Skip to main content
Emerging ThreatsData Breaches

Nutex Health Probes Data Breach After Servers Exfiltrated

Hospital corridor with server room door ajar, employees in blurred background.

“Based on preliminary findings from the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including some information that may be private and/or confidential,” Nutex disclosed in an SEC filing.

Nutex Health’s public disclosure and corporate profile

The incident was revealed in a filing with the U.S. Securities and Exchange Commission, where Nutex described an unauthorized third party gaining access to company servers and exfiltrating information. Nutex Health operates 28 facilities across 12 states, including the Bayou City ER & Hospital in Texas and Green Bay ER & Hospital in Wisconsin. The company reported annual revenue of $875 million in 2025, a market capitalization of $1.28 billion, and is publicly traded as NUTX on the Nasdaq Capital Market.

What Nutex says may have been taken — and what remains unknown

In its filing Nutex said its investigation is ongoing and that it has not yet determined the types of data accessed or the classes of people or organizations affected. The company is “assess[ing] whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated,” the filing reads. Nutex has not stated which, if any, of those categories were actually compromised.

Immediate response steps reported by the company

After detecting the intrusion, Nutex says it retained external incident-response and forensic specialists, activated its cybersecurity response plan, implemented containment measures, and notified law enforcement. Those measures are presented in the SEC filing as part of the company’s effort to investigate and limit the incident’s impact while determining what, if anything, was taken from its systems.

What this means for patients, credentialed providers, and business partners

  • Patients: Nutex’s statement specifically acknowledges the possibility that “patient” information could be among what was accessed, and the company is still assessing that potential. Patients linked to the company’s 28 facilities will be watching for any direct notifications and for details that clarify whether medical or personally identifiable information was involved.
  • Credentialed providers: The company explicitly names “credentialed provider” information as a data class under review. Credentialed providers associated with Nutex facilities should expect follow-up from the company if their professional credentials or related records were involved.
  • Business partners: Nutex lists “confidential business and financial information” as a category under review, which may be relevant to vendors, insurers, and other partners who share data or systems with the company.

Signals from outside the company and security context cited in the filing

BleepingComputer reported that it could not find any threat actor publicly claiming responsibility for the attack. The source material also includes an industry observation about post-access behavior: “Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.” That point is presented alongside a reference to the Blue Report 2026, which the source says measures defenses technique by technique across 338 million simulations run in customer production environments.

As of August 24, Nutex stated it had found no material impact on its operations or financial reporting systems, and it does not currently believe the incident will materially affect its business strategy, operations, financial condition, or results. The company has said it will continue its investigation and assessment of potential disclosures. BleepingComputer contacted Nutex for comment and said it will update the story when the company responds.

Original BleepingComputer report