HOUSTON — Healthcare services company Nutex Health Inc. has confirmed that an unauthorized third party accessed and exfiltrated sensitive information from its computer network, including data belonging to patients, employees and credentialed healthcare providers.
The company disclosed the expanded findings in a Form 8-K filed with the U.S. Securities and Exchange Commission on August 31, 2026, one week after its initial cyber incident disclosure. Nutex said the stolen information includes patient and employee data, credentialed provider information, and private or confidential business and financial information. The unidentified third party has threatened to publish the stolen data.
Nutex first disclosed the incident on August 24 after discovering unauthorized activity involving data stored on its computer network.
At that time, the company said it had engaged an independent cybersecurity response team and forensic specialists, activated its incident-response plan, implemented containment measures and notified law enforcement. Nutex initially said it believed certain information maintained on its servers had been accessed and exfiltrated, while it was still determining whether patient, employee, credentialed provider, confidential business and financial information, intellectual property or other information had been affected.
The August 31 filing provided a more definitive account of the data affected, confirming that the exfiltrated information included patient and employee data, credentialed provider information, and private or confidential business and financial information.
The company has not disclosed the number of affected individuals, the specific types of patient or employee data involved, the amount of information taken, or the method attackers used to gain access.
Nutex also has not publicly identified the third party responsible in its SEC filings.
The company said the investigation remains active and that it continues to determine whether additional categories of information, including intellectual property and other confidential material, were accessed or removed.
Nutex said it has not identified a material impact on its business operations or financial-reporting systems as of the August 31 filing.
That distinction is significant in a healthcare-sector incident.
A cyberattack can involve substantial data loss even when hospitals, clinical systems or financial-reporting platforms remain operational. Data exfiltration creates a separate risk because copied information can be retained, traded, sold, leaked or used in later fraud and identity-theft activity even after the original intrusion has been contained.
The threat to release the stolen information adds another layer of risk to the incident.
Nutex did not state whether a ransom or other demand was made, whether negotiations are taking place, or whether any stolen data has already been published.
The company said it is continuing to evaluate its legal and regulatory notification obligations and intends to make required notifications, including to affected patients where applicable.
The incident affects a healthcare organization with a substantial operational footprint.
Nutex is headquartered in Houston and operates 27 hospital facilities across 12 states through its hospital division. Its business includes micro-hospitals, specialty hospitals and hospital outpatient departments, along with a population health management division built around physician networks.
As of June 30, 2026, the company reported approximately 1,037 full-time employees, contracts with more than 280 physicians at its facilities, and partnerships with more than 3,600 physicians across its networks.
Nutex reported approximately $427.2 million in total revenue during the first six months of 2026, including roughly $409.4 million from its hospital division and $17.8 million from its population health management division.
The scale of the company means the final scope of the breach could carry consequences beyond a single facility or local patient population, depending on which systems and datasets were accessed.
Healthcare organizations routinely maintain combinations of personally identifiable information, protected health information, employment records, provider credentials, insurance information and internal financial records.
Nutex has not yet specified which individual data fields were taken, so the exposure should not be described more narrowly than the company’s current findings support.
The incident has already resulted in litigation.
A proposed class-action lawsuit, Haley v. Nutex Health, Inc., was filed on August 27 in the U.S. District Court for the Southern District of Texas, Houston Division.
According to Nutex’s SEC filing, the lawsuit seeks to represent individuals whose personally identifiable information or protected health information was allegedly accessed or acquired in connection with the incident.
The complaint alleges negligence, negligence per se, breach of third-party beneficiary contract and unjust enrichment. It seeks damages, injunctive relief, credit monitoring, identity-theft insurance and attorneys’ fees and costs.
Those claims remain allegations in civil litigation and have not been resolved by the court.
Nutex said it cannot currently predict the outcome of the lawsuit or estimate the ultimate impact the cybersecurity incident may have on its business strategy, operations, financial condition, results or common-stock trading price.
The company also identified several potential continuing risks tied to the incident, including unauthorized publication or fraudulent use of stolen information, regulatory scrutiny, litigation, remediation expenses, reputational damage, insurance-coverage questions and the diversion of management resources toward incident response.
The breach remains under investigation.
The central unanswered questions now involve the number of affected people, the exact data elements stolen, the attacker’s initial access method, whether additional systems were compromised, and whether the stolen information will be publicly released.
For Nutex patients, employees and providers, those details will determine the practical severity of the incident once the forensic investigation is complete.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



