Novocure disclosed on September 1 that an intruder reached some of its information systems in mid-August. The company filed the incident under Item 8.01 of a Form 8-K, the other events line, rather than Item 1.05, which covers material cybersecurity incidents.

Internal patient ID numbers for more than 1,400 US patients were exposed with no names attached. Fewer than 50 patients in the western US had identifying information exposed. Provider contact details and employee job titles and phone numbers were also in the set. Novocure said it activated its cybersecurity response plan, contained the access and brought in outside forensic experts.

The company said no one reached its treatment devices, its systems stay fully functional, and it does not currently believe the incident will have a material financial effect. It committed to amending the filing within four business days if that assessment changes, and said it will notify affected patients as its findings require.

The choice of item number is the part to read closely. Filing under 8.01 says the company has not concluded the incident is material while still putting the facts on the record, and it starts a clock the company wrote for itself. The amendment, if one comes, is where the real scope shows up.