Hospital Operator Nutex Health Tells SEC Data Was Exfiltrated in Cyberattack Across Its 28-Facility Network
Nasdaq-listed hospital and healthcare network operator Nutex Health disclosed in an SEC filing that unauthorized third parties breached its corporate server infrastructure and exfiltrated confidential data across its network of 28 medical facilities.
Overview
| Attribute | Detail |
|---|---|
| Target Organisation | Nutex Health Inc. (NASDAQ: NUTX) |
| Enterprise Scale | 28 hospital facilities across 12 US states; $875M reported 2025 revenue |
| Incident Type | Network intrusion and unauthorized data exfiltration |
| Status | Contained; forensic scope investigation ongoing |
| Attribution | Unclaimed; no threat group identified |
| Date | 2026-08-25 |
Disclosure Details & Incident Response
Nutex Health filed a Form 8-K disclosure stating that external threat actors accessed corporate systems and exfiltrated files containing confidential and private information.
Upon detecting unauthorized access, the organisation initiated incident response measures: - Retained external cybersecurity and forensic investigation firms. - Isolated impacted segments and contained the intrusion across its multi-state infrastructure. - Notified federal law enforcement agencies and regulatory oversight bodies.
As of 24 August 2026, the company reported no material operational disruption or financial impairment, though comprehensive analysis remains underway to determine the precise volume and categories of patient, employee, provider, or corporate records impacted.
Significance
Healthcare networks remain highly targeted due to the high sensitivity of protected health information (PHI) and the operational criticality of clinical services. SEC cyber disclosure rules continue to enforce transparency for publicly traded healthcare providers experiencing data exfiltration.