Nutex Health Tells the SEC Hackers Walked Off With Data From Its Servers

The Nasdaq-listed hospital operator, which runs 28 facilities across 12 states, says the stolen files may include private information but has not yet pinned down whose.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial image, full frame 16:9, of a dimly lit call centre workstation at night: a headset resting on a keyboard, a blurred screen showing an abstra
Share

Key points

  • Nutex Health disclosed a data breach to the U.S. Securities and Exchange Commission, saying an unauthorised third party accessed and copied information from its servers.
  • The company runs 28 hospitals and clinics across 12 states and trades on the Nasdaq under NUTX.
  • As of 24 August, Nutex says it has found no material impact on its operations or financial systems.
  • The company has not yet worked out whether patients, staff, doctors, or business partners are affected.
  • No hacking group has publicly claimed the attack.

Nutex Health, a for-profit hospital operator listed on the Nasdaq, has told U.S. regulators that hackers broke into its servers and copied data out.

The company disclosed the breach in a filing with the U.S. Securities and Exchange Commission, the federal agency that public companies must inform when something material happens to their business. Nutex says the stolen files may include "private and/or confidential" information, but has not yet said whose.

What actually happened?

Someone got into Nutex's servers and took data. That is what the company has confirmed so far, and not much more.

In the filing, Nutex says its own investigation shows that "certain information maintained on the Company's servers was accessed and exfiltrated by an unauthorized third party." Exfiltrated is the industry word for copied out to a system the attacker controls. Think of it as a burglar photographing files rather than smashing the safe.

After spotting the intrusion, Nutex brought in outside incident-response and forensic specialists (the digital equivalent of crime-scene investigators), turned on its cyber response plan, tried to contain the damage, and told law enforcement.

Who is Nutex Health, and how big is this?

Nutex Health runs 28 hospitals and clinics across 12 states, including Bayou City ER & Hospital in Texas and Green Bay ER & Hospital in Wisconsin. It reported annual revenue of $875 million in 2025 and carries a market value of about $1.28 billion.

It trades publicly as NUTX on the Nasdaq Capital Market. That is why the SEC filing exists at all: listed companies in the United States have to tell shareholders promptly when a cyber incident could matter to the business.

Detail Figure
Facilities 28 across 12 states
2025 revenue $875 million
Market cap $1.28 billion
Ticker NUTX (Nasdaq)
Disclosure date 24 August

Should patients and staff be worried?

Honest answer: nobody knows yet, including Nutex. The company says it is still working out whether patient records, employee files, doctor credentials, business contracts, financial information, or intellectual property were caught up in the theft.

Hospitals hold some of the most sensitive personal data going: medical histories, insurance details, Social Security numbers. If any of that turns up, U.S. law requires Nutex to notify the people affected directly, usually by letter.

In the meantime, anyone who has been treated at a Nutex facility or worked for one should keep an eye on bank statements and insurance paperwork, and be wary of phone calls or emails that reference their care and ask for further personal details. That is the classic follow-up pattern after a healthcare breach.

Who did it?

Unclear. Nutex has not named a suspect, and as BleepingComputer noted, no ransomware crew or extortion group has posted Nutex on a leak site claiming credit.

That could mean several things. The attackers might still be negotiating quietly. They might be a data-theft-only crew that never posts publicly. Or Nutex may have caught them before they got what they wanted. We will update as more surfaces.

One last note on the SEC angle. The filing is careful to say that as of 24 August the company does not believe the incident will materially affect its business, operations, or financial results. In plain English: Nutex is telling investors the lights are still on. Whether that holds depends entirely on what turns out to have been in those files.

© 2026 Threat Vectr