Nutex Health has disclosed a cybersecurity incident involving unauthorized activity on its computer network, with preliminary findings indicating that an unknown third party accessed and exfiltrated information stored on company servers.
The Houston, Texas-based healthcare company revealed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission dated August 24, 2026.
Nutex Health said it recently became aware of suspicious activity affecting data maintained within its network environment. The company has launched an investigation with support from an independent third-party incident response team and forensic experts.
It also activated its cybersecurity response plan, deployed containment measures, and notified law enforcement authorities. According to the filing, the unauthorized party accessed and removed certain data from Nutex Health servers.
The company said the affected information may include private or confidential records. However, the full scope of the data exposure has not yet been determined.
Nutex Health is assessing whether patient information, employee records, credentialed provider data, confidential business information, financial data, intellectual property, or other sensitive records were accessed, acquired, or exfiltrated during the intrusion.
The disclosure does not identify the initial access vector, the date of intrusion, the threat actor, malware used, or whether the incident involved ransomware.
The company also did not confirm the volume of data allegedly taken from its systems or whether stolen information has been published, sold, or otherwise misused.
At the time of the filing, Nutex Health said it had not identified a material impact on its business operations or financial reporting systems.
The organization further stated that it does not currently believe the incident has had, or is reasonably likely to have, a material impact on its business strategy, operational performance, financial condition, or results of operations. However, the investigation remains ongoing, and the assessment could change as forensic analysis develops.
Healthcare-sector breaches can create significant exposure because affected environments may hold protected health information, personally identifiable information, employment records, provider credentials, billing data, and internal business documents.
Nutex Health said it is evaluating its legal and regulatory notification obligations. If the investigation determines that patient information was involved, the company intends to issue required notifications to impacted individuals and other relevant parties.
The filing also warns that the incident may result in legal, financial, operational, reputational, and regulatory risks. These could include data disclosure, fraudulent use of stolen information, loss or destruction of company data, regulatory scrutiny, litigation, remediation expenses, and disruption caused by management’s diversion of attention to incident response.
Organizations handling healthcare data remain attractive targets for financially motivated threat actors because medical and business records can be monetized through identity fraud, extortion, phishing, and resale on criminal marketplaces.
The Nutex Health incident highlights the importance of rapid containment, forensic evidence preservation, privileged-access monitoring, network segmentation, and timely notification procedures following suspected data exfiltration.
Nutex Health has not yet disclosed whether it will provide additional technical details, indicators of compromise, or a final count of the number of impacted individuals.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…