Item 1.05
AdaptHealth Corp.
Item 1.05 section not located in normalized markdown
**UNITED STATES** **SECURITIES AND EXCHANGE COMMISSION** **WASHINGTON, D.C. 20549** **FORM ****8-K** **CURRENT REPORT** **Pursuant to Section 13 OR 15(d)** **of The Securities Exchange Act of 1934** **Date of Report (Date of earliest event reported): ****June 27, 2026** **AdaptHealth Corp.** (Exact name of registrant as specified in its charter) (State or other jurisdiction of | | (Commission File Number) | | (IRS Employer Identification No.) | (Address of principal executive offices) | | (Zip Code) | (Registrant’s telephone number, including area code) | (Former name or former address, if changed since last report.) | Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions: ☐ Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425) ☐ Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12) ☐ Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b)) ☐ Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c)) Securities registered pursuant to Section 12(b) of the Act: Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§240.12b-2 of this chapter). Emerging growth company ☐ If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐ **Item 1.05 Material Cybersecurity Incidents.** AdaptHealth Corp. (the “Company”) is investigating a security incident whereby a threat actor gained unauthorized access to Company systems and exfiltrated certain data therefrom. Upon learning of the incident, the Company promptly activated its incident response procedures, launched the investigation with the support of external advisors and cybersecurity experts to assess and contain the threat and notified law enforcement. While the investigation is ongoing, the Company has been able to confirm certain facts about the incident, and on June 27, 2026, the Company determined that the incident is material, due to the nature and potential volume of the data that is at risk. Specifically, based on information obtained to date, the Company believes that a threat actor gained unauthorized access to certain of the Company’s cloud-based business applications, including certain internal patient management systems and document storage platforms. On June 15, 2026, the Company received a communication from a threat actor claiming to have obtained certain data from the Company’s systems. The Company has confirmed that certain data was exfiltrated from its systems including a stored password file associated with insurance billing; the Company also has confirmed that certain external electronic health record system portals were accessed by the threat actor. The data affected includes passwords associated with insurance billing and certain personally identifiable information and protected health information of patients. **The Company does not collect Social Security numbers in the affected systems and does not store individual financial account information or payment card information in those systems.** The incident was the result of a successful social engineering attack that compromised a user session associated with a third-party contractor. Following detection, the Company promptly implemented containment measures, including disabling the compromised user account, resetting affected credentials, and implementing additional access controls, and the incident has been contained. The Company is continuing to investigate the nature and scop
Market reaction
Issuer share price following the disclosure
Closing prices for AdaptHealth Corp.’s common stock (AHCO) around the filing date, set against the S&P 500 over the same period. The baseline is the last close preceding the filing date; percentage changes are computed on prices adjusted for splits and dividends.
| Offset | Close date | Close | Change from pre-filing close | S&P 500, same period |
|---|---|---|---|---|
| Pre-filing close (baseline) | 2026-07-01 | $10.60 | — | — |
| Filing date | 2026-07-02 | $10.76 | +1.5% | −0.1% |
| 1 day after filing | 2026-07-06 | $10.27 | −3.1% | +0.7% |
| 3 days after filing | 2026-07-06 | $10.27 | −3.1% | +0.7% |
| 14 days after filing | 2026-07-16 | $10.90 | +2.8% | +0.7% |
| 1 month after filing | 2026-08-03 | $10.83 | +2.2% | +1.6% |
| 3 months after filing | Not yet matured | |||
| 6 months after filing | Not yet matured | |||
Filings accepted by EDGAR after 5:30 p.m. Eastern are dated the following business day, so the filing date shown is generally the first session in which the market could respond. Offsets falling on non-trading days resolve to the next session. End-of-day price data provided by Tiingo.
Comparable filings
Structurally comparable filings in the corpus
Ranked by structural similarity over the extracted incident:v2 axes (attack source, data classes, materiality determinations, disclosure basis, records scale). Click any row to read that filing alongside its own extraction registry.
- Nutex Health Inc.NUTX8-K · Filed 2026-08-31 · Item 1.05 · +14.7% at 14 days · S&P 500 −1.1%unauthorized activity involving data stored on its computer networkOwn systemsPII + PHIOp deniedFin pending
- Park Dental Partners, Inc.PARK8-K · Filed 2026-09-01 · Item 1.05 · 9.01 · −0.1% at 14 days · S&P 500 −1.3%unauthorized access to computer networkOwn systemsPII + PHIOp denied
- Cencora, Inc.COR8-K/A · Filed 2024-07-31 · Item 1.05 · +3.1% at 14 days · S&P 500 +0.3%data exfiltration from information systemsOwn systemsPII + PHIOp denied
- DROPBOX, INC.DBX8-K · Filed 2024-05-01 · Item 1.05 · 7.01 · 9.01 · +3.0% at 14 days · S&P 500 +5.5%unauthorized access to Dropbox Sign production environmentOwn systemsPII + credentialsOp denied
- Nutex Health Inc.NUTX8-K · Filed 2026-08-24 · Item 8.01 · +2.6% at 14 days · S&P 500 0.0%unauthorized activity involving data stored on its computer networkOwn systemsPII + PHIOp denied