Item 8.01 Other Events.
DocGo Inc. (the “Company”) recently identified a cybersecurity incident involving certain of the Company’s systems.¹,² Promptly after detecting unauthorized activity, the Company took steps to contain and respond to the incident³, including launching an investigation, with assistance from leading third-party cybersecurity experts, and notifying relevant law enforcement⁴.
As part of its investigation, the Company has determined that the threat actor accessed and acquired data, including certain protected health information, from a limited number of healthcare records⁵,⁶ within the Company’s U.S.-based ambulance transportation business, and that no other business lines have been involved. In addition, although the investigation is ongoing, as of the date of this Current Report on Form 8-K (this “Report”), the Company has found no evidence of continued unauthorized activity on its systems and has contained the incident⁷. The Company has started the process of providing notifications as required by applicable law.
To date, the cybersecurity incident has not had a material impact on the Company’s operations, and the Company currently does not expect that the cybersecurity incident will have a material impact on its overall financial condition or on its ongoing results of operations⁸,⁹,¹⁰.
Cautionary Note Regarding Forward-Looking Statements
This Report may contain forward-looking statements (including within the meaning of Section 21E of the Securities Exchange Act of 1934, as amended, and Section 27A of the Securities Act of 1933, as amended) concerning the Company. All statements other than statements of historical fact are forward-looking, including, but not limited, to statements regarding the impact from the cybersecurity incident, the scope of the investigation and the Company’s possible or assumed future actions, business strategies, plans and goals. These statements may be identified by words such as “may”, “will”, “expect”, “intend”, “plan”, “potential”, “believe”, “seek”, “could”, “estimate”, “judgment”, “targeting”, “should”, “anticipate”, “predict” “project”, “aim”, “goal”, “outlook”, “guidance”, and similar words, phrases or expressions. These forward-looking statements are based on management’s current expectations and beliefs, as well as assumptions made by, and information currently available to, management, and current market trends and conditions. Forward-looking statements inherently involve risks and uncertainties, many of which are beyond the Company’s control, and which may cause actual results to differ materially from those contained in the Company’s forward-looking statements. Accordingly, you should not place undue reliance on such statements. Potential risks and uncertainties that could cause the actual results of the Company’s operations or financial condition to differ materially from those expressed or implied by forward-looking statements include, but are not limited to: the Company’s ongoing assessment of the impacts of the cybersecurity incident; the Company’s ongoing assessment and investigation of the incident, including the Company’s potential discovery of additional information related to the incident in connection with its investigation or otherwise; the impact of the cybersecurity incident on the Company’s relationships with customers, partners, employees and regulators; legal, reputational and financial risks resulting from the cybersecurity incident; the extent of available insurance coverage; any regulatory inquiries and/or litigation filed in connection with this incident and associated costs; the Company’s ability to service its customers following the issue and any change in customer behavior as a result of the issue; the scope of personal information that was accessed or obtained by the unauthorized third party and the negative consequences of the illegal or improper use of such information by the unauthorized third party, such as fines, penalties, or loss of reputation, competitiveness or customers; and that any future, or still undetected, cybersecurity related incident, whether an attack, disruption, intrusion, denial of service, theft or other breach could result in unauthorized access to, or disclosure of, data, resulting in claims, costs and reputational harm that could negatively affect our actual results of operations or financial condition; and other risks detailed in the “Risk Factors” section of the Company’s Annual Report on Form 10-K for the year ended December 31, 2023 and Quarterly Reports on Form 10-Q as well as any subsequent filings with the Securities and Exchange Commission, including Forms 8-K filed or furnished with the SEC. The forward-looking statements in this document speak only as of the date of this Report. The Company undertakes no intent or obligation to publicly update or revise any of these forward-looking statements, whether as a result of new information, future events or otherwise.