CSIDB logo
Incident

Nutex Health Inc.

Incident posture

Attack window
Aug 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-26 18:47

Linked entities

Victim
Nutex Health Inc.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending

Summary

Nutex Health Inc. disclosed a data breach after learning of unauthorized activity on its computer network, stating that an unknown party accessed and exfiltrated data that may be private or confidential. The company filed the incident under SEC Form 8‑K Item 8.01, indicating it does not currently view the breach as material, though it has engaged forensic experts, contained the activity, and notified law enforcement. Nutex operates micro‑hospitals and emergency departments in multiple states and is still determining whether patient, employee, or business information was compromised. It says it will make any required notifications once the investigation concludes and will continue to assess applicable legal and regulatory obligations.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Nutex Health Inc. disclosed a data breach last week and filed a Form 8‑K with the Securities and Exchange Commission on August 24 2026, reporting the incident under Item 8.01 (“Other Events”) rather than Item 1.05 (“Material Cybersecurity Incidents”). The filing, signed by Chief Financial Officer Jon C. Bates, stated that the company recently learned of unauthorized activity involving data stored on its computer network, engaged an independent third‑party cybersecurity response team and forensic experts, activated its internal cybersecurity response plan, implemented containment measures, and notified law enforcement. Based on preliminary findings, Nutex said an unauthorized party accessed its servers and exfiltrated data, including information that “may be private and/or confidential,” but the company had not yet determined whether the stolen records included patient, employee, provider, business, financial, or intellectual property information. The filing did not disclose the attack vector, the volume of data taken, which facilities were affected, how long the intruders had access, or whether any ransom demand had been made, and no known ransomware group had claimed responsibility for the attack as of August 26 2026. SecurityWeek observed that the disclosure signaled possible extortion leverage, noting that the filing suggested the attacker might attempt to publicly release the stolen data without a formal ransom claim.

Nutex characterized the incident as not material under the SEC’s cybersecurity disclosure rules, explaining that it chose Item 8.01 because it did not believe the unauthorized access had, or was reasonably likely to have, a material impact on the company’s business strategy, operations, financial condition, or results of operations. The company said it continues to evaluate applicable regulatory and legal notification requirements and will make any required notifications based on the investigation’s findings. If the investigation confirms that unsecured protected health information was compromised, HIPAA’s Breach Notification Rule would require individual notification within 60 days of discovery; Nutex placed the discovery date in August 2026, meaning notifications could be required as soon as late October should PHI be confirmed. The HHS Office for Civil Rights is mandated to investigate all HIPAA breaches affecting 500 or more individuals, and a breach spanning Nutex’s 28 facilities in 12 states could trigger such review. Should the ongoing investigation reveal that the scope, sensitivity of the data, risk of regulatory enforcement, or reputational consequences rise to the materiality threshold, Nutex would be obligated to file an Item 1.05 Form 8‑K within four business days of that determination. As of August 25 2026, a national class‑action law firm had publicly announced an investigation into potential legal claims on behalf of affected individuals.

Nutex Health operates 28 micro‑hospitals and emergency‑department facilities across 12 U.S. states, including Texas, Wisconsin, and Arkansas, and reported $875 million in revenue for 2025. The breach occurs amid a record wave of healthcare sector incidents, with 772 large healthcare data breaches reported in the United States in 2025 and 2026 on pace to exceed that number. Healthcare remains the most costly industry for data breaches, averaging $7.42 million per incident in 2025, and breaches in the sector take an average of 279 days to identify and contain. Hacking accounts for over 80 percent of large healthcare data breaches, up from 49 percent in 2019, driven by centralized electronic health record infrastructures. The benchmark event in U.S. healthcare cybersecurity remains the February 2024 Change Healthcare ransomware attack, which the HHS confirmed affected approximately 192.7 million individuals. Regulatory developments include a January 2025 HHS Notice of Proposed Rulemaking that would make multi‑factor authentication, network segmentation, encryption of data at rest and in transit, and annual penetration testing mandatory; as of August 2026 the final rule had not been issued. Under SEC Chair Paul Atkins, who took office in April 2025, the commission has pursued a broadly deregulatory agenda, limiting enforcement focus on cybersecurity disclosures, with the most prominent prior action being the Flagstar Bancorp settlement in December 2024.

Sources

Sources available to members: 1 source.

CSIDB