The quiet filing: what a medical device marketing agency reads in a breach disclosure
NovoCure just became the eleventh medtech manufacturer this year to tell the SEC about a cyberattack, and its choice of words is the real story. For any medical device marketing agency guiding a client through the same moment, that wording is the whole campaign.
By Katie Delaney · 2026-09-04 · 12 min read
NovoCure’s filing is the industry’s eleventh this year#
A fox does not need to be caught in the open to be noticed; one paw print pressed into wet undergrowth tells the whole story. NovoCure Ltd left exactly that kind of print on 1 September 2026, filing a Form 8-K that disclosed a cyberattack discovered in mid-August, through a subsidiary. The scope, as the chart above shows, was narrow rather than nothing: internal patient ID numbers for more than 1,400 US records, and fewer than 50 patients in the western United States whose fuller identifying information was also exposed, alongside some healthcare-provider and employee contact details.
NovoCure is not the outlier here, it is the pattern completing itself. MedTech Dive's own trend reporting counts NovoCure as the eleventh named medtech manufacturer to disclose a cyberattack in 2026, after Stryker, Medtronic, Intuitive Surgical, Abbott, iRhythm, AdaptHealth, Cook Medical, Baylor Genetics, UFP Technologies and Boston Scientific. “There were few instances in the industry over the past several years,” the same reporting notes; 2026 broke that quiet run wide open.
Eleven names, one season#
Read that list the way you would read fox tracks along a hedgerow: not eleven separate stories, but one trail. A single breach disclosure is a headline. Eleven in one year is a season, and a medical device marketing agency that treats each filing as an isolated crisis rather than a recurring cost of doing business is already behind the story its own client is living.
None of this required a whistleblower or a leak. NovoCure told the story about itself, on its own form, in its own words, because that is what the rule requires once a subsidiary discovers something worth reporting. The quiet, procedural nature of the disclosure is precisely why it matters to marketing and comms teams: nothing about a routine 8-K forces a headline, but nothing stops one either, and the gap between those two facts is where reputational risk actually lives.
NovoCure becomes aware of unauthorised access to some of its information systems, through a subsidiary, per its own Form 8-K.
The company files under Items 8.01 and 9.01, not Item 1.05, the item reserved for incidents already determined material, per SEC staff guidance.
MedTech Dive reports the disclosure independently, the moment a medtech marketing team's own comms plan gets tested by someone else's headline.
NovoCure has committed to amend the filing within four business days of any materiality determination, the same clock SEC guidance sets for every registrant.
What a medical device marketing agency should read into ‘not material’#
folkfox does not sell to patients. Our clients are the medical device marketing agency's own client, the manufacturer, and the brand teams and comms leads who answer to a regulator, a clinician and an investor on the same afternoon. So the interesting sentence in NovoCure's filing is not the breach description, it is the materiality line: “At this time, we do not believe that this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations,” the company writes. That is not evasive. It is precise, and precision is the entire craft of a medical device marketing agency's job during a breach.

The company also states plainly that “no access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional,” per the same filing. Two sentences, one careful and one confident, sitting side by side. That pairing is the actual template: acknowledge scope honestly, then state operational reality plainly, without letting either sentence borrow drama from the other.
Vague, defensive, unreadable as evidence
We take security extremely seriously and are committed to protecting the data entrusted to us by our valued partners and patients.
Specific, sourced, self-contained
Unauthorised access affected internal patient ID numbers for over 1,400 US records; fewer than 50 patients had further identifying data exposed, and no treatment device was accessed.
The second version is duller. It is also the one a journalist can quote without ringing the legal team first, and the one an investor can weigh without translating it. SEC staff have been explicit that Item 1.05 of Form 8-K is reserved for incidents already determined material, precisely so investors “more easily distinguish between the two and make better investment and voting decisions.” NovoCure filed under Item 8.01 instead, the item for events not yet material, which is why “not material yet” is not a dodge. It is the correct box on the correct form.
The legal standard behind all of this is not exotic. Information is material under the SEC's own compliance guide, if there is a substantial likelihood a reasonable shareholder would consider it important, a bar that has nothing to do with how the incident feels and everything to do with what a reasonable shareholder would want to know before making a decision. A medical device marketing agency's job is to help a client write a public account of an incident that would survive being read against that exact test.
Why the wording is the whole campaign#
Say too little and the silence itself becomes the story a trade desk writes for you. Say too much and a plaintiff's lawyer gets a gift, quoted back at the company in whatever comes next. A medical device marketing agency earns its fee in that narrow gap: matching every public sentence, press line, website update, sales deck, to the filing's own careful register, so nobody outside the legal team ever has to guess which version of events is the true one.
Building a medical device marketing strategy that survives a breach#
Healthcare data breaches cost an average of $6.64 million in 2026, the thirteenth consecutive year the sector has topped every other industry on cost, per IBM's own benchmark study. A medical device marketing strategy that treats cybersecurity as an IT footnote is budgeting against last decade's risk, not this one's.
Materiality is a legal test. Trust is a marketing one, and it fails on a shorter clock.
The same research found the average breach now takes 247 days to identify and contain, reversing five straight years of improvement, Help Net Security's read of the report notes. Eight months of undiscovered exposure is eight months where a medical device marketing strategy has no facts to work with, and a competitor has every headline it needs.
Put the clock on the wall#
folkfox tells every medtech marketing client the same thing: know your clocks before you need them. The SEC gives four business days from a materiality determination to an amended filing. Where protected health information is involved, HHS gives 60 days from discovery to notify affected individuals and, above 500 records, the media. Two different clocks, two different audiences, and one comms team that has to speak to both without contradicting itself.
A medical device marketing agency that keeps both clocks on the same wall, in the same shared document, stops discovering the second deadline the week the first one lands. That is the whole of the strategy, honestly: not cleverness, just a calendar nobody has to hunt for.
None of this needs a bigger budget, it needs an earlier invitation. Bring the medical device marketing agency into the incident-response plan before the incident, not after the filing, and the first public sentence the world reads will already have been drafted, reviewed and approved days before anyone needed it.
The medical device cybersecurity baseline FDA already expects#
None of this starts with the breach. FDA's own premarket guidance, updated February 2026, already asks manufacturers to document a Secure Product Development Framework, a Security Risk Management Report and a software bill of materials before a device reaches market, so that medical device cybersecurity is a design condition, not an afterthought bolted on once a subsidiary gets breached.
“Manufacturers are responsible for remaining vigilant about identifying risks and hazards associated with their medical devices, including risks related to cybersecurity,” FDA states plainly on its own guidance for the sector. That sentence belongs pinned above every brand brief a medical device marketing agency writes, because a claim of safety that skips cybersecurity is a claim the regulator has already flagged as incomplete.
In plain terms, that means a documented design process that treats security as a requirement rather than a patch, a written account of what could go wrong and how the device resists it, and a full inventory of every software component inside the device, so that when a vulnerability surfaces anywhere in that inventory, the manufacturer already knows every product it touches. None of the three is a marketing document, but all three are the facts a medical device marketing agency should be reading before it writes a single safety claim.
The one-in-three problem#
NovoCure's “not material, for now” is not a lonely sentence. Among the Form 8-K cybersecurity filings tracked in the rule's first year, roughly a third landed on exactly that determination, immaterial, at least at the point of filing, one legal analysis of the first year of filings found. The chart below shows the full split.
Measuring trust once the filing goes quiet#
This is the number a medical device marketing agency should actually track, not the breach count. ‘Not material’ is the industry's default reading of itself right now, and a brand that treats its own immaterial determination as embarrassing, hiding the filing rather than explaining it, is out of step with how a third of its own sector is behaving. The vixen does not apologise for the den, she simply keeps it dry.
folkfox has watched this exact tension play out before, just from the other side of the privacy fence: The pixel is now the liability and the pixel promised discretion, the FTC read the payload both trace what happens when a healthcare brand's tracking choices say one thing while its privacy policy says another. Any best healthcare marketing agency now has six pixel laws to check, and disclosure language is fast becoming a seventh. Even a pharmaceutical marketing story about six sellers and one lawsuit makes the same point from a different shelf: the copy has to survive the discovery request, not just the campaign brief.
None of this is about winning a news cycle. It is about making sure that, six months from now, when a regulator, a journalist or a rival names NovoCure alongside Stryker and Medtronic in the same retrospective, the record shows a company that spoke once, carefully, and stood by it.
One sentence to defend to the board#
Pick a single line and be ready to say it out loud in front of a board that is nervous about the wrong thing. Something like: our disclosure matched our filing, word for word, everywhere we said it. That is a sentence a brand strategy team can build a whole quarter around, and it is the discipline behind folkfox's content marketing work for regulated clients: write once, mean it everywhere, and never let the marketing page contradict the filing.
The fox that survives the season is not the one who was never seen, it is the one whose tracks always led somewhere sensible. NovoCure's quiet filing does exactly that job. The next filing, from whichever manufacturer is next, deserves the same discipline: a medical device marketing agency that reads its own client's regulatory language before it writes a single word of the client's marketing copy.
Frequently asked questions#
What does a medical device marketing agency actually do during a breach disclosure?
It does not write the SEC filing itself. It makes sure every other public sentence, the press statement, the website update, the sales deck, matches the filing's own materiality language exactly, so a clinician or investor never reads two different versions of the same event from the same company.
How is medtech marketing different once a cybersecurity incident is disclosed?
The audience widens overnight to include regulators, investors and trade press who read filings for a living. During that window, medtech marketing means matching tone to the regulatory register, not softening it, because softened language reads as evasive next to a precise legal document.
Should breach risk be part of a medical device marketing strategy before an incident happens?
Yes. A medical device marketing strategy that only reacts once a filing exists is always a step behind. Pre-approved language for materiality statements, one shared timeline, and a named owner for comms during the SEC's four-business-day amendment window all belong in the plan already.
What does FDA guidance on medical device cybersecurity actually require?
FDA's premarket guidance, updated February 2026, expects manufacturers to submit a Secure Product Development Framework, a Security Risk Management Report and a software bill of materials before a device reaches market, treating medical device cybersecurity as a design requirement rather than an incident-response afterthought.
What makes the best medical device marketing agency for a breach response?
One that reads the regulatory filing before writing a single word of public messaging, keeps every disclosure clock (SEC, HIPAA, state law) in one shared document, and never lets a marketing page say something braver than the company's own SEC filing says.
How many medtech companies have disclosed a cyberattack in 2026?
NovoCure is the eleventh named medical device manufacturer to disclose a cyberattack in 2026, following Stryker, Medtronic, Intuitive Surgical, Abbott, iRhythm, AdaptHealth, Cook Medical, Baylor Genetics, UFP Technologies and Boston Scientific, according to MedTech Dive's own tracking.
Read more on this topic#
The pixel is now the liability
What a tracking pixel actually promises, and what it doesn't.
Read the pieceThe pixel promised discretion. The FTC read the payload
One lawsuit, and the gap between a privacy policy and the code.
Read the pieceAny Best Healthcare Marketing Agency Now Has Six Pixel Laws to Check
Six laws, one checklist, before the next campaign ships.
Read the pieceSix Sellers, One Lawsuit
What a black-market supply chain does to a pharma brand's copy.
Read the pieceNeed a steadier line for the next filing?
folkfox writes the marketing and comms layer that sits beside a medical device marketing agency's own regulatory language, so the brand says the same true thing everywhere at once.