Nutex Health says an unauthorised third party accessed and stole information from company servers during a cyberattack. The healthcare operator disclosed the incident in a filing with the US Securities and Exchange Commission.

The company says some of the stolen material may contain private or confidential information. However, investigators have not yet determined exactly what data the attacker took or who the incident may affect.

Nutex investigates stolen data

Nutex Health is investigating the cyberattack with external incident-response and forensic specialists. The company has also activated its cybersecurity response plan, contained the incident and notified law enforcement.

The Nutex Health cyberattack may involve patient, employee and credentialed-provider information. Investigators are also reviewing potential exposure of confidential business records, financial information, intellectual property and other data.

Nutex has not confirmed whether the attacker accessed information belonging to patients, employees or business partners.

Healthcare operator runs 28 facilities

Nutex Health operates 28 healthcare facilities across 12 US states. Its network includes emergency hospitals and healthcare centres, such as Bayou City ER & Hospital in Texas and Green Bay ER & Hospital in Wisconsin.

The company reported annual revenue of $875 million in 2025. It trades on the Nasdaq Capital Market under the ticker NUTX.

Because healthcare providers hold sensitive medical, financial and personal data, investigators must determine the scope of the alleged theft before they can assess the full risk.

Company reports no material operational impact

As of August 24, Nutex said the attack had not materially affected its operations or financial reporting systems.

The company also said it does not currently expect the incident to materially affect its business strategy, financial condition or results. Still, the investigation remains ongoing.

Nutex may need to provide further updates if investigators identify affected people or confirm that the attacker obtained sensitive information.

No group has claimed the attack

No ransomware or extortion group had publicly claimed responsibility for the Nutex Health cyberattack at the time of reporting.

That does not rule out a future claim. Cybercriminal groups often wait before naming victims or releasing stolen data to increase pressure during extortion attempts.

For now, Nutex continues to investigate the incident and assess the potential impact of the stolen data.


0 responses to “Nutex Health Cyberattack Leads to Data Theft Investigation”