
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers.
The organization has disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC), noting that the stolen data includes details that may be private or confidential.
“Based on preliminary findings from the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including some information that may be private and/or confidential,” Nutex says.
Nutex Health is a for-profit healthcare company that operates 28 facilities across 12 states, including the Bayou City ER & Hospital in Texas and Green Bay ER & Hospital in Wisconsin.
The company had an annual revenue of $875 million in 2025, a market capitalization of $1.28 billion, and is publicly traded as NUTX on the Nasdaq Capital Market.
After detecting the intrusion, the company hired external incident-response and forensic specialists, activated its cybersecurity response plan, implemented containment measures, and notified law enforcement.
Nutex has yet to determine the type of data that may have been compromised and if the impact includes patients, employees, or business partners.
“The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity on the Company, including any potential disclosure of private and/or confidential information by the third party,” reads the SEC filing.
As of August 24, the company says it found no material impact on its operations or financial reporting systems, and it currently does not believe the incident will materially affect its business strategy, operations, financial condition, or results.
BleepingComputer could not find any threat actor claiming the attack on Nutex.
We contacted Nutex for a comment about the incident and we will update this post as soon as we receive a response.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report