “if a company chooses to disclose a cybersecurity incident for which it has not yet made a materiality determination, or a cybersecurity incident that the company determined was not material, the Division of Corporation Finance encourages the company to disclose that cybersecurity incident under a different item of Form 8-K (for example, Item 8.01).” The stated reason was that keeping Item 1.05 for material incidents lets investors “more easily distinguish between the two and make better investment and voting decisions.”

    Park filed under 1.05 anyway. The company’s own explanation is in the text — “due to the possible access of patient data, we are treating this as a reportable event” — and that phrase is doing real work. Reportable is a health-privacy concept. A dental group that may have exposed protected health information has obligations under the HIPAA Breach Notification Rule and under state breach statutes, and those obligations attach regardless of whether the incident moves the stock. Materiality under the securities rules is a separate question with a separate test. The filing collapses the two, using the securities item reserved for one to satisfy an instinct that belongs to the other.

    What makes this worth writing down is that it is the third distinct reading of the same rule this publication has seen this week. NovoCure filed under Item 8.01 on September 1 and wrote its own future 1.05 trigger into the text of the filing. Nutex Health filed under 8.01 and then moved the same disclosure to Item 1.05 seven days later, also while saying it had identified no material impact. Park went straight to 1.05 on day two and disclaimed material impact in the same breath. Three registrants, three procedures, one rule.

    The direction of the error matters more than the error. Filing under 1.05 when materiality is undetermined is the conservative choice for a company and its counsel — nobody has ever been sued for disclosing too promptly under the wrong heading. But it is the expensive choice for everyone reading the wire, because the entire design of the two-item split is to make “the company has concluded this is material” a distinguishable signal. If 1.05 becomes the default heading for any incident involving regulated data, the item stops carrying information, and the only way to tell a material incident from a precautionary one is to read every filing in full. That is precisely the outcome the 2024 staff statement was written to prevent, and two years on, the drift is visible in a single week’s filings.

    One paragraph in the filing deserves a careful read rather than a quotation. Park states that it “maintains a cybersecurity risk-management program designed to assess, identify, and manage material risks arising from cybersecurity threats, consistent with the standards reported by peer companies in the dental and medical industries, which commonly leverage the National Institute of Standards and Technology (‘NIST’) Cybersecurity Framework as a basis for security posture measurement and risk management.” That is not a claim that Park follows the NIST CSF. It is a claim that its program is consistent with what peer companies report about themselves, and that those peers commonly use the framework. The construction sits two removes from any assertion about Park’s own controls.

    What to do

    For patients and for employers whose plans route to Park practices, there is nothing actionable in this filing. It names no affected population and offers no notice. The document to watch is not the next 8-K but the U.S. Department of Health and Human Services Office for Civil Rights breach portal: if protected health information is confirmed and 500 or more individuals are affected, the incident must be reported there within 60 days of discovery, which would put the deadline in late October. State attorney general filings typically arrive on a similar or faster schedule.

    For anyone tracking the filing itself: Item 1.05 requires an amendment on Form 8-K/A within four business days of the registrant obtaining information that was unavailable at the time of the original filing. Park has told the market its investigation is ongoing and that additional information “may become available that could affect the Company’s assessment.” An 8-K/A is the expected next document, and its item choice will say whether the company has since made a materiality determination or is standing on the original heading.

    For filers and their counsel, the practical takeaway is narrow: if you have not determined materiality, the staff’s stated preference is Item 8.01, and using 1.05 as a precaution does not create a safe harbor — it creates a public record that says you determined an incident was material when your own text says you did not.

    Sourcing note

    Checked: EDGAR full-text search for Form 8-K filings carrying Item 1.05 between August 31 and September 2, 2026, which returned Park Dental Partners and Nutex Health; the filing index for accession 0001104659-26-104300, which gives the filing date of September 1, 2026, the period of report of August 28, 2026, and the EDGAR acceptance timestamp of 4:05 p.m. ET; and the filing document park-20260828x8k.htm itself, from which every quotation above is taken verbatim. Also checked: the SEC Division of Corporation Finance statement of May 21, 2024, quoted directly; and Park’s own Exhibit 99.1 press release for the practice, doctor, and staff counts.

    Could not reach: Maine’s attorney general breach portal, which remains offline pending the office’s review of what it has described as an apparent abuse of its reporting system. No corresponding notice was found on the HHS Office for Civil Rights portal at the time of writing, which is expected this early.

    Unresolved: how many individuals are affected; whether protected health information was in fact accessed rather than potentially accessed; which of the 87 practice locations sit on the affected network; and whether Park made a materiality determination before filing under an item that presupposes one. No attacker claim is associated with this incident in any source consulted, and nothing here should be read as attribution. Related coverage: Nutex Health’s move from Item 8.01 to Item 1.05 and NovoCure’s Item 8.01 filing with a self-written 1.05 undertaking.